Failure analysis

The accident was due to human-machine mismatch , namely, operating in a latent exceptional situation .

Design mistakes

The sources for this misfortune were:

  Guidelines about rules defining proper scenarios, and keeping with the rules

  Guidelines about assuring the operator's awareness of the system situation

Sources for the design mistakes

The operational rules were implicit . The design did not constrain the supertanker to operate according to navigation rules .

  Guidelines about the alarm design

  Guidelines about protecting from operator's mistakes

 

 


Updated on 17 Apr 2016.