The Sea World Helicopter Tragedy: How Change Created a Fatal Conflict Point
- Safety Jon

- 6 hours ago
- 17 min read
Four people died in seconds. The operating conditions that placed two helicopters in the same airspace had been developing for months.
Editor’s note: This article is based primarily on the Australian Transport Safety Bureau’s final investigation report, released on 9 April 2025. ATSB investigations are conducted to improve transport safety and do not determine criminal or civil liability. A Queensland coronial inquest has since examined the deaths and is presently adjourned, with a date for findings yet to be confirmed. This article does not pre-empt those findings. Sea World Helicopters was an independent operator that held a concession to use the theme park’s land and branding. (ATSB)
THE FATAL CONFLICT POINT
How operational change placed two helicopters in the same space

On 2 January 2023, passengers boarded two helicopters for short scenic flights over Queensland’s Gold Coast.
A few minutes later, at 1356h, the two Eurocopter EC130 B4 helicopters collided approximately 130 feet above Broadwater.
VH-XKQ became uncontrollable and fell onto a sandbar. Pilot Ashley Jenkinson and passengers Vanessa Tadros, Ronald Hughes and Diane Hughes were killed. Three other passengers in that helicopter were seriously injured.
VH-XH9 was extensively damaged. Its injured pilot managed to retain control and land on the sandbar. The pilot and two passengers were seriously injured, while three other passengers sustained minor injuries. (ATSB)
The physical collision occurred in seconds.
But the conditions that allowed it to happen were not created in seconds.
They were created through operational change, weakened controls, incomplete risk analysis, stale information, failed communication and a system that ultimately depended on two pilots seeing each other in time.
That is the first point every organisation should understand:
The accident was sudden. The risk was not.
The ATSB’s official investigation summary explains how changes to the operation, communication failures, visual limitations and the positioning of the two helipads combined. Viewer discrection is advised as it contains accident imagery.
The collision did not begin in the air
The accident occurred only one week after Sea World Helicopters began using two EC130 B4 helicopters concurrently in its scenic-flight operation.
The operator had also undertaken several changes over the preceding years. These included new ownership, redevelopment of its main heliport, reopening a separate helipad inside the theme park and introducing larger helicopters.
Each change was intended to improve the tourism operation.
Together, they changed the risk.
When the park pad reopened in March 2022, helicopters could depart from that location while other helicopters approached the main heliport approximately 220 metres away. The normal departure and arrival paths intersected at the same height.
The ATSB found that this created a defined conflict point. It was not an unusual deviation flown by either pilot on the day. Both aircraft were following paths that sat within the bounds of the operator’s normal practices. (ATSB)

The problem was not simply whether either helipad could safely accommodate a helicopter.
The real question was whether both helipads could operate at the same time without placing arriving and departing aircraft in the same location.
That wider question was not adequately examined.
The ATSB found that the change-management process used before reopening the park pad did not properly assess its effect on the existing scenic-flight operation. The intersecting flight paths and the conflict point they created were not formally analysed. The EC130 helicopters were also introduced without a formal change-management process. (ATSB)
This is a failure that translates directly into ordinary workplaces.
A new forklift route may appear safe when assessed on its own.
A pedestrian entrance may also appear safe when assessed on its own.
But if the forklift route crosses the pedestrian entrance at a blind corner during shift change, the system is not safe.
A new machine may comply with guarding requirements but create an additional energy source that has not been incorporated into the isolation procedure.
A new delivery schedule may improve customer service while increasing fatigue, loading congestion, time pressure and vehicle interaction.
A new contractor may be competent in their own work but introduce plant, personnel and work methods that conflict with the host organisation’s operations.
The danger often sits at the interface, not inside the individual component.
How the defences failed
The arriving helicopter, VH-XH9, made the operator’s standard inbound radio call approximately two minutes before the collision.
At that time, the pilot of VH-XKQ was loading passengers, settling the cabin and preparing for departure. The ATSB concluded that the demands of passenger loading and cabin preparation probably prevented the inbound call from registering with the departing pilot. (ATSB)
After loading was completed, ground crew checked the doors, waterway and airspace behind VH-XKQ.
The crew member assessed the area as clear, gave the pilot a thumbs-up and left the helipad.
The helicopter did not immediately depart.
At the likely time of the ground crew’s check, VH-XH9 was approximately 1,220 metres away and visually difficult to detect. By the time VH-XKQ took off, the arriving helicopter had closed to approximately 425 metres.
Information that may have been accurate when the check occurred was no longer current when the helicopter moved. (ATSB)
The departing pilot was expected to make a taxi radio call immediately before lifting.
The arriving pilot knew that VH-XKQ was on the ground and expected that call to provide a warning if its status changed. Hearing it would have prompted the arriving pilot to look for the departing aircraft and arrange separation.
Evidence indicated that the departing pilot probably made the taxi call.
But the call was almost certainly not successfully transmitted.
Post-accident examination identified defects and intermittent performance in the helicopter’s radio antenna system, including a fractured soldered connection and a defect in the radio-frequency cable connector.
The departing pilot had no indication that the call had failed.
The arriving pilot heard no call and therefore received no trigger to reassess VH-XKQ as an immediate collision threat. (ATSB)
Both pilots were also managing legitimate operational demands.
The departing pilot was monitoring vessels, the departure path and another known traffic area.
The arriving pilot was concentrating on landing, maintaining access to a forced-landing area and avoiding a vessel crossing the approach path.
A passenger in the arriving helicopter saw the danger and attempted a verbal warning seven seconds before impact. Two seconds before impact, the passenger tapped the pilot on the shoulder.
It was too late.
The system had given both pilots a believable but incorrect understanding of reality.
The departing pilot believed the airspace was clear.
The arriving pilot believed the other helicopter remained on the ground.
Neither belief was unreasonable based on the information available to each pilot.
Both beliefs were wrong.
Lesson 1: Management of change must examine the whole system
The reopening of the park pad was not adequately assessed in the context of the complete scenic-flight operation.
The assessment needed to extend beyond whether the physical pad was suitable.
It needed to ask:
Where will departures from this pad intersect with existing arrivals?
What will each pilot be doing at that location?
What will each pilot be able to see?
How will each pilot know the other aircraft is moving?
Which existing controls will become less reliable?
What will happen if one radio transmission fails?
What happens during peak demand, when aircraft movements increase and workers are performing repetitive tasks?
Those questions were not resolved before concurrent operations became normal.
Australian risk-management guidance requires controls to be reviewed before workplace changes likely to create new or different risks, and emphasises that risk management is an ongoing process requiring particular attention when changes affect work activities. (Safe Work Australia)
A change-management process is therefore not a document created to justify a decision that has already been made.
Its purpose is to test the decision.
A proper process may show that the proposal can proceed.
It may show that additional controls are required.
It may show that the operation must be sequenced differently.
It may also show that the change should not proceed at all.
That is the point.
If the organisation is not prepared for the change assessment to stop the project, it is not conducting risk management. It is conducting paperwork.
Lesson 2: A control that expires before exposure is not a reliable control
Ground crew checked the area and advised that it was clear.
The problem was not necessarily that the check was carelessly performed.
The problem was that the procedure allowed monitoring to stop before the helicopter departed.
The environment continued to change after the signal was given.
The control expired before the exposure occurred.
Left image: ATSB Figure 28 — visual angle of VH-XH9 from the ground crew position
Right image: ATSB Figure 29 — passage of VH-XH9 from the ground crew position
The arriving helicopter was difficult to detect during the likely ground-crew checking window. By the time the departing helicopter lifted, the traffic situation had changed materially. Credit: Source: Australian Transport Safety Bureau, Investigation AO-2023-001, Figures 28 and 29, CC BY 4.0. (ATSB)
The same weakness appears across Australian workplaces.
A spotter checks behind a vehicle and then walks away before it reverses.
An exclusion zone is checked before a crane lift but is not maintained while the load is suspended.
A gas test is performed before conditions inside a confined space change.
A load is inspected and then altered without another verification.
A permit is issued for one equipment configuration and relied upon after that configuration changes.
A supervisor checks that an area is clear before another workgroup enters it.
The question is not only:
“Was the check completed?”
The question is:
“Was the information still true when the dangerous action occurred?”
“Clear” is not a permanent condition.
A time-sensitive control needs a defined validity period. It must remain current until the movement, entry, energisation, lift or other hazardous action has been completed.
A thumbs-up does not control risk after the information supporting it has become obsolete.
Lesson 3: Silence is not confirmation
The separation system depended heavily on radio broadcasts.
The departing pilot was expected to transmit a taxi call.
The arriving pilot expected to hear it.
But there was no positive acknowledgement confirming that the message had been transmitted, received and understood.
When the transmission failed, the system did not reveal the failure.
The departing pilot could not distinguish between:
a successful call with no conflicting traffic;
a call that another pilot had not heard; and
a call that had never left the aircraft.
The arriving pilot could not distinguish between:
a helicopter remaining on the pad;
a pilot omitting the call; and
a failed transmission.
Silence was interpreted as evidence that the status had not changed.
It was actually an absence of reliable information.
Examination of the communication system identified intermittent performance, corrosion and a fractured soldered connection. The radio was present, powered and expected to work—but could not be relied upon to transmit the critical call. Credit: Source: Australian Transport Safety Bureau, Investigation AO-2023-001, Figures 45 and 48, CC BY 4.0. (ATSB)
Safety-critical communication should be closed-loop wherever reasonably practicable.Similar processes are used in defence field radio usage.
The sender communicates the instruction or information.
The receiver repeats the critical content.
The sender confirms the repeat-back.
The activity does not proceed when confirmation is absent or unclear.
This principle applies well beyond aviation.
It applies to crane lifts, electrical isolation, rail protection, confined-space entry, emergency response, vehicle movements, plant start-up and any activity where one person’s decision depends on another person receiving critical information.
If a message must work to prevent someone being killed, transmitting it is not enough.
The system must confirm it arrived.
And where confirmation does not occur, the default state should be stop, not assumption.
Lesson 4: Human vision cannot recover every earlier system failure
After the inbound call failed to register, the ground-crew information became stale and the taxi call failed to transmit, the remaining defence was visual detection.
The pilots had to see and avoid one another.
That sounds reasonable until the actual visibility conditions are examined.
The ATSB’s detailed visibility study found that aircraft structures, limited contrast, minimal relative movement, the geometry of the convergence and the pilots’ operational workload restricted the opportunity for detection.
For the arriving pilot, the departing helicopter was shielded from the likely eye position for part of the critical period. Before being shielded, its lack of contrast and limited apparent movement reduced the chance of it attracting attention.
For the departing pilot, the arriving helicopter moved behind cockpit structures. The departing pilot was also positioned and oriented in a way that restricted the ability to manoeuvre or conduct an effective clearing turn. (ATSB)
Two pilots. Two restricted views. One conflict point.
These ATSB reconstructions represent the investigators’ best estimate of what each pilot could have seen when looking directly ahead during the final 39 seconds.
The easy recommendation after an event like this is:
“Maintain situational awareness.”
Or:
“Remain vigilant.”
Or:
“Look before moving.”
Those statements are not wrong. They are simply inadequate.
Human attention is finite.
A person concentrating on one legitimate hazard may fail to detect another.
A driver checking one blind spot cannot simultaneously see every other area around the vehicle.
A crane operator monitoring the suspended load may not see a person entering the exclusion zone.
A plant operator responding to one alarm may miss a developing condition elsewhere.
A worker conducting a complex isolation can be interrupted.
A supervisor managing an emergency can become focused on the most visible problem while another hazard develops.
The correct response is not to demand superhuman awareness.
The correct response is to design work around human limitations.
Eliminate the conflict point.
Separate incompatible movements.
Sequence the work.
Provide positive traffic control.
Introduce interlocks or independent detection.
Create mandatory hold points.
Prevent simultaneous operations where separation cannot be assured.
Human attention should remain a defence. It should not be the organisation’s plan for recovering every previous control failure in the final seconds.
Lesson 5: A fatal risk cannot depend on one call, one person or one device
The taxi call had become a critical control.
If it worked, the arriving pilot would likely reassess the departing helicopter and arrange separation.
When it failed, there was no clear indication that it had failed and no dependable independent control remaining.
The ground-crew information was no longer current. Visual detection was unreliable. The flight paths still intersected.
The ATSB described the operator’s separation process as reactive and found that it lacked redundancy where a taxi call was not made, transmitted or heard. It also found that available additional controls for improving alerted see-and-avoid had not been implemented. (ATSB)
That is a direct warning for every high-risk business.
If one control sits between normal work and multiple fatalities, management must know:
What exactly must the control do?
Under what conditions must it work?
How is its availability confirmed?
How is its performance tested?
How will workers know when it has failed?
What is the immediate response to failure?
What independent control remains?
A control listed in a risk assessment is not automatically a functioning control.
A radio may be installed and not reliably transmit.
A gate may be present and routinely left open.
An interlock may exist and be bypassed.
A spotter may be appointed and unable to see the danger area.
A permit may be signed and no longer reflect the plant configuration.
A supervisor may be accountable and unavailable.
The existence of a control is not enough.
Its performance must be defined, verified and monitored.
A control without a performance standard is an aspiration.A critical control without redundancy is a single point of failure.
Lesson 6: Control drift is organisational change
Some changes occur through formal projects.Others happen gradually.
The ATSB found that, following the change in ownership, existing controls involving enhanced communication and in-cockpit traffic information progressively degraded and were ultimately withheld without formal analysis.
That reduced the information available to pilots and weakened their ability to maintain a shared understanding of each other’s position and intentions. (ATSB)
This is how controls often disappear in real workplaces.
A supervisor position remains vacant.
A damaged barrier is removed and not replaced.
An inspection interval quietly stretches.
A protective device is awaiting repair.
A second worker is no longer available.
A temporary procedure becomes the normal procedure.
A software installation is delayed while operations continue.
An experienced worker leaves and their knowledge is assumed to remain in the organisation.
A maintenance activity is repeatedly deferred.
No one announces that the organisation is accepting greater risk.
The system simply becomes weaker one compromise at a time.
Management of change must therefore be triggered when a control is:
removed;
degraded;
bypassed;
delayed;
replaced;
reduced in frequency;
reassigned;
made dependent on a temporary workaround; or
no longer operating as originally intended.
Controls do not need to be formally cancelled to stop protecting people.
Lesson 7: A safety system can be active and still manage the wrong risks
Sea World Helicopters had a safety management system.
The ATSB did not find a complete absence of safety activity.
It found that the system did not effectively manage aviation risk in the context of the organisation’s primary business. Its objectives were non-specific and much of its attention was directed towards ground handling and general work health and safety matters rather than the aviation hazards capable of producing catastrophic consequences. (ATSB)
That distinction is important.
An organisation can have:
safety meetings;
inspections;
training records;
completed forms;
incident dashboards;
policies;
audits; and
action registers,
while still failing to understand the risk most capable of killing people.
Safety performance cannot be measured by administrative volume.
The correct question is not:
“How much safety activity occurred?”
It is:
“Did that activity verify that the controls preventing death were effective?”
An organisation may be measuring minor injuries while failing to monitor vehicle-pedestrian interaction.
It may be counting toolbox talks while plant isolation controls are degrading.
It may be tracking overdue actions while failing to identify that two normal work processes now occupy the same hazardous space.
It may have a polished system that is looking in the wrong direction.
Lesson 8: Low reporting may mean blindness, not safety
The operator conducted approximately 7,500 flights during 2022.
Between December 2019 and December 2022, the ATSB identified only two incident reports and no hazard reports relating to aviation safety risk.
When an external audit questioned the low reporting rate, senior management expressed the view that a well-operated aviation organisation should not have incident or hazard reports.
The ATSB rejected that reasoning. It found that the lack of reporting prevented operational hazards, variability and emerging safety conditions from being captured and managed through the safety management system. (ATSB)
A clean dashboard may indicate strong control.
It may also indicate:
workers do not recognise what should be reported;
the reporting system is difficult to use;
people believe nothing will be done;
managers treat reports as evidence of poor performance;
repeated deviations have become normal;
operational concerns remain inside informal conversations; or
the organisation is recording the wrong events.
A near miss is not an inconvenience that damages a safety statistic.
It is free information about a system that nearly produced harm.
Suppressing that information does not improve safety performance.
It removes the opportunity to act before the consequence becomes irreversible.
Lesson 9: Consequence controls deserve the same discipline as prevention controls
The ATSB also examined passenger survivability.
Passengers were routinely being incorrectly restrained because of problems combining multipoint seatbelts with constant-wear lifejackets. Training and passenger safety information also contained inconsistent or incorrect guidance concerning restraint fitment, emergency exits and brace positions.
The ATSB could not determine the precise contribution that incorrect restraint made to individual injuries. It nevertheless found that correct restraint fitment improves occupant outcomes and allows energy-absorbing seats and other protective features to work as designed. (ATSB)
At the same time, another consequence control worked.
Although injured and flying an extensively damaged helicopter, the pilot of VH-XH9 assessed that the controls remained functional and landed on a predetermined forced-landing area.
That preparation and retention of control prevented an already catastrophic event from becoming even worse. (ATSB)
Prevention remains the priority. But prevention can fail. Organisations must also be prepared for what happens next.
That includes:
emergency stops;
rescue plans;
occupant restraints;
emergency access;
fire protection;
evacuation arrangements;
first aid capability;
trauma support;
incident command;
backup communication; and
realistic emergency exercises.
A laminated emergency plan is not preparedness. A procedure that has never been practised is still an assumption.
A note on the cocaine evidence: causation must remain disciplined
The ATSB found it was very likely that the pilot of VH-XKQ had used cocaine approximately one and a half days before the collision.
That conduct was contrary to regulatory requirements and the legitimate expectations placed upon the pilot of a passenger-carrying aircraft.
The ATSB’s toxicological analysis nevertheless found that the pilot was unlikely to have been directly affected by cocaine during the accident flight. The quantities detected were very low, impairment of psychomotor skills was considered unlikely, and the ATSB did not find that the cocaine consumption contributed to the development of the collision. (ATSB)
Drug-and-alcohol management is among the matters considered by the coronial inquest. Findings remain pending. (Coroners Court)
The lesson is not that illicit drug use should be minimised.
It should not.
The lesson is that investigation must distinguish between:
conduct that is unacceptable;
conduct that increases risk; and
conduct that caused or contributed to the particular event.
A confronting personal fact can dominate public attention because it provides a simple explanation.
One person broke a rule.
The person caused the event.
Remove the person, remind everyone of the rule and declare the risk controlled.
That conclusion may be emotionally satisfying. It may also be wrong.
A serious individual breach can exist alongside failures involving change management, flight-path design, communication, maintenance, visual detection, reporting and control assurance.
One does not erase the other.
Causation is not a morality contest.
An organisation that focuses only on the most blameworthy fact may leave the underlying pathway to catastrophe open for the next worker.
What changed after the accident
Following the collision, Sea World Helicopters reported introducing several additional controls, including:
updated hazard analysis for scenic flights and both helipads;
a dedicated pad boss providing traffic advice;
supplementary air-traffic information systems in each helicopter;
additional mandatory radio calls;
procedures intended to prevent passenger distraction during approach;
high-intensity strobe lighting;
high-visibility main rotor blade markings;
human-factors training for all staff; and
revised passenger briefing and seatbelt training.
CASA also updated heliport guidance to address interaction between flight paths from nearby facilities and updated passenger safety guidance relating to multipoint restraints and lifejackets. (ATSB)
The ATSB acknowledged the action taken but found that four identified safety issues had not been adequately addressed at the time of the final report. It issued recommendations concerning conflict-point design, aviation-safety objectives and stronger change-management processes. (ATSB)
These changes matter because they show that stronger layers of protection were available.
The purpose of learning is to identify and implement those layers before people die.
The practical management-of-change test
Before approving the next operational change, leaders should require evidence-based answers to the following questions.
What new interaction will the change create?
Map people, vehicles, plant, energy, information, timing and authority.
Do not assess only the new equipment or location.
Assess what it will interact with.
Which existing controls will become weaker?
A control designed for the previous operating environment may not remain effective after the change.
What assumptions are being made?
Do not write “workers will maintain awareness” or “communication will occur” without testing how, when and under what conditions.
Can any control fail without anyone knowing?
A silent failure is particularly dangerous because work continues under false confidence.
What happens during the transition?
New equipment, temporary procedures, unfamiliar work and incomplete technology often make the commissioning period more dangerous than the intended final operation.
What happens during peak demand?
A control that works during a quiet trial may fail under real production pressure.
What is the stop condition?
Management must define when unavailable, degraded or unverified controls require the work to cease.
What will be reviewed after implementation?
Change management does not end when the new operation starts.
Field observation, worker consultation, incident reporting and control verification must test whether the original assumptions remain true.
If those questions cannot be answered with evidence, the change is not ready.
The consequences did not end on the sandbar
Safety discussions can become absorbed in diagrams, procedures, radios, flight paths and risk controls.
But the purpose of examining those matters is not technical fascination.
It is the human consequence.
Ashley Jenkinson died.
Vanessa Tadros died.
Ronald Hughes died.
Diane Hughes died.
Other passengers sustained serious and life-changing injuries.
Families who expected their loved ones to return from a short scenic flight instead entered years of grief, rehabilitation, investigation and court proceedings.
Workers, witnesses, bystanders and emergency responders were exposed to the immediate aftermath.
In July 2026, more than three years after the collision, the victims’ families addressed the final hearing day of the coronial inquest and described the continuing effect of their losses. Coroner Carol Lee is now preparing findings, with the matter formally adjourned and no findings date yet confirmed. (ABC News)
The families’ statements demonstrate that the consequences of a catastrophic safety failure continue long after the investigation scene has been cleared.
That is what inadequate change management can produce.
Not an overdue action.
Not a poor audit score.
Not an incomplete risk-assessment form.
Death.
Permanent injury.
Trauma.
Children losing parents.
Parents losing children.
Partners returning home alone.
Families spending years waiting for answers that cannot restore what was taken.
No revised procedure can undo that. No new technology can return those four people.
The lesson has already been paid for.
Final lesson
The narrow lesson from the Sea World collision would be to maintain radio antennas.
That is correct. It is not enough.
Another narrow lesson would be to make more radio calls.
Also correct. Still not enough.
Another would be to remind pilots to look carefully before moving.
Again, correct. Still not enough.
The deeper lessons are these:
Changes must be assessed across the whole operating system.
Conflict points should be eliminated or positively controlled.
Safety-critical information must remain current.
Critical communication requires confirmation.
Controls must reveal when they have failed.
Human attention cannot be the only recovery mechanism.
Fatal-risk controls require redundancy.
Control degradation must trigger change management.
Reporting systems must expose operational reality.
Safety management must focus on catastrophic risk—not administrative activity.
Emergency and survival controls must be ready when prevention fails.
The two pilots were operating inside a system that gave each of them a different and incorrect version of reality.
A safe system does not expect people to detect and correct every earlier failure in the final seconds.
It finds the conflict point before people enter it.
It tests the assumptions.
It verifies the controls.
And it ensures that one missed call, one blind spot, one stale check or one failed component cannot create a direct path to four deaths.












Comments