Qantas Flight 72
- Date
- Phase of flight
- Cruise
- Location
- Over the Indian Ocean, 154 km (83 NM) west of Learmonth, Western Australia; landed at Learmonth
- Aircraft
- Airbus A330-303
- Registration
- VH-QPA
- Operator
- Qantas
- Flight
- Qantas 72
- Occupants
- 315
- Fatalities
- 0No fatalities; 12 occupants seriously injured (1 crew member and 11 passengers), and at least 110 passengers and 9 crew members injured in all
- Investigating body
- Australian Transport Safety Bureau
- Final report
- AO-2008-070
- Report date
- Report title
- In-flight upset, 154 km west of Learmonth, Western Australia, 7 October 2008, VH-QPA, Airbus A330-303
On 7 October 2008 a Qantas Airbus A330 cruising at FL370 off Western Australia suddenly pitched nose-down twice. One air data inertial reference unit was sending false angle of attack spikes, and a limitation in the flight control software let such spikes trigger nose-down commands. Many occupants were injured.
On 7 October 2008, Qantas flight 72, an Airbus A330-303 registered VH-QPA, was cruising at FL370 from Singapore to Perth when one of its three air data inertial reference units (ADIRUs) began sending false data. Two minutes later, at 04:42:27 UTC (12:42 local time), the aircraft's flight control computers suddenly commanded it to pitch nose-down. Almost everyone who was not strapped in was thrown against the ceiling. A second, smaller pitch-down followed. The crew diverted to Learmonth, Western Australia, and landed there safely.
The aircraft carried 303 passengers and 12 crew. At least 110 passengers and 9 crew members were injured, 12 of them seriously. Nobody was killed.
The Australian Transport Safety Bureau (ATSB) investigation is a study of how a highly redundant fly-by-wire system can still be misled by one faulty source, and of how an unexpected combination of two rare problems can escape the safety analysis of a certified design. It is also a reminder about seat belts.

The flight
VH-QPA was built in 2003 and had flown 20,040 hours. It left Singapore at 01:32 UTC (09:32 local; local time in Singapore and Western Australia was UTC plus 8 hours) with a captain, a first officer and a second officer on the flight deck and nine cabin crew. The captain was pilot flying. By 02:01 the aircraft was in cruise at FL370 at Mach 0.82 with autopilot 1 and autothrust engaged. The weather was fine and there had been no turbulence. At 04:39 the first officer left for a rest break and the second officer took the right seat.
The A330's three ADIRUs each combine an air data reference (ADR) part, which supplies airspeed, altitude and angle of attack (AOA), and an inertial reference (IR) part, which supplies attitude and position. The flight control primary computers (FCPCs) use their data to fly the aircraft in normal law, with protections that include a high angle of attack protection against the stall.
The accident
At 04:40:26 ADIRU 1 began sending intermittent, incorrect values (spikes) on all its parameters. Two seconds later autopilot 1 disconnected and the captain took manual control. Caution messages, stall warnings and overspeed warnings began and continued for the rest of the flight. The captain's airspeed and altitude indications fluctuated, so he flew using the standby instruments and the first officer's display. Autopilot 2 was engaged for 15 seconds and then disconnected by the crew. The captain asked for the first officer to be called back.
| Time (UTC) | Event |
|---|---|
| 04:40:26 | ADIRU 1 starts sending data spikes; autopilot 1 disconnects 2 seconds later |
| 04:42:27 | First pitch-down: up to 8.4° nose-down, peak vertical acceleration −0.80 g; 690 ft lost over 23 seconds |
| 04:42:43 | Seat-belt sign already switched on; announcement for passengers and crew to return to their seats and fasten seat belts |
| 04:45:08 | Second pitch-down: about 3.5° nose-down; 400 ft lost over 15 seconds |
| 04:45:11 | Flight control law reverts to alternate law for the rest of the flight |
| 04:47:25 | Autothrust disconnected; captain flies manually on standby instruments |
| 04:49:05 | PAN call; diversion to Learmonth requested |
| 04:54:25 | MAYDAY declared after reports of serious injuries |
| 05:32 | Landing at Learmonth on runway 36 |
During the first pitch-down the captain pulled back on his sidestick at once, but for about 2 seconds the flight control system did not respond, and the aircraft descended about 150 ft before it did. The acceleration at the centre of gravity reached −0.80 g; in the rear cabin it was probably beyond −1.2 g. The second event was similar but milder. Afterwards the ECAM kept scrolling repeated messages, with chimes and stall and overspeed warnings the crew could not silence, and the autotrim was lost, so the captain trimmed manually.
The crew decided to land as soon as possible, fearing further pitch-downs, and Learmonth was the nearest airport suitable for an A330. They consulted the operator's maintenance watch by satellite phone and, on its suggestion, switched off FCPC 3 at 05:20, which did not stop the scrolling messages or the warnings. They descended cautiously in wide orbits, kept the cabin crew seated in case of another upset, managed the cabin pressure manually and planned for manual braking. The aircraft landed at 05:32 after a straight-in visual approach.
The investigation
Why the computers pushed the nose down
The FCPCs normally used the average of AOA 1 and AOA 2, and compared all three AOA values for consistency. If AOA 1 or AOA 2 deviated from the others, the computers held the last good value for 1.2 seconds (a memorisation period). This handled single spikes, runaways and step changes, and on this flight it filtered out almost all of ADIRU 1's spikes.
But the algorithm had a gap. If one spike started a memorisation period and a second spike was present exactly when that period ended, the computers accepted the next values as valid. That is what happened. Airbus's simulations matched the recorded elevator movement when an AOA 1 spike of 50.6° was averaged with a true AOA 2 value of 2.3°, and the FCPCs used an angle of attack of 26° for about 400 milliseconds, then decreased it gradually under a rate limiter.
Two mechanisms responded to that false high AOA. High angle of attack protection, available only in normal law, commanded about 4° of nose-down elevator; anti pitch-up compensation, which counters the swept wing's tendency to pitch up at high Mach and high AOA, added about 6°. The resulting 10° nose-down elevator command was close to the most the two mechanisms could produce. While the false value stayed above the threshold, about 1.8 seconds, the captain's sidestick inputs had no effect on pitch. The second pitch-down involved at least four spikes, and the sidestick had no effect for about 2.8 seconds.
Monitoring then did what it was designed to do. The computers' command and monitor channels disagreed, faults were declared on FCPC 1, then FCPC 3 and FCPC 2, and after the second event the control law reverted to alternate law, in which high AOA protection is not provided. That sequence also removed the autotrim.

The ADIRU failure
The ADIRU, a Northrop Grumman LTN-101, sent incorrect air data as valid data without a fault message, whereas almost all of its incorrect inertial data, such as pitch attitude, was flagged as invalid. The spikes were probably produced when the unit's central processor combined the value of one parameter with the label of another. The exact mechanism and trigger could not be found. A software bug, corruption, hardware fault, temperature, vibration and electromagnetic interference, including from a naval communication station near Learmonth, were all found unlikely. A single event effect, a high-energy atmospheric particle striking an integrated circuit, could not be ruled in or out, and the ATSB flagged such effects as a continuing risk for avionics.
The same unit had shown the failure mode on the same aircraft on 12 September 2006, without affecting the flight path, and a different unit on another Qantas A330, VH-QPG, did so on 27 December 2008. Those were the only three known occurrences in over 128 million hours of unit operation. The unit's built-in test equipment was not designed to detect this kind of problem.
Certification and the safety analysis
The FCPC software had been developed in 1991 and 1992 with peer reviews, a system safety assessment, testing and simulation. None identified the gap, and the processes did not fully consider frequent spikes from an ADIRU. In over 28 million flight hours of A330/A340 operation this was the only known pitch-down caused this way, a rate within the certification objective for a "hazardous" effect. The ATSB judged that the limitation was very unlikely to have caused a worse outcome: an AOA value above 30° would have forced alternate law, high AOA protection needs 2 seconds of confirmation below 500 ft, and anti pitch-up compensation works only above Mach 0.65 with the aircraft clean. Even so, it called the limitation very undesirable and a significant threat to those on board.
The crew
The ATSB found that the only action that would have prevented the first pitch-down was to switch off ADR 1. No ECAM message called for it, and nothing suggested a threat to the flight controls, so it was not reasonable to expect the crew to do so in the two minutes available. The captain's responses to both pitch-downs were prompt and of the right size; the ATSB noted the risk of an over-correction making the accelerations worse. It found that the crew's handling showed sound judgement and a professional approach, and that the stream of spurious warnings created significant workload and distraction.
The cabin
More than 60 of the 303 passengers were seated without their seat belts fastened at the first upset. As in earlier upsets, injuries were far more frequent and severe among occupants who were not seated or not belted. The seat-belt sign had not been on; the second officer switched it on immediately after the first event.
Probable cause and contributing factors
The ATSB does not state a single probable cause; it lists findings. Its executive summary gives the key outcome, that the upset:
occurred due to the combination of a design limitation in the flight control primary computer (FCPC) software of the Airbus A330/A340, and a failure mode affecting one of the aircraft's three air data inertial reference units (ADIRUs).
The contributing safety factors in its findings were:
- the FCPC algorithm limitation that let multiple AOA spikes from one ADIRU produce a nose-down elevator command (a significant safety issue);
- Airbus's system safety assessment and other development processes of the early 1990s, which did not fully consider frequent data spikes from an ADIRU;
- the ADIRU data-spike failure mode, which sent incorrect air data as valid, and a probable marginal hardware weakness in the unit involved, which had shown the failure mode before;
- built-in test equipment that did not detect the problem or flag the air data as invalid, and the ADIRU manufacturer's failure mode effects analysis, which had not identified the failure mode;
- passengers not following advice to keep seat belts fastened when seated.
Among other safety factors, the ATSB listed the workload and distraction caused by the spurious warnings, the susceptibility of avionics (including this ADIRU model) to single event effects, for which there were no specific certification requirements, and the limited research into how design engineers evaluate systems and into what influences passengers' use of seat belts.
Safety recommendations and what changed
The ATSB made no formal safety recommendations. It was satisfied that Airbus's action would address the significant safety issue, and for the minor safety issues it recorded the action taken.
- Procedures. On 15 October 2008 Airbus issued an Operations Engineering Bulletin: after a NAV IR FAULT, crews select the ADR and then the IR part of that ADIRU OFF. It was revised in December 2008, and again in January 2009 after the VH-QPG event showed that the procedure then in force did not stop the inertial data. EASA and CASA made each version mandatory by airworthiness directive. On 27 December 2008 the VH-QPG crew applied the procedure and switched ADR 1 off after 28 seconds.
- Flight control software. An interim FCPC standard with revised monitoring of five parameters was fitted to Qantas A330s by November 2009. The new AOA algorithm drops the 1.2-second memorisation and rejects an ADR for the rest of the flight if its AOA is inconsistent or oscillating. Later software standards with the redesigned algorithms were certified by EASA during 2011 for all but one A330/A340 model. Airbus also reviewed its handling of ADIRU data on the A320 and A380 and updated its design guidelines.
- ADIRU. At Airbus's request, the manufacturer enhanced the unit's monitoring so that data transmission failures are more likely to be detected and the affected outputs stopped; the change had passed testing and was expected to be certified by the end of 2011. By the time of the report, additional ADIRU 1 parameters were being recorded on all Qantas and Jetstar A330s.
- Single event effects. EASA asked applicants on recent certifications to consider them, and the FAA was considering the IEC TS 62396 guidance.
- Seat belts. The ATSB and CASA reinforced the message to keep seat belts fastened whenever seated, and the operator looked at measuring passengers' seat belt use.
Lessons for pilots
Fly the aircraft first, with measured inputs. The captain's immediate, proportionate sidestick response limited the height loss. An upset from an automatic command is sudden and startling; the ATSB noted the risk of overcorrection. See fly-by-wire for how the control laws and protections work.
Exam tip: On Airbus fly-by-wire aircraft, normal law provides the flight envelope protections, including high angle of attack protection. Alternate law keeps some protections in modified form but loses others, including high AOA protection; direct law has none. Know which cue on the primary flight display tells you the law has changed.
Protections are only as good as their inputs. High AOA protection pushes the nose down because it believes the wing is near the stall. Here it acted on a false angle of attack. Understanding where each flight deck display and computer takes its data, and which ADIRU feeds which side, helps a crew isolate a faulty source. See angle of attack, stall warning and stall protection.
Note: Spurious stall and overspeed warnings together, with fluctuating speeds on one side only, point to an air data problem rather than a real stall or overspeed. Cross-check the other primary display and the standby instruments before acting.
When the ECAM cannot help, prioritise. The crew recognised that the scrolling messages were not giving useful guidance, flew the aircraft, and chose to land as soon as possible. Asking maintenance for help, keeping the cabin informed and descending cautiously were all part of managing the threat.
Design assurance has limits. The system met its certification targets, yet two rare problems combined in a scenario that the safety assessment had not identified. For students of failure conditions and system safety, this is the practical meaning of "extremely remote": it is not "impossible".
Keep your seat belt fastened whenever you are seated. This applies to crew members as well as passengers. On this flight 31% of the occupants wearing seat belts were injured, against 93% of those seated without them and 97% of those not seated, and cabin briefings are part of cabin safety.
The ATSB does not state a probable cause. It found that the in-flight upset "occurred due to the combination of a design limitation in the flight control primary computer (FCPC) software of the Airbus A330/A340, and a failure mode affecting one of the aircraft's three air data inertial reference units (ADIRUs)." Multiple angle of attack spikes from that unit, 1.2 seconds apart, caused the FCPCs to command the aircraft to pitch down.
Train this on v1prep
The theory behind this accident and the questions that test it, each with a worked explanation.
Question banks
- ATPL Instruments597 questions with worked explanations
- A320 Flight Controls237 questions with worked explanations
- A320 Navigation249 questions with worked explanations
In the Library
- Fly-by-Wire and Flight Envelope ProtectionHow fly-by-wire replaces mechanical linkages with computers and electrical signals, the redundancy that makes it safe, the Airbus control laws and the flight envelope protection they provide.
- Angle of Attack, Stall Warning and Stall ProtectionHow angle of attack is sensed and displayed, how stall warning systems use it, and how envelope protection works from AoA.
- Failure Conditions and System SafetyExplains how certification classifies failure conditions by severity and links each to a maximum allowed probability, including software assurance levels.
- Cabin Safety and Passenger ManagementCabin crew numbers and roles, the senior cabin crew member, cockpit-cabin communication and the cabin secure report, passenger signs and safety briefings, seat belts and infant restraints, passengers with reduced mobility and portable electronic devices.
Frequently asked questions
What caused the Qantas Flight 72 pitch-down?
The ATSB found that the upset resulted from a design limitation in the A330/A340 flight control primary computer software combined with a failure mode of one of the aircraft's three air data inertial reference units. That unit sent frequent false spikes in angle of attack. When one spike was followed by a second 1.2 seconds later, the computers accepted the second as valid, so they believed the angle of attack was too high and commanded the aircraft to pitch nose-down.
How many people were injured on Qantas 72?
The aircraft carried 303 passengers and 12 crew. At least 110 passengers and 9 crew members were injured. In all, 51 passengers and 2 crew members were treated in hospital, and 12 of them were admitted (serious injuries). Almost all the unrestrained occupants were thrown against the ceiling during the first pitch-down. More than 60 passengers were seated without their seat belts fastened, and injuries were much more frequent and severe among those not seated or not belted.
Why did Qantas 72 pitch down if the pilots did not command it?
The flight control computers have two mechanisms that command nose-down elevator when angle of attack is too high: high angle of attack protection and anti pitch-up compensation. A false 50.6° spike made the computers use an angle of attack of 26°, and together the two mechanisms commanded about 10° of nose-down elevator. For about 2 seconds the captain's sidestick inputs had no effect. The aircraft reached 8.4° nose-down and descended 690 ft before returning to FL370.
Could the Qantas 72 crew have prevented the upset?
The ATSB found that the only crew action that would have prevented the first pitch-down was to select the air data part of ADIRU 1 OFF. No ECAM message or procedure called for that, and nothing indicated a threat to the flight controls, so it was not reasonable to expect the crew to do it in the two minutes available. The ATSB described the crew's responses as timely and appropriate.
What changed after Qantas Flight 72?
Airbus issued procedures within days telling crews to switch off the air data and inertial reference parts of an ADIRU showing a fault; EASA and CASA made them mandatory. Airbus then redesigned the flight control software's angle of attack algorithm and reviewed its handling of other ADIRU data, including on the A320 and A380. The ADIRU manufacturer improved the unit's built-in fault detection, and the ATSB highlighted seat belt use.
Sources and further reading
- ATSB, Aviation Occurrence Investigation AO-2008-070 (Final), In-flight upset, 154 km west of Learmonth, WA, 7 October 2008, VH-QPA, Airbus A330-303
- Copy of the ATSB final report AO-2008-070 used for this page (PDF hosted by aussieairliners.org)
- EASA, Easy Access Rules for Large Aeroplanes (CS-25), including CS 25.1309 system safety
Crash Investigations pages summarise official investigation reports for study and exam preparation. The investigating body's report is the authoritative account and prevails wherever it differs from this page. Under ICAO Annex 13, an investigation exists to prevent accidents, not to apportion blame or liability.