Accident · ssh / airDisasterReports
United Airlines Flight 232 Crash Investigation
When United Flight 232 lost all three hydraulic systems over Iowa, its flight controls effectively stopped working. What followed became one of aviation’s most important studies of engine failure, redundancy and crew teamwork.

At 37,000 feet over the American Midwest, the crew of United Airlines Flight 232 heard a violent bang.
The center engine mounted in the tail of their McDonnell Douglas DC-10 had failed.
An engine failure by itself should not have made the aircraft uncontrollable. The DC-10 had three independent hydraulic systems specifically so that losing one—or even two—would not remove its flight controls.
Within moments, all three were effectively gone.
The pilots could move their control columns and pedals, but the elevators, rudder and ailerons that normally obeyed them had lost hydraulic power.
For the next 44 minutes, the crew tried to fly a widebody airliner with almost nothing except the thrust of its two surviving engines.

The Failure Began Inside the Tail Engine
Flight 232 left Denver on 19 July 1989 bound for Philadelphia, with a planned stop in Chicago. About one hour and seven minutes after departure, its No. 2 engine suffered a catastrophic failure.
The engine was a General Electric CF6-6D.
Investigators eventually traced the failure to the engine's stage-one titanium fan disk. According to the National Transportation Safety Board, the disk contained a metallurgical defect created during manufacture.
A fatigue crack originated at that defect very early in the disk's operating life and grew gradually through thousands of takeoff-and-landing cycles.
This was not an invisible crack forever.
The NTSB final report concluded that a detectable surface crack roughly half an inch long existed during United's most recent inspection of the disk in April 1988, about 760 cycles before the accident.
It was not detected.
Eventually the disk could no longer withstand normal operating loads.
It fragmented at high speed.
Three Hydraulic Systems Had One Physical Weakness
The exploding fan disk released fragments with enormous energy.
Some struck the aircraft's tail structure and penetrated hydraulic lines.
This revealed a critical distinction between functional independence and physical independence.
The DC-10's three hydraulic systems were separate systems. Each had its own fluid and power source, and the aircraft was designed to remain controllable with failures affecting one or two systems.
But in parts of the tail, hydraulic lines from all three systems had to pass relatively close together.
The FAA's Flight 232 case study explains that debris from the No. 2 engine damaged all three.
Hydraulic fluid escaped.
The airplane had no mechanical backup system allowing the pilots to move the major control surfaces directly.
The redundancy still existed on the engineering diagram.
A single physical event had defeated all of it.
The Throttles Became the Flight Controls
The DC-10 did not immediately fall out of the sky.
Its two wing-mounted engines—No. 1 and No. 3—were still operating.
Captain Alfred Haynes and his crew discovered that changing their thrust could influence the aircraft's motion.
If one engine produced more thrust than the other, the resulting yaw could indirectly produce roll and help change direction. Increasing or reducing overall power could also influence pitch, although very imprecisely.
This technique is called differential thrust.
It was never intended to replace normal flight controls.
The airplane continually wanted to turn right and oscillated in pitch. The crew could influence its general direction but could not hold the kind of precise attitude, altitude or flight path expected during a normal approach.
Then an extraordinary piece of luck entered the cockpit.
Dennis Fitch, an off-duty United DC-10 training check airman travelling as a passenger, offered to help.
Haynes brought him forward and eventually assigned him to manipulate the two surviving engine throttles while the captain and first officer continued working the normal controls.
Four experienced pilots were now effectively improvising a new method of flying the aircraft in real time.
Sioux City Became Their Only Realistic Destination
The crew chose Sioux Gateway Airport in Iowa for the emergency landing.
Air traffic control originally expected Flight 232 to use Runway 31. But the aircraft's unstable flight path and difficulty turning left placed it more naturally toward Runway 22, which was closed.
Haynes elected to continue toward it.
The crew could not extend normal flaps or slats using the lost hydraulic systems, so the DC-10 approached unusually fast.
The NTSB calculated that during the final 20 seconds, airspeed averaged about 215 knots and descent rate about 1,620 feet per minute.
Near the ground, the aircraft's right wing dropped sharply.
The right wingtip hit first, followed by the right main landing gear. The aircraft broke apart, rolled and caught fire.
Of the 296 people aboard, the NTSB officially classified 111 fatalities. The remaining 185 survived the initial accident, although one seriously injured passenger died 31 days later and was classified as a serious injury under the reporting rule then in effect.
Investigators Found Two Different Safety Failures
The accident investigation did not stop with the hydraulic lines.
Investigators worked backward into the failed engine itself.
The NTSB found that the titanium fan disk contained a manufacturing defect known as a hard-alpha defect. The crack that grew from it had survived manufacturing inspections and later maintenance inspections.
The Board's probable-cause finding focused particularly on human-factor limitations in the inspection and quality-control procedures at United's engine-overhaul facility, which allowed the fatigue crack to go undetected.
But the accident exposed a second design problem.
The energy and distribution of the fan-disk fragments exceeded the protection provided to the hydraulic systems. Three nominally independent systems could still be defeated by one uncontained engine failure because of their physical proximity.
That is known as a common-mode or zonal vulnerability.
The Crew Did Better Than Investigators Thought Was Possible
After the crash, investigators tried to reproduce the emergency in DC-10 simulators.
The results were sobering.
The NTSB concluded that training crews specifically for the exact Flight 232 failure would probably not have made a successful runway landing reliably achievable. The damaged airplane was technically still flyable, but precise landing control without hydraulic flight controls was extraordinarily difficult.
The Board said the performance of the Flight 232 crew was highly commendable and greatly exceeded reasonable expectations.
Crew Resource Management mattered too.
Instead of treating the captain as the only source of solutions, the cockpit used the experience of the first officer, flight engineer and an off-duty pilot who happened to be aboard. Tasks were divided while ideas were tested under enormous pressure.
The crash also demonstrated why redundancy must be examined physically, not only logically.
Three backup systems are less independent than they appear if one fragment can reach all three.
Flight 232 therefore left aviation with two very different lessons.
One came from failure:
a microscopic manufacturing defect, missed during inspection, eventually destroyed an engine and exposed a hidden weakness in aircraft-system redundancy.
The other came from what happened afterward:
when the designed control system disappeared, four pilots created just enough control from what remained to give many people aboard a chance to survive.

Conversation
Comments
Sign in to join the conversation.