MENU
Kazubara
Site administrator
A former engine designer at an automobile manufacturer. I will share my mechanical design skills based on 15 years of work experience. For job inquiries, please contact me using the inquiry button below.

20 Lessons Learned from the Comet Jet Crash: Technological History and Lessons from the Disaster (Responsibilities, Accident Investigation, Third-Party Committees, Safety)

In the previous installments, we considered all the problems in the development of the Comet.

In the previous discussion, we focused specifically on the test flight, which is the final stage of development.

This time, let's consider how the Comet aircraft was handled in the wake of the accident.

First, although it will be a review, let me briefly introduce the basic procedure for handling an accident once again.

table of contents

Basic principles and procedures for accident response

I previously explained the general approach and procedures for responding to an accident.

Detailed explanation of accident response approach → Technological history and lessons learned from the Comet crash 9: The Comet crash and cause analysis (destruction engineering, FTA, FMEA, cause-and-effect diagram, hypothesis and verification)

Collect and analyze the parts of the machine that caused the accident.

To briefly review, the first step in responding to machine malfunctions and accidents is to recall the affected product.

No matter how small the part may be, we will gather as many parts and fragments as possible by pooling all our resources.

Next, the collected parts and fragments are put together like a puzzle to return them to their original form.

Once the collected parts and fragments have been restored to their original shape, the next step is to check all the fracture surfaces of the damaged parts.

The traces left on the fracture surface help determine whether it was a single-shot fracture, a fatigue fracture, or a combination of fatigue fracture and single-shot fracture.

If you know the form of the destruction, an engineer with a certain level of experience can determine the order in which the destruction occurred.

This process will help us determine which part of the machine broke first, and which part of that part broke first.

From here on, we'll gather a large group of people to brainstorm hypotheses about the cause.

Formulating hypotheses about the cause of the accident

To briefly review the process of formulating hypotheses about the cause of this accident, we use tools such as FTA, FMEA, and cause-and-effect diagrams for analysis.

Basically, FTA considers component failure as the top event and then gradually narrows down the analysis to determine what events would cause component failure.

On the other hand, FMEA, unlike FTA, first considers the possible failure modes for all parts and then thinks about what impact the failure of a particular part will have on the entire machine.

In short, FTA and FMEA have completely opposite approaches. FTA starts with the top event and considers various other events, gradually breaking down the problem into smaller and smaller parts, while FMEA starts by considering the failure of the smallest components of the machine and then considers what impact it will ultimately have on the entire machine.

Ideally, you should always have time to perform both, but you can also choose which to use depending on the nature of the accident and the type of machinery involved.

Finally, there's the cause-and-effect diagram, which is a method of analysis used to investigate whether there are any problems in the surrounding environment related to the machine.

A representative example is the 5Ms, which can be thought of as the axes of Machine, Man, Manufacture, Method, and Measure.

This is merely a list of recommended elements; if there are other related factors such as transportation and parts storage, you should add them to the analysis to make it more effective.

Based primarily on these three analyses, we formulate the most probable hypothesis.

Next, since hypotheses must be supported by empirical evidence, we will conduct empirical experiments.

Reproduction test

The approach to creating the demonstration experiment was explained here.

The approach to creating reproduction tests → Technological history and lessons learned from the Comet crash: 10 Reproduction tests and cause analysis of the Comet crash (reproduction tests, strain gauges, load cells, reliability engineering)

Basically, the process involves trying to reproduce the hypothesized situation using some method, then using reliability engineering to verify whether it can actually be reproduced, and finally creating a reproduction test.

After that, if the reproduction tests are completed and the hypothesis is successfully proven, then the hypothesis will be closer to the truth.

Summary of approaches and methods for accident response

The accident response process up to this point can be represented as a flowchart as follows:

While you don't necessarily need to memorize everything, remembering this flowchart will be extremely useful not only for accident response but also for resolving everyday problems, troubles, and issues that frequently occur in your work. So, if you feel like it, I would be happy if you could write it down on paper.

HoweverThe key to using it regularly is not to overthink it.

If you're stuck on one analysis and can't move on to the next, it's better to skip it and move on.

Also, ifIf you can expect cooperation from family or colleagues, don't hesitate to ask for their help; it will improve the accuracy of your analysis and speed up the process.

That concludes our review.

Now let's look at how the Comet aircraft was handled in the accident.

Response to the Comet series of crashes

I have previously described the timeline of events, responses, reconstruction tests, and the process of determining the cause of the Comet accident, so I will omit them here.

Timeline of the crash and investigation of its causes → Technological history and lessons learned from the Comet crash, Part 9: The Comet crash and its causes (destructive engineering, FTA, FMEA, cause-and-effect diagram, hypothesis and verification)

Reproduction testing and root cause analysis using RAE → Technological history and lessons learned from the Comet crash 10: Reproduction testing and root cause analysis of the Comet crash (reproduction testing, strain gauges, load cells, reliability engineering)

I also shared my own perspective on accidents, multi-perspective checks for accident response, and mutual checks.

Accident Analysis, Multi-Perspectives, and Mutual Checks → Technological History and Lessons Learned from the Comet Jet Crash 13: Reconsidering General Lessons and Causes of the Comet Jet Crash (Stress Concentration, Fatigue Failure, Multi-Perspective Checks, Mutual Checks)

Based on these points, let's focus on aspects other than the engineering aspects and RAE reproduction testing that we've discussed so far.

First, as a review, let's look at the timeline of the accident using a snake diagram.

Here everyoneThe biggest question and problem I see is, "Why weren't full-scale investigations launched after the first and second accidents?"

Considering the response to the first crash: British Airways Flight 783, 1953.

Let's start by looking at the response to the first accident, the British Airlines Flight 783 incident in May 1953.

This accident response is among the worst I have ever seen, heard about, or investigated.

The conclusion reached by the government and the development and manufacturing company regarding the cause of this accident was pilot error.

Furthermore, the Indian government's investigation concluded that the weather was bad and there were thunderstorms on the day of the accident, and they believe this condition further contributed to the pilot's error.

That's an overly simplistic conclusion.

Moreover, since the ground tests were not conducted to the point of destroying the test unit, even if the pilot made an operational error, no one knew how much overload would cause it to break, making this an impossible conclusion given the terrifying situation.

like thisAny conclusions drawn without identifying the cause are called speculation or conjecture, and are largely meaningless.

As I've mentioned before, regardless of the degree of fault, accidents are almost never 100% the fault of the person; there's almost always some problem with the machine (especially when used by professionals).

moreoverThe typical engineer's way of thinking is that humans are prone to making mistakes, so they try to compensate for those mistakes with technology and the aircraft itself.

Moreover, even after investigating this accident myself, I found no evidence that a proper investigation into the cause had been conducted, and for some reason, it was simply concluded that it was due to pilot error.

Ultimately, it was deemed the pilot's fault, no thorough investigation was conducted, no countermeasures were taken, and the flight permit was not revoked.

Apparently, some people pointed out defects in the pressurized chamber at this stage, but their concerns were not taken seriously.

Even based on the author's own observations, despite the numerous mistakes and miscalculations during development, it seems that even at this stage, there was little suspicion of a malfunction in the aircraft.

This meansI sense arrogance and overconfidence on the part of the British government that issued the approval for the development and manufacturing company.

Even without a large-scale accident investigation, if an accident like this occurs, the development and manufacturing company would normally review the development process and development data.

IfIf the development and manufacturing companies are not taking such action, it would be easy for the government to order them to re-examine the development content and development data.

There is no evidence that even that was done.

Furthermore, in a typical accident response, even if pilot error is the most likely cause, if it cannot be definitively determined, the government or the development and manufacturing company would normally create an accident investigation team to investigate (and since this is the world's first, anything could happen, so they would proceed cautiously).

Even if the Comet resumes commercial flights, it's standard practice to continue investigating the accident behind the scenes as a precaution.

If a thorough investigation had been conducted here, history would have undoubtedly changed for the better.

When dealing with malfunctions or accidents in the market, it's essential to promptly investigate the true cause, clarify the cause, and implement the correct countermeasures. However, in this case, they haven't even bothered to investigate the cause, let alone implement any countermeasures.

ThanksIt seems that both the government and the development and manufacturing company were blinded by their desire to get the Comet into commercial flight as quickly as possible.

Considering the response to the second crash: British Airways Flight 781, January 1954

After the second accident, British Airways Flight 781 in January 1954, which disintegrated in mid-air, some kind of preventative measures were apparently taken.

As I've written before, the modifications mainly involved about 60 areas of protection for fuel and electrical systems related to fire, in response to the prevailing trend at the time of in-flight fire prevention (which did not occur on the Comet).

However, examination of the bodies revealed neither signs of burns from the fire nor metal fragments from explosions caused by the fire.

In other words, the evidence suggests that no fire occurred on board the aircraft.

This measure was completely meaningless. It did not investigate the cause of the incidents described above, and was simply a temporary solution to the prevailing trend of in-flight fires on aircraft other than the Comet.

ObviouslyTaking countermeasures without knowing the cause is completely meaningless.

Just as hypothesis and verification go hand in hand, troubleshooting and accident response always involve identifying the cause and proposing countermeasures.Otherwise, it's meaningless.

This response is merely a preventative measure against a potential in-flight fire that might occur on a Comet in the future; it's not a preventative measure.

Logically, no matter what measures were taken, permission to fly again would not be granted as long as the cause remained unknown. However, for some reason, the British government granted permission.

In addition to the first accident,The government's judgment is completely wrong.

Perhaps they didn't want to tarnish the Comet's legacy, and when weighing the business and political losses resulting from being unable to fly against safety, they made the wrong choice.

They probably also trusted the prestigious development and manufacturing company (de Havilland).

In the first placeSafety is the top priority and should not be weighed against anything else; it should take precedence over everything else.

Even at this stage, the government, which should have been the oversight body for the development and manufacturing companies, was completely ineffective.

On the other hand, looking at the actions of the development and manufacturing companies, this is also unlikely.

A normal, competent company would immediately take action as described above—like the accident investigation team assembled by Churchill or the RAE in this story—when such a situation occurs (many Japanese companies these days are unable to do this).

While it certainly couldn't have the budget and personnel of a national project, the development and manufacturing company (de Havilland) was a very prestigious and massive corporation, so it should have been able to assemble a research team with considerable capabilities and a reasonable scale.

The important point here is that, based on my experience, there are roughly four main reasons why we didn't investigate the cause at this stage.

Reasons for not conducting a cause investigation

- They don't perceive it as a particularly major social problem.

We don't bear much responsibility.

- Money, time, and people are taken up considerably, interfering with other businesses.

- Not profitable

I have a feeling that's what he thinks.

This reflects the same perception of how to address malfunctions in modern Japan.

Therefore, no one in the company wants to do it, it doesn't get recognized, the budget isn't approved, and the company itself simply lacks motivation—a perfect combination of four problems.

I think it's the same for many companies, but one of the reasons companies fall into this psychological state is that no matter how sloppy their internal development is or how many problems occur during development, they have a habit of insisting that they have released a perfect product once it's on the market.

It seems that companies really dislike being criticized by others, and once they release a product to the market, they are very reluctant to admit to any defects.

Furthermore, there seems to be a concern that if they immediately admit to defects or problems with a new product, all of their past products might be questioned or thought to have been mistakes.

In that sense, an atmosphere of not wanting to acknowledge or do anything about it persists even today (often resulting in illicit modifications).

The company that developed and manufactured the Comet probably felt the same way, especially since they were a prestigious company.

Identifying the cause is a very difficult task that requires a lot of time, money, and manpower, so we are taking a preliminary approach based on recent incidents (airplane fires) that are common in the area.

This was another bad thing, but because they took some kind of action, the development and manufacturing company mistakenly believed that Comet had become an even more perfect machine (even though the action was completely meaningless).

What made things even worse was that the British government recognized the effectiveness of this pointless response and granted permission for the aircraft to fly again, which only further boosted their misplaced confidence and self-esteem.

Normally, an internal accident investigation team would be formed immediately after the first accident, but they couldn't even do that, and they didn't even check the development content and development data, which should have been the bare minimum.

If they had remained calm and checked the development details and reviewed the development data, they should have easily identified the problems in the development process that I pointed out (there were probably many engineers who were more than 100 times more capable than me).

Even if there were others who noticed the same problems as me (and I think there were quite a few), given the circumstances, it's likely that neither the company nor the government would have listened.

It feels like all they're thinking about now is getting the Comet back into commercial flight as soon as possible.

In fact, the same thing happened closer to home some time ago when the third-generation compact car F from H, a major Japanese automobile company, was recalled more than six times (or was it eight?) for its DCT transmission.

I think there will probably be more than 10 cases, including market modifications that don't result in a recall.

This, too, was initially dismissed as a minor issue (without properly investigating the cause) and a series of haphazard, stopgap measures were implemented. As a result, we ended up having to deal with the problem more than 10 times, losing not only money and time but also a considerable amount of trust.

Next, let's consider the third accident.

Considering the response to the third plane crash: South African Airways Flight 201, April 8, 1954.

Looking at the response to the third accident, it's clear that the government and the development and manufacturing company were completely dysfunctional, and it's even questionable whether they were sane.

The development and manufacturing company attributed the first accident to pilot error and irregular conditions such as bad weather.

For the second incident, for some reason, they implemented fire prevention measures on the aircraft, which was approved by the British government, allowing them to obtain permission to fly again.

After this response, a third accident occurred, so the development and manufacturing company could no longer dare to admit that there might be a problem with the Comet (even at this stage, they still believed there was nothing wrong with the Comet).

Announcing that there may have been a problem with the Comet aircraft at this point would be tantamount to admitting that the cause of the first accident and the response to the second accident were meaningless.

The moment you admit it, you become fodder for the media.

Like thisMaking the wrong decision at the beginning is extremely difficult to correct later, and the losses will be much greater, so it's a very dangerous situation.

またThe government is probably in the same situation and is in a very precarious position where they can't back down (since they issued permission for the aircraft to fly again, they can't easily revoke it).

If the government were to say, "There was a problem with the Comet," it would have a significant impact on its international credibility and the aviation industry.

When governments and companies are pushed to this point, they often become half-frenzied and reach a state of madness where they try to crush anyone who even slightly disagrees with their policies.

Well, at any stage, you really have to be prepared to lose face and immediate profits if you pursue and announce the truth (especially the government), and in fact, looking back, starting over honestly will cause far less damage to your credibility and face than running away with lies.

From here,Fortunately, Prime Minister Churchill was there, so he made a big decision, invested a large budget with people who had no vested interests, and was able to pinpoint the cause.

What I particularly liked was,The key factor was that it was spearheaded by the RAE (Royal Aeronautical Institute) and the British military, who had no vested interest in the matter.

As you have probably already realized, the government and the development and manufacturing companies, having become stakeholders, have put themselves in a situation where they can no longer function normally.

Ideally, the government and the company should have been subject to mutual checks and balances, but conflicting interests prevented that (they wanted to launch the Comet missile quickly).

This is a classic example of how things can go wrong if you don't approach things with an honest eye and an unbiased, neutral mindset free from vested interests.

Here tooCorporate ethics and engineering ethics are very important factors.

Ultimately, it was the RAE, a neutral third party with no vested interest, that grasped the cause of the Comet crash.

Thus, while ideally the parties involved (in this case, the government and the company) should be able to resolve, address, and take measures themselves, due to conflicting interests, it's often better to rely on a third party (RAE) as soon as things go wrong.

This kind of wisdom has been passed down to the present day, and even in modern Japan, when a problem arises, the government quickly assembles a third-party committee or experts.

It would be wonderful if this gathering were conducted without any vested interests, but in reality, the system has become completely meaningless, and it looks like they're just inviting friends, resulting in a disappointing outcome.

Furthermore, while companies have outside directors (who I've never seen actually be helpful) for management, there is no system in modern Japan for a third-party organization that can respond to problems and accidents on the ground or in the market.

で き れ ばBeyond just business management, we should learn from history and create some kind of system, such as third-party verification, to ensure customer safety and prevent market malfunctions.

Learning and acting upon true lessons from history is very difficult.It is.

Next time, I will summarize my re-examination of the causes of the Comet jet crash and write an afterword.

To those who found this article helpful in understanding design:

Since we're on the subject, I'd like to recommend a book that's essential for mechanical design.

To be honest, the content is extremely unhelpful, but it can be used like a dictionary when you forget the details. If you read this article, you should be able to understand the content and use it effectively. It also includes commonly used standards, making it quite useful.

If you don't already own one, I highly recommend getting one, even though it's a bit pricey. However, new ones are expensive, so if you're considering buying a used one, I strongly recommend checking that the surface roughness conforms to the new JIS standard.

[For those considering using our services in organizations such as corporations, companies, government agencies, and educational institutions.]
If you intend to use the information explained in this article for training, materials, technical standards development, or reports within your organization,Information page for corporations and organizationsPlease check the terms of use for more details.

We also offer consultations regarding detailed technical support and consulting.Dedicated formWe are accepting at.

No prior notification or special procedures are required for sharing on personal blogs or social media, or for using the content within the scope of appropriate citation (such as including the source). Please feel free to use it actively.

If you like this article
Follow me!

Share it if you like!
  • I copied the URL!
  • I copied the URL!

Person who wrote this article

Kazubara's avatar Kazubara Site administrator / Technical advisor / Article supervisor

Previously worked at Honda R&D (motorcycles), where I was responsible for engine and drivetrain design, CAE analysis, and systems engineering (design process construction using MBSE).
We promote the design and CAE of the CRF series and large motorcycles, as well as the development of design processes and field implementation projects.
I currently work as a website administrator, technical advisor, and article supervisor, so please feel free to contact me.
I also run a YouTube channel called "KazubaraTube," so please check it out.

Comment:

To comment

table of contents