A REX Regional Express Saab 340B, registration VH-ZRM performing flight ZL-5267 from Townsville,QL to Hughenden,QL (Australia) with 15 passengers and 3 crew, was departing Townsville's runway 01, shortly after becoming airborne the first officer engaged flight director and autopilot to follow the standard instrument departure. However, the aircraft entered a left turn away from the SID track, the captain intervened, disengaged the autopilot and resumed manual flight. The crew requested radar vectors and later re-engaged the autopilot. The aircraft continued to destination without further incident.

The ATSB released their final report concluding the probable causes of the incident were:

Contributing factors

For reasons undetermined, the CATEY ONE standard instrument departure likely appeared as invalid data in the flight management system, which resulted in an unexpected turn off the departure procedure when the autopilot was engaged.

When flight crew programmed the flight management system before engine start using external power, Regional Express procedures did not require them to verify their programmed flight plan after engine start and before take-off, which increased the risk of an aircraft departing with a data error. (Safety issue)

Other factors that increased risk

The pilot in command misunderstood the operator's intended flight management system check of the first waypoint to mean the first waypoint of the company flight plan instead of the first waypoint after take-off. While it could not be determined if this contributed to the incident, it increased the risk of a data entry error going undetected.

The ATSB analysed:

Invalid data in the flight management system

On the morning of 19 November 2025, the first officer (FO) for the Regional Express Saab 340 flight from Townsville to Hughenden requested and received their airways clearance from air traffic control for their flight to Hughenden via CATEY with the CATEY ONE standard instrument departure (SID). The pilot in command (PIC) programmed the flight management system (FMS) with the company flight plan for CATEY to Hughenden and the CATEY ONE SID. This was likely done on external power, which would have required the FMS to be subsequently powered down for engine start and then powered up after engine start. As the flight plan was retained by the FMS after power up, the 7-minute data retention period associated with the FMS power down cycle was likely not exceeded.

When the flight directors and autopilot were engaged after take-off, the autopilot immediately attempted to turn the aircraft left, off the SID track. The FO noted that the flight directors and FMS were indicating that CATEY was the first active waypoint instead of AGSIR, which was the first SID waypoint. They also noted that the SID waypoints were in the FMS flight plan and in the correct sequence but had a different appearance to the active waypoints and were possibly ‘greyed out’. The FO attempted to re-sequence the SID with the ‘Direct-To’ function, but the FMS would not accept any of the SID waypoints they selected.

No fault was found with the CATEY ONE SID in the operator’s FMS database, and the FMS manufacturer was unable to replicate the reported symptoms using its FMS Trainer.

Subsequently, the FMS manufacturer provided several potential scenarios for review by the ATSB. The manufacturer’s scenarios and ATSB analysis of each one was as follows:

- The FMS SID will appear greyed-out if it is entered as a pilot-created SID procedure instead of a navigation database selection. However, the PIC reported that they selected the CATEY ONE SID from the departures menu in the FMS and therefore this scenario was considered unlikely.

- An incorrect runway selection could result in the procedure appearing in the flight plan with fewer waypoints but not connecting to the active leg. However, there was no runway change before departure and the FO reported seeing the correct SID waypoints in the FMS, therefore this scenario was also considered unlikely.

- Loading an active navigation leg for Townsville to CATEY prior to the SID entry would retain the original active leg rather than automatically sequencing to the first SID waypoint. A ‘Direct-To’ would have been required to manually sequence onto the SID.

However, the FO reported that they could not re-sequence the SID with the ‘Direct-To’ function, so this scenario was also considered unlikely.

- The SID entry might have been initiated but not fully completed before the FMS was powered down for engine start. After engine start, the aircraft would have then taxied and departed with the SID displayed but not linked to the active guidance. This scenario could explain the FO’s observation that the SID waypoints appeared different in the FMS flight plan. However, the manufacturer could not replicate the fault.

Without a download of the FMS or cockpit voice recorder, further analysis was not possible and therefore, the reason for the appearance of invalid data could not be determined.

Operator’s procedures

The operator’s Flight crew operating manual included the checklists for its normal procedures. The After start scan-action flow included the NAV AIDS (navigation aids)/FMS brief. This item was required to be delivered by the PIC (left seat pilot) and checked by the FO (right seat pilot) and included confirmation of the first waypoint in the FMS. However, external power was available at Townsville Airport, which allowed the FMS programming and NAV AIDS/FMS brief to be conducted before engine start. In that case, the NAV AIDS/FMS check in the After start scan-action flow was abbreviated to the PIC announcing ‘Nav aids set’. Similarly, the Take-off brief, which included the SID brief and followed the NAV AIDS/FMS brief, could also be conducted before engine start and, after engine start, the flight crew were only required to announce that it was ‘Complete’.

If the FMS was programmed before engine start, it was required to be powered down for engine start and then powered up again after. Provided it was powered up within 7 minutes of being powered down, it would retain its programmed data. The flight plan was retained by the FMS after power up, and therefore, it was likely the FMS was powered up within the 7-minute data retention period.

The Taxi checklist included a check of the flight instruments. However, it did not include a check of the FMS programming, or a crosscheck of the navigation displays (EHSI) to verify that the correct information was displayed before take-off. The PIC reported that they did not crosscheck their navigation display with the SID before take-off because it was not required by the procedures and the operator acknowledged that there was no specific validity check of FMS data after engine start if the FMS was programmed on external power and then powered down for engine start. Furthermore, the navigation display can be partly obscured by the yoke if it is in the forward position.

An ATSB review of FMS programming and check procedures for an Australian and US regional airline identified that both airlines included the FMS programming and waypoint verification steps in their checklists before engine start. However, their departure briefs were conducted after engine start, and both required their flight crew to verify that their displays presented the correct information. This occurred in the Taxi pre-take-off checklist for the Australian operator and in the Before take-off checklist for the US operator.

The aircraft manufacturer advised that it did not have any specific guidance or recommendations for FMS crosschecks before take-off, and that such procedures and practices should be developed by operators and their flight crew. Of note, the US Federal Aviation Administration’s (2017) guidance on when operators may need to modify checklists provided by the manufacturer included after incidents.

Noting the International Air Transport Association’s (2015) report finding that the main reported FMS data entry errors occurred during programming, it was considered likely that this fault occurred either during the programming of the FMS, or when the FMS was powered down for engine start. It was considered unlikely that the FMS was powered up with valid SID data that later became invalid during taxi or take-off.

As the FMS and flight director were pointing to CATEY after take-off, it was considered likely that this was the case when the aircraft was taxied for take-off. Therefore, it was also considered likely that the invalid data could have been detected by the pilots verifying the SID programming on their navigation displays in one of the checklists after engine start and before take-off. This would have mitigated the likelihood of an unexpected turn on departure and the risk of a loss of safe separation standards with terrain or traffic.

Pilot in command misunderstanding

The After start-action flow included an item where the left seat pilot (PIC) briefed the NAV AIDS/FMS setup. This included a check of the first waypoint on the FMS, which was confirmed by the right seat pilot (FO). The PIC reported their understanding that the FMS first waypoint brief was for the first waypoint of the company flight plan, which was CATEY on the incident flight. However, the FO reported that the brief was for the first waypoint after take-off, which was the first waypoint of the SID – AGSIR.

The operator confirmed the FMS first waypoint brief was for the first waypoint after take-off, which should have been AGSIR for the incident flight. However, without a download of the FMS, it could not be determined exactly what was programmed and how it was programmed; and without a download of the cockpit voice recorder, it could not be determined exactly what was briefed by the PIC and how the FO responded.

Therefore, while the PIC and FO provided different interpretations for the first waypoint in the FMS they checked, there was insufficient evidence to determine if this discrepancy contributed to the incident. However, more generally, the PIC's misunderstanding of the operator’s intent for the FMS first waypoint brief could contribute to the check missing a data entry error with unforeseen consequences.

This article is published under license. Article Source

Published Date