At 01:25:00 on 26 March 2024 the containership Dali lost electrical power 3,200 feet from the Francis Scott Key Bridge in Baltimore. Four minutes and nine seconds later she struck Pier 17. Six highway workers, filling potholes on the bridge, died.
01:28:49 Rate of turn reaches zero. The Dali starts coming to port 01:28:57 Bow thruster. Second mate: "No, it's not working." 01:28:59 Sound of anchor chain running 01:29:09 IMPACT. Starboard bow strikes Pier 17 at 6.4 knots 01:29:15 Span 18, with four vehicles on it, begins to collapse 01:29:22 Pier 17 collapses 01:29:24 Span 20, two vehicles, collapses 01:29:27 Span 21 collapses 01:29:28 Span 22 - the inspector's vehicle - collapses On March 26, 2024, about 1:29 a.m.
Eastern Standard Time, the container ship Dali was transiting out of Baltimore Harbor in Baltimore, Maryland, when it experienced losses of electrical power, propulsion, and steering, and struck Pier 17, the southern pier that supported the central span of the Francis Scott Key Bridge, a substantial portion of the bridge subsequently collapsed into the river and portions of the pier, deck, and truss spans collapsed onto the vessel's bow and forward most container bays. Tragically, six workers, who were on the bridge, died as a result of the collapse. A seventh worker survived, but suffered serious injuries, an inspector escaped without physical injuries, and one of the 23 crew members aboard the Dali, sustained sustained minor injuries. On behalf of the entire agency, I want to extend our deepest sympathies to those who lost loved ones in this terrible, terrible tragedy.
as well, of course, of the survivors, who I hope, are on the mend. I was the board member on scene for this accident. And I met with the families, and I boarded the Dali several times, and saw the devastation up close. I can only imagine what the families and survivors have gone through over the last 20 or so months.
I also imagine that this has been difficult for those who witnessed the devastation. The senior pilot who called for help as the vessel approached the bridge, the pilot dispatcher, who notified the Maryland Transportation Authority, the MDTA police, who were on the bridge at the time, and who, within seconds, closed the bridge to traffic, saving countless lives. And the crew aboard the Dali, many of whom are still in the United States. For those in the room, or in the family briefing room, Elias Kontanis from our transportation disaster assistance division is here, and we'll be here throughout the course of the board meeting to provide support to anyone who may need it.
Elias and I think that's Max back there, Max Green, if you could just raise your hand. If anyone needs support, please come see them. They'll be at the back of the room. The fact is, none of us should be here today.
This tragedy should have never occurred. Lives should have never been lost. As with all accidents that we investigate this was preventable. Throughout this meeting, you're gonna hear exactly how.
I'm not going to get ahead of The pictures you just saw came from a security camera on the west bank of the Patapsco River. Its clock was never corrected, so this film uses the National Transportation Safety Board's times instead. For twenty months the Board investigated the collapse of the Francis Scott Key Bridge, and it put almost everything it gathered on public record: the ship's chart recordings, the pilot's, the shore cameras, the transcript of the ship's bridge, the interviews, the laboratory photographs. This film is made from that record, and from the Board's own recordings, in order.
Saturday, the twenty-third of March, twenty twenty-four, early in the afternoon by its own uncorrected clock. Another camera at the same industrial site, pointed at the same bridge, records a container ship coming in from the sea, played here four times faster than life. She is the Dali, flagged in Singapore, nine hundred and eighty-four feet long, on a regular run up the east coast from Busan, by way of Newark and Norfolk. At twelve minutes past three she tied up at the Seagirt Marine Terminal.
The bridge she passed under had opened to traffic on the twenty-third of March, nineteen seventy-seven, forty-seven years to the day. It was about nine thousand feet long, and gave a hundred and eighty-five feet of clearance over a shipping channel seven hundred feet wide. More than thirty-four thousand vehicles crossed it every day. It was built with what engineers now call nonredundant steel tension members.
If one of them fails, the bridge is likely to come down, partly or entirely. It met the standards it was designed to in the nineteen sixties, and it was rated satisfactory at its last inspection. Two supports, Pier seventeen and Pier eighteen, stood on either side of the channel. Each had a timber and concrete fender, and four round steel dolphins stood in the water nearby.
Monday, the twenty-fifth. The crew was doing maintenance in port before that night's departure. Working on the exhaust scrubber of generator two, the only generator then running, a crewmember mistakenly closed its exhaust damper. The generator choked and slowed, the power management system disconnected it, and the whole ship blacked out.
The electrician brought the power back. To do it, he switched the ship's low voltage supply from the transformer that had been in use for months, transformer two, to the other one, transformer one, by closing its two breakers by hand. The NTSB was told this was common practice. The ship would sail on transformer one.
Its circuit was the one with the loose wire. Five minutes later the ship blacked out again. Generators three and four were being fed their fuel by a single pump that was never meant for the job: a flushing pump, used to clean fuel lines, with no backup and no automatic restart. When the power dropped, it stopped, and it did not start again by itself.
The crew recovered. Neither blackout was reported outside the ship. At twenty-two minutes past eleven that night the steering gear was tested, and logged as satisfactory.
This is the playback of the pilot's portable unit, the chart the Maryland pilots carry aboard with them, from twenty past midnight on Tuesday the twenty-sixth, running sixteen times faster than life. Two pilots had boarded at about five past midnight, a senior pilot and a pilot in training. The Dali was bound for Colombo, in Sri Lanka, a voyage of twenty-seven days, with four thousand, six hundred and seventy-nine containers aboard. On the bridge ahead, seven highway workers from Brawner Builders were filling potholes in the right southbound lane, with one inspector.
Maryland Transportation Authority police officers sat in their cars at each end of the bridge, slowing traffic past the work. The inspector had the officers' phone numbers, and the crew's. He was the only link between them. Tugs took the Dali off the berth and into the channel.
At eight minutes past one the forward tug was let go, as was normal practice in Baltimore once a ship was steady in the channel. The pilot in training took the conn. At twenty-one past one, the senior pilot told him to keep the speed at ten knots or less. Now the ship's own electronic chart display, as its voyage data recorder kept it, replayed at ten times speed on the NTSB's screen and filmed there.
The channel runs straight to the south east, under the bridge. When the power went, the voyage data recorder had no backup supply for its ship's data, and it stopped recording speed, heading and rudder. The ship's position during those minutes comes from its automatic identification system, which kept transmitting. That is why the NTSB said the recorder's standards had to change.
On the other bank, a home security camera in Dundalk was recording the same water from a quarter past one, here eight times faster. The next file in its series was corrupted and could not be played. This one ends at one thirty. The west bank camera, 01:22 to 01:24, four times real speed.
What follows runs in real time, from twenty-four and a half minutes past one to one thirty. On the left, the west bank camera. In the middle, the Dundalk camera, on its own uncorrected clock. On the right, the pilot's unit.
The words are the NTSB's transcript of the ship's bridge and its record of the calls ashore, at the times the NTSB established. Nothing else is added. 01:24:30 Dali outbound in the Fort McHenry Channel, heading 141, about 8.9 knots 01:25:00 FIRST BLACKOUT. Steering pumps 1, 2 and 3 lost.
3,200 feet from the bridge 01:25:03 Voyage data recorder stops recording ship data 01:25:08 Main engine shuts down 01:25:14 Senior pilot: "Do we have steering?" 01:25:16 Second mate: "We have steering." 01:25:17 Helmsman: "Yes sir. Yes sir." 01:25:27 Master orders the bosun to stand by at the anchor brake 01:25:47 Helmsman: "Swinging to starboard, wheel on hard port sir" 01:25:58 Electrician closes breakers HR1 and LR1 by hand. Power back after 58 01:25:59 Senior pilot phones the pilots' dispatcher: have the Key Bridge shut down seconds 01:26:10 Emergency generator connects - 70 seconds after the blackout 01:26:12 Senior pilot orders port 20 01:26:18 Rate of turn to starboard reaches 7.5 degrees a minute 01:26:38 Senior pilot calls for tugs on channel 14 01:26:44 Pilots' dispatcher calls the MDTA command center 01:26:47 Senior pilot to tug Eric McAllister: power lost, heading for the Key Bridge 01:26:57 Senior pilot on VHF: "that's it, hammer down" 01:27:02 Senior pilot orders "port anchor", shouting 01:27:04 SECOND BLACKOUT - high and low voltage 01:27:07 Generator 2 restores high voltage. Low voltage still dark 01:27:14 Master shouts to the bosun to let go the port anchor 01:27:23 Senior pilot orders hard port 01:27:25 Pilot-in-training makes the securite call 01:27:36 Low voltage restored by hand through HR2 and LR2 01:27:42 Senior pilot: "captain, do we have a bow thruster?" 01:27:46 Senior pilot orders "full to port" on the bow thruster 01:27:53 MDTA relays: stop traffic at both ends of the bridge 01:27:55 Bosun reports he cannot open the anchor brake 01:27:57 Third engineer restarts the flushing pump 01:28:10 Bow leaves the channel, 656 feet from the bridge, grounding in mud 01:28:21 MDTA officers block both ends of the bridge 01:28:42 Bosun confirms the brake is open 01:28:49 Rate of turn reaches zero.
The Dali starts coming to port 01:28:57 Bow thruster. Second mate: "No, it's not working." 01:28:59 Sound of anchor chain running 01:29:09 IMPACT. Starboard bow strikes Pier 17 at 6.4 knots 01:29:15 Span 18, with four vehicles on it, begins to collapse 01:29:22 Pier 17 collapses 01:29:24 Span 20, two vehicles, collapses 01:29:27 Span 21 collapses 01:29:28 Span 22 - the inspector's vehicle - collapses 01:29:37 Pilot-in-training calls the Coast Guard: bridge down, people possibly in the water At the moment of impact, the seven workers were on their break, sitting in their vehicles on spans eighteen and twenty. They were never told the ship was coming.
The inspector had been walking the bridge to check drying cement. He heard what he called a crumbling thunder noise, and ran north. He reached span twenty-three before the span he had been on fell. Twenty-eight seconds after the impact, the pilot in training called the Coast Guard.
One worker got out through the open window of his vehicle, swam to floating debris, and held on until an MDTA police boat pulled him out at five to two. The tug the pilot had called was the first vessel on scene, at one forty. The first Coast Guard boat arrived at about one fifty-one. The six other workers died.
The search went on until twenty-seven minutes past eight that evening, when the Coast Guard turned it into a recovery. Aboard the Dali, one of the twenty-three people on board had a minor injury.
Thank you for joining us. My name is Jennifer Homendy, and I'm the chair of the National Transportation Safety Board. Normally, our investigator in charge, his name is Marcel Muise, M-U-I-S-E, his first name is M-A-R-C-E-L. Marcel Muise is our investigator in charge for this investigation, but just given that he's not on scene today, it's very early, I've asked that he remain at the command post to continue what he is doing so that I can brief you on what we're doing so far.
Also with me is one of our newest board members. This is Alvin Brown, and this is his training launch. So the NTSB arrived on scene at 6 a.m. to investigate an accident involving a Singapore registered vessel with the name DALI, D-A-L-I, which made contact with the Francis Scott Key Bridge in Baltimore, Maryland at around 1:30 a.m.
this morning. The vessel is 985 feet long. It's a 95,000 gross ton container ship. I've seen information about crew members on board.
We still need to verify the numbers of crew on board and their status. Under our Memorandum of Understanding with the Coast Guard, the NTSB is leading this investigation. The Coast Guard will support this investigation. Our memorandum of understanding, for example, provides for when an accident involves another mode of transportation and other factors, the NTSB will lead that investigation.
Now I want to thank the U.S. Coast Guard. We have a very cooperative relationship with the U.S. Coast Guard.
I particularly want to thank Deputy Commandant for Operations, Vice Admiral Gauthier. I want to thank Admiral Gilbreth, who is Commander of the 5th Coast Guard District, and Captain O'Connell, who is the Sector Commander. Before I go on, on behalf of the NTSB, I want to extend our deepest sympathies to those who have been affected by this significant event. The NTSB, as I mentioned, does many significant transportation events, not just aviation.
We do accidents and incidents in marine safety as well, and of course with bridges and other highway infrastructure. And for this, there were many that were affected by this collapse and our deepest sympathies go out to the families, loved ones, and others who have been affected. I'm going to get questions on fatalities and injuries, which I'm not going to answer. That is not something that the NTSB answers.
I will refer you to local authorities on all of that information. What I can tell you is a search and rescue is still underway. So we are very hopeful and again our thoughts are with the families and their loved ones. Again we got here at 6 a.m.
and we are standing back to allow the Coast Guard and Search and Rescue to continue their search and rescue operations while we gather information from the command post. There is a lot of information that we can begin to collect. We have a team of 24 on scene, including Member Brown and me. The team of experts include experts in nautical operations, and what they're going to look This is the NTSB's own footage from the air, taken the day of the collapse.
The central spans lie across the Dali's bow. The ship carried fifty-six containers of hazardous materials, seven hundred and sixty-four tons, mostly corrosives and flammables, and batteries. Some were breached. The Dali could not be moved.
Its twenty-one crew stayed aboard, and the NTSB's investigators went to them, by police boat and up a rope ladder, in the rain. Many of the crew were still in the United States when the Board met, twenty months later. On the thirteenth of May, salvors used explosives to cut the collapsed spans off the Dali's bow. A week later she was refloated and taken back to Seagirt.
About fifty thousand tons of steel and concrete came out of the river, and on the tenth of June the channel reopened. Replacing the bridge is estimated at between four point three and five point two billion dollars. Now we have a recorders group. Which is responsible for locating, retrieving, and downloading any recorder or recorded information that may relate to the accident.
We do have the Voyage data recorder. They worked on that all day to validate that information. They also have a printout of the alarms. That's the log.
They still have to go back and look at that and validate that information at a later time. In addition to that, our survival factors group interviewed or discussed with the Maryland Transportation Authority Police the timeline of events that occurred around the time of the bridge strike. That two sets of information we're putting together in a timeline that we will release through our social media channels. But for right now, I'm going to ask Marcel to go through the Voyage Data Recorder information that we have to share with you, as well as some of the information that we gathered from the police.
Thank you, Chair. Information from the Dali's Voyage Data Recorder, or what we call a VDR, was successfully recovered on the morning of the accident by the U.S. Coast Guard. It was provided to the NTSB upon our arrival.
Approximately six hours of VDR data was provided to the NTSB. The recording included the time period from midnight to 6 a.m. By regulation, the VDR is required to record 30 days of history, and the NTSB is continuing to obtain more data. The time is expressed below as recorded by the VDR and converted to local Eastern Daylight Time.
All information is preliminary and subject to final validation. The VDR data is comprised of audio from the ship's bridge, as well as recordings from the ship's VHF or very high frequency radios. The quality of that audio varies widely because of the high levels of background noise and alarms. Additional analysis will be performed at the NTSB's lab to filter out the audio and improve its quality.
Additionally, the VDR recorded limited sensor data. An example of that data recorded includes the ship's speed, engine RPM, ship's heading, and rudder angle, as well as some alarm information. NTSB engineers are working to identify and validate all of that data. The VDR recorded the ship's departure from Seagirt Marine Terminal at approximately 1239.
It recorded the ship's transit outbound in the Fort McHenry Channel and the striking of the Francis Scott Key Bridge. By 1.07, the ship had entered the channel, and by 1.24, the ship was underway on a true heading of approximately 1.41 in the Fort McHenry Channel at a speed of over ground of approximately 8 knots, or 9.2 miles per hour. At 0124 and 59 seconds, numerous audible alarms were recorded on the ship's audio, bridge audio. About the same time, VDR sensor data ceased recording, and where the VDR audio continued to record using the redundant power source.
At around 0126 and 2 seconds, the VDR resumed recording sensor data, and during this time and there were steering commands and rudder orders recorded on the audio. At around 01.26 and 39 seconds, the ship's pilot made a general VHF radio call for tugs in the vicinity to assist. About this time, the pilot association dispatcher phoned the MDTA duty officer regarding the blackout. Around 01.27 and 4 seconds, the pilot ordered the Dali to drop the port anchor and additional ordered additional steering commands.
Around 1.27 and 25 seconds, the pilot issued a radio call over the VHF radio reporting that the Dali had lost all power and was approaching the bridge. Around this time, MDTA data shows the following also occurred. Their duty officer radioed two of their units that were already on scene due to construction on the bridge, one on each side of the bridge, and ordered them to close traffic on the bridge. All lanes were then shut down by MDTA.
Around 01.29, the ship's speed over ground was recorded at just under 7 knots, or 8 miles per hour. From this moment until approximately 01.29 and 33 seconds, the VDR audio recorded sounds consistent with the collision of the bridge. Additionally, around this time, MDTA dash cameras show the bridge lights extinguishing. Additional analysis of the VDR audio in comparison with other time sources will be needed to determine the exact time of contact between the Dali and the bridge.
At 1.29 and 39 seconds, the pilot reported the bridge down over the VHF radio to the Coast Guard. The ntsb will later convene a group of technical experts to review the entire vdr recording and develop a detailed transcript of the dialogue and the events and the event alarms as recorded a few areas of that I just want to clarify the data that we received from the coast guard which was they were able to obtain on the bridge by downloading the information from the vdr from midnight to 6 a.m that's a standard time frame they provide that immediately so we can see that time a time frame around when the accident or incident occurred knowing that we can go back and get the rest that there should be 30 days there so this is the immediate information that they give us but it's not I don't want anyone to think anyone anything was being held back that's That's very standard information. I do want to thank the Coast Guard for that because that was pretty immediate. It was done right away, and then they provided us with a thumb drive that we were able to evaluate back at our lab at headquarters.
And I'm sure you will have questions on that. I do want to also say I've seen a lot of comparison between the VDR and CVRs and FDRs or black boxes on commercial airliners. This is really a basic system. An FDR would give you a thousand parameters.
That's not this. VDR is basic. It is a snapshot of the major systems on a vessel, and we have long wanted more recording, more parameters to be recorded on a VDR. So that's hopefully something that we can provide.
And happy to answer more questions about that timeline, but before I do, I want to continue with what our team has done our survival factors group their whole role is to examine the response and so they were able to obtain dispatch logs from the Maryland Transportation Authority the Baltimore County Fire Department the Baltimore City Fire Department to begin to put together a timeline and they will be conducting interviews tomorrow including with a few people in the bridge area now we also have from our office of highway safety a bridge structures group many know that the bridge was built in 1976 it has three spans the main span is 1200 feet the entire bridge is 9090 feet in length the average annual daily traffic on the bridge is 30,000 seven hundred and sixty seven vehicles per day thirty thousand seven hundred and sixty seven vehicles per day the bridge is fracture critical it's a fracture critical bridge what that means is if a a member fails that would likely cause a portion of or the entire bridge to collapse. There's no redundancy. The preferred method for building bridges today is that there is redundancy built in, whether that's transmitting loads to another member or some sort of structural redundancy. This bridge did not have redundancy.
There are 17,468 fracture-critical bridges in the United States out of 615,000 bridges total, and that comes from the Federal Highway Administration. This bridge was in satisfactory condition. The last fracture-critical inspection was in May 2023, three we have not been able to go through that inspection and all the documents that but that will occur after we leave the on-scene portion but we've also requested all fracture critical routine and other underwater inspections of the bridge over the last decade once we receive that we will begin to go through all of those documents we've also requested information on peer protection on all MDTA that's Maryland Transportation Authority owned bridges they have four bridges where we would have they would have information on peer Aboard, the question was why a ship that had power at the dock had lost it in the channel. The crew did not know.
The investigators tested breaker HR one, and it worked. They waited, and days later it failed again. At the Board meeting you will hear how that search went. The NTSB's hazardous materials investigators and engineers, aboard two days after the collapse.
The forward container bays lay under the fallen truss. The voyage data recorder could not be downloaded on board. The NTSB took the unit to its manufacturer. Its bridge microphones had been mixed into a single channel, so voices, alarms and noise lay on top of one another, and only the bridge side of the telephone to the engine room had been recorded at all.
NTSB photographs (Flickr). The NTSB public docket for this investigation: 168 items.
Good afternoon. NTSB Chairman Jennifer Homendy will brief you today on the collapse of the Francis Scott Key Bridge. Good afternoon and thank you for joining us. Next week marks one year since the striking of the Dali container ship with the Francis Scott Key Bridge in Baltimore.
The bridge subsequently collapsed into the Patapsco River, killing six construction crew members and injuring another as well as one person on board the vessel. I want to once again extend our deepest sympathies to those who lost loved ones or were injured in this terrible tragedy. Today we're issuing four urgent safety recommendations to bridge owners, the Federal Highway Administration, the United States Coast Guard and the U.S. Army Corps of Engineers.
Specifically, we're urging 30 owners of 68 bridges in 19 states to perform a vulnerability assessment of their bridge's risk of catastrophic collapse from a vessel collision, determine whether they need to implement countermeasures to reduce vulnerability, report their findings to the NTSB, and, if warranted, implement a comprehensive risk reduction plan that includes, at a minimum, short- and long-term strategies to reduce the probability of a bridge collapse from a vessel collision. We're also urging the Federal Highway Administration, in coordination with the U.S. Coast Guard and the U.S. Army Corps of Engineers, to provide guidance and assistance to bridge owners on evaluating and reducing the risk of a bridge collapse from a vessel collision.
As part of our investigation, we completed a vulnerability assessment of the Francis Scott Key Bridge ourselves to determine how susceptible it was to collapse from a vessel collision, taking into account engineering and shipping advances since the Key Bridge first opened in 1977. this vulnerability assessment is essentially a mathematical risk model used to determine how susceptible a bridge is to collapse from a vessel collision and it's not new the american association of state highway and transportation officials or AASHTO developed and published the vulnerability assessment calculation for new bridges on the national highway system in 1991 in response to our investigation of the sunshine skyway bridge collapse in tampa bay florida the state of maryland was on AASHTO's executive committee at the time and served on AASHTO's highway subcommittee on bridges and structures which developed those standards in 1991 and revised them in 2009. Included in the 1991 standards was a recommendation from AASHTO that all bridge owners conduct a vulnerability assessment of existing bridges to evaluate the risk of catastrophic collapse in the event of a vessel collision and take action. AASHTO reiterated that recommendation to states again in 2009 and I want to read the quote from the AASHTO guidance in 2009.
All remaining existing bridges over navigable waterways with commercial barge and ship traffic should be evaluated using a vulnerability assessment in accordance with with risk analysis procedures contained in this guide. The vulnerability assessments would meet NTSB recommendations to AASHTO, FHWA, and other federal agencies for improved bridge safety based on previous vessel collision accidents involving bridge failures. AASHTO continues on. Based on the vulnerability assessment evaluations of existing bridges within the state system, A screening process based on the estimated annual frequency of collapse can be used to identify and rank high-risk bridges and to prioritize vulnerable structures for potential rehabilitation, retrofit, pier protection countermeasures, or replacement.
The Maryland Transportation Authority never ran the calculation on the Key Bridge, And as of October 2024, they still haven't on the Chesapeake Bay Bridge. Had they ran the calculation on the Francis Scott Key Bridge, the MDTA would have been aware that the bridge was almost 30 times greater than the risk threshold AASHTO sets for critical essential bridges. 30 times greater. And almost 15 times greater for Pier 17, which the DALY struck, as well as Pier 18.
What's frustrating is not only did MDTA fail to conduct the vulnerability assessment on the key bridge, they did not provide, nor were they able to provide, the NTSB with the data needed to conduct the assessment, including the characteristics of vessel traffic passing under the bridge, vessel transit speeds, vessel loading characteristics, waterway and navigable channel geometry, water depths, environmental conditions, bridge geometry, pier protection systems, and ultimate lateral capacity of the bridge piers we asked them for that data they didn't have it we had to develop that data ourselves with the help of our federal partners at the federal highway administration and I want to take a moment to thank the team at the federal highway administration for all their assistance on this investigation we conclude in our report that had the mdta conducted a vulnerability assessment of the Key Bridge based on recent vessel traffic, the MDTA would have been able to proactively identify strategies to reduce the risk of a collapse and loss of lives associated with a vessel collision with the bridge. Like the Key Bridge, other bridges throughout the United States were designed before AASHTO's 1991 guidance to understand the scope of that risk. We asked the Federal Highway Administration to identify bridges that cross navigable waterways and are used by ocean-going vessels like the Dali and gather information about protection devices in place for those bridges, like dolphins, like fender systems. We then narrowed that list based on when the bridge was built, whether it had a vertical clearance of at least 80 feet, and whether it had substructures such as piers in a waterway.
We also evaluated vessel traffic transiting under the bridges. We repeated the same process for bridges owned by the U.S. Army Corps of Engineers. And as a result, we identified 72 bridges in 19 states managed by 30 bridge owners that were likely not designed and built to AASHTO specifications.
Owners of four of those bridges performed a recent vulnerability assessment and are either implementing a plan to reduce their bridges vulnerability or will be doing so in the future. The remaining 68 bridges that have not undergone a vulnerability assessment based on recent vessel traffic have an unknown level of risk of collapse from a vessel collision, which is why we're recommending that those 30 bridge owners take action now frankly we've been sounding the alarm on this since the tragedy occurred and in testimony before the house transportation and infrastructure committee last April we need action public safety depends on it so the 30 bridge owners who will receive our urgent recommendations are the bay area toll authority cal trans the golden gate bridge highway and transportation district the u.s army corps of engineers the florida department of transportation the georgia department of transportation skyway concession company llc the louisiana department of transportation and development the new orleans public belt railroad the maryland transportation authority the massachusetts department of transportation the mackinaw bridge authority the new hampshire department of transportation the delaware river port authority the new jersey turnpike authority mta bridges and tunnels the new york city department of Transportation, the New York State Bridge Authority, the Ogdensburg Bridge and Port Authority, the Port Authority of New York and New Jersey, the Seaway International Bridge Corporation, the Thousand Islands Bridge Authority, the Ohio Department of Transportation, the Oregon Department of Transportation, the Pennsylvania Turnpike Commission, the rhode island turnpike and bridge authority the harris county toll road authority the texas department of transportation the washington state department of transportation and the wisconsin department of transportation now I want to emphasize because we don't want to see headlines naming a bridge of being at risk of collapse or imminent risk of collapse a risk level above the acceptable threshold doesn't mean a collapse from a vessel collision is an absolute certainty likewise a bridge design with a risk level below the acceptable threshold doesn't guarantee that a collapse from a vessel collision won't occur what we are telling bridge owners is that they need to know the risk and determine what actions they need to take to ensure safety again I want to reiterate our exact findings today and all four urgent safety recommendations verbatim for finding number one had the maryland transportation authority conducted a vulnerability assessment of the francis scott key bridge based on recent vessel traffic as recommended by the 1991 and 2009 American Association of State Highway and Transportation Officials Guide specifications, the MDTA would have been aware that this critical essential bridge was above the AASHTO threshold of risk for catastrophic collapse from a vessel collision when the Dali collision occurred finding number two had the maryland transportation authority conducted a vulnerability assessment of the francis scott key bridge using the american association of state highway and transportation officials method 2 vulnerability assessment calculation the mdta would have had information to proactively identify strategies to reduce the risk of a collapse and loss of lives associated with a vessel collision with the bridge. Finding number three, the 30 owners of 68 bridges over navigable waterways frequented by ocean-going vessels are likely unaware of their bridge's risk of catastrophic collapse from a vessel collision and the potential need to implement countermeasures to reduce the bridge's vulnerability. Urgent Recommendation 1 to the Federal Highway Administration.
In coordination with the U.S. Coast Guard and U.S. Army Corps of Engineers, establish an interdisciplinary team, including representatives from the Federal Highway Administration, U.S. Coast Guard, and U.S.
Army Corps of Engineers, and provide guidance and assistance to bridge owners on evaluating and reducing the risk of a bridge collapse from a vessel collision. Urgent Recommendation No. 2. The U.S.
Coast Guard and the U.S. Army Corps of Engineers is the recipient of Recommendation No. 2. Support the Federal Highway Administration in establishing an interdisciplinary team and provide guidance and assistance to bridge owners on evaluating and reducing the risk of a bridge collapse from a vessel collision.
Urgent Recommendation No. 3 to the 30 bridge owners. Calculate the AASHTO Method 2 annual frequency of collapse for the bridges identified in Appendix B of the report that we issued today, for which you are responsible, and inform the NTSB whether the probability of collapse is above the AASHTO threshold. If the calculations that you performed in response to the safety recommendation indicate that a bridge has an annual frequency of collapse greater than the AASHTO threshold, develop and implement a comprehensive risk reduction plan that includes, at a minimum, guidance and assistance from the Federal Highway Administration, U.S.
Coast Guard, and U.S. Army Corps of Engineers interdisciplinary team. And the fourth recommendation, develop short and long-term strategies to reduce the probability of a potential bridge collapse from a vessel collision. Now, a few things about the status of the investigation itself.
We're releasing over 1,000 pages of investigative material in the public docket today, including our bridge factual report and some interviews. Next week, we intend to release the hazardous materials, meteorological and survival factors factual reports as well as a study conducted by our office of research and engineering on vessel size increases and associated safety risk in the next few weeks we intend to publicly release the voyage data recorder audio transcripts and associated data we're still finalizing the engineering nautical operations and anchorage factual reports will then be begin working on our analysis and developing our findings our probable cause and our safety recommendations with a final report released this fall now with that I will take some questions please raise your hand I'll call on you please state your name and your affiliation yes so these bridge owners need to be looking at recent vessel traffic things have changed, things have changed over time. Vessels have gotten bigger, heavier. At one point in the 1950s, we had vessels that had just 800 containers on them.
Now we're talking 24,000 containers. So they need to take a look at specific measures that are included in the AASHTO guidance. So yes, MDTA would have known the risk and could have taken action to safeguard the Key Bridge. Had they done that the collapse couldn't it could have been prevented yes the question is whether the 30 bridge owners that were issuing these recommendations do whether we believe their risk assessment will show that they're above the AASHTO threshold we don't know that that is something that this is why we We are urging those bridge owners to take action.
We're hoping it's very few, but we don't know that at this time. We believe they don't know that, and they need to determine what the risk is and start to put in those protective measures if warranted. One thing I do want, back to your question on could they have taken action, would have prevented it, this is not new. They could have been evaluated, MDTA could have done this evaluation numerous times over the past several decades they were it was recommended by AASHTO in 1991 it was recommended by AASHTO in 2009 they were part of that subcommittee and issuing those recommendations and they especially should have looked at the change in vessel traffic as certainly after the 2016 expansion of the Panama now yes so the question is the vulnerability assessments and how MDTA had not done these vulnerability assessments it was a recommendation from AASHTO in 1991 and again in 2009 as part of our investigation we asked had you done these vulnerability assess this vulnerability assessment on the key Bridge?
The answer was no. We then asked, are you doing this vulnerability assessment on the Chesapeake Bay Bridge? The answer is no. They have not.
Yes, sir. Thank you. The question is on the follow-up and urgent recommendations. When we issue urgent recommendations, we are saying there is a safety deficiency here, a potential safety risk, and you need to take immediate action.
So we will follow up with all of the bridge owners over time. We will follow up with federal highways. We had a briefing for federal highways today. I also called the state of Maryland to make sure they knew that we were issuing this, as well as several others.
So we expect action. And we have an entire team that follows up on those recommendations and will do so yeah the question is on did MDT is the Chesapeake Bay Bridge on the list of 68 bridges and its bridges and bridge spans the answer is yes the east and westbound part portions of the bridge are on the list of 68 and then the question is about their vulnerability assessment and conducting the vulnerability assessment and we we asked MDTA are you doing it in writing as of October they stated no certainly if they build a new bridge they will have to but as of the existing bridge we know that they have not done that calculation that calc that vulnerability assessment takes a long time there's no reason why they shouldn't have done it before now it shouldn't take an urgent safety recommendation to get action and we expect that to be done now and we'll follow up sure yes sir yeah the question is about concerns over safety and driving over the Bay Bridge I also drive over the Bay Bridge at times I would say the reason we are issuing urgent safety recommendations is we don't want this to occur certainly the same type of traffic goes under the bay bridge but at higher speeds and so what we are trying to do is prevent something in the future that is always what we're trying to do in issuing our safety recommendations in this case they need to know the risk and take action it doesn't mean there is a risk there they just don't know right now so they need to determine that and do some work is this something that drivers should take into consideration I mean drivers have to make their own decisions uh especially uh you know when it comes to their day-to-day travel yes ma'am uh have I spoken with governor uh Wes Moore about the challenges with mdta we our investigative team has worked well with mdta throughout the investigation they have gotten a lot of information from them if they didn't have the information to provide so it wasn't that they were withholding the information but they didn't have the data that needed to go into that calculation why that is is another issue they should have had that data we did the work but they have worked well with our team yes sir and then I'll go over here does MDTA have the data to do a full risk assessment of the Chesapeake Bay Bridge they've certainly had enough notice to go and get that data together this is part of our recommendations where we are asking federal urging Federal Highway Administration the US Coast Guard and others to work with the states to help them do that so hopefully they'll be able to take action but this is a great question for mdta on what they do have available for the chesapeake bay yep and that testimony was before house transportation and infrastructure committee uh you know their authority I think is the is I I don't know the answer to their authority we will get back to you on that they did not have the authority at the time federal highways administration also currently doesn't have the authority to mandate that that risk assessment and those changes for those older bridges prior to 1991 but what I did testify to at that time is that bridge owners need to take action now and not wait and then yeah we're what were we surprised by the numbers uh I I can say yes we were very surprised that they were so high 30 times great almost 30 times greater than the threshold that AASHTO sets and uh 15 times for pier 17 and pier 18 uh that's that was a surprise to all of us but you know it's something that MDTA could have known and should have known and why is it more important you asked it's important to understand risk so that you can take action now implement short-term and long-term strategies to ensure public safety last question they might want to where they there was a quote somebody read about a response on pier protection and about how it applies to new bridges that 1991 they might want to read their own guidance they were on the AASHTO executive committee in 1991 and they were on the subcommittee that developed the 1991 guidance and the 2009 update it says very clearly on like page three you should do the same calculation and risk assessment and put protective measures in place for your existing bridges before this guidance came out so There's no excuse. Thank you so much.
Washington, the eighteenth of November, twenty twenty-five. The Board met in public to adopt its report. Its staff presented the investigation first, in about an hour. It is played here as they gave it, with their slides and with the camera recordings they showed: an infrared camera of the collapse, and the last vehicle to cross.
The presentations will begin with an investigation overview by the Investigator In Charge, Marcel Muise, Mr. Muise. Thank you, Mr. Curtis.
Good morning, Chairman Homendy and members of the board. This morning, staff will present our investigation into the contact of the container ship Dali with the Francis Scott Key bridge which occurred on March 26, 2024. In addition to those who are participating in today's meeting, I'd like to acknowledge the staff noted here for their support and assistance during the investigation and report development. I'd also like to acknowledge the staff noted here, who facilitated this board meeting.
Parties to the investigation are listed here, and we thank them for their assistance throughout the investigation. Substantially interested states are listed here. We also thank them for their assistance. The Dahli was a 984 foot long Neo-Panamax container ship, built in 2015 in Ulsan, South Korea.
The ship was operate the ship operated in the container liner trade between Asia and the US East Coast. The Singapore flagship was owned by Grace Ocean, operated by Synergy Marine Group, and was classed by Nipong, Kaji, Kyokai, also known as Class ANK. The Francis Scott Key Bridge carried Maryland Route 695 over the Patapsco River, from Baltimore to Dundock. The bridge is owned and operated by the Maryland Transportation Authority, and open to traffic on March 23rd, 1977.
On the morning of March 26th, a crew of 7 highway workers and one inspector were working on the bridge, repairing potholes. The Dali arrived in Baltimore at the Secret Marine Terminal shown here on the north side of the harbor on the morning of March 23rd. Cargo was completed on the evening of March 25th. The crew completed pre-departure checks before 2 pilots from the Association of Maryland pilots boarded the ship shortly after midnight.
The ship was assisted off the pier by 2 harbor cyst tugs at 036. This chart shows the Fort McHenry Channel. And Dali's outbound passes towards the bridge. The channel is 700 feet wide with a base course of 140.
The channel has a projected depth of 50 feet, and Dali's underkill clearance was about 10 feet. The Curtis Bay Channel intersects the Fort McHenry Channel about a half a mile north of the Key Bridge. Environmental conditions were favorable, and the accident occurred in darkness. This graphic displays the ship's power management system.
Glowing yellow parts represent online machinery or live electrical circuits. The Dahli was propelled by a single, slow speed, 57,000 horsepower diesel engine, which was directly connected to a propeller, a vessel's rudder, was moved by Rams, and up to 3 steering pumps. The ship's electrical power was supplied by 4 diesel generators. The diesel generators were connected to a high voltage main electrical bus that directly powered certain shipboard equipment, including the main engine lubricating pumps, the ball thruster, and refrigerated containers.
The Dali had a low voltage bus, which was powered from the high voltage bus, through a pair of redundant stepped down transformers, depicted here as TR1 and TR2. The low voltage bus supplied electrical power to Dali's remaining equipment and services, including the steering gear, managing cooling water pumps, fuel oil pumps and vessel lighting. The vessel was also equipped with an emergency diesel generator, which was designed to start automatically following a blackout and supply power to the emergency bus and some critical systems. The components and circuits shown here that are glowing yellow show the configuration of the vessel as it got underway prior to the accident.
Generators 3 and 4 were running, empowering the vessel. The bow thruster was on, but it was not being operated. The low voltage power was being supplied from step down transformer number one. About 0108, the ship entered the Fort McHenry Channel.
The senior pilot let the assist tugs go, and as the ship lined up in the channel, he turned the con over to the pilot in training. Speed was then increased to slow ahead. At 0 125 as the ship approached the intersection of the Curtis Bay Channel with the Fort McHenry Channel, breaker HR1 unexpectedly opened. The ship and the ship experienced a low voltage blackout.
As a result, the vessel lost steering, the ability to operate the bow thruster and most of the vessel's lighting and equipment essential for operations. Eight seconds later, the cooling water pump is essential for the main engine to operate shut off due to the low voltage blackout. Loss of the cooling water pressure triggered an automatic manage shutdown, causing the vessel's propeller to come to a stop. The main engine, as well as the balance thruster, remain off throughout the remainder of the casualty.
At 125 and 58 seconds, almost a minute after Breaker, HR one unexpectedly open, causing the blackout. The vessel's engineering crew manually closed breaker HR1, NLR1, restoring low voltage power. Much of the equipment that had shut down with the initial loss of low voltage power began to automatically restart, including most of the vessel's lighting and steering gear pumps. The electric pumps supplying the fuel to generators 3 and 4 was not capable of restarting automatically, following the restoration of power and remained off.
To restart this bump. A crew member had to do so manually from a local station. Generators 3 and 4 remain running by consuming the remaining fuel in the supply line. The ship was closing with the bridge at 8.6 knots.
The vessel developed a starboard rate of turn of 4.5 degrees per minute, and the senior pilot gave a port 20 degree rudder command. He also called this dispatcher by cell phone and requested the bridge be close to vehicle traffic. He then called for tug assists by radio. Sensing the loss of power to the emergency bus, the vessel's emergency diesel generator automatically started and powered the emergency bus at 126 and 10 seconds.
For mercy lighting around the vessel came back on. That's the fuel pumps for generator 3 and 4 had still not been mainly restarted. What fuel remained in the supply line was insufficient to keep the 2 generators running, and the generators began to stumble. Sensing the underperformance of generators 3 and four, the vessel's automated power management system automatically started standby generator, number two.
66 seconds after the low voltage power was initially restored, and before generator 2 could come up to speed and connect to the high voltage bus, the power management system disconnected generators 3 and 4 due to their inability to maintain a rate of speed to produce a submission power. This resulted in a 2nd blackout, this time both the high voltage buses blacked out. The emergency generator continued operating, empowered the emergency bus through the 2nd blackout, which supplied power to some of the vessel's lights, navigation equipment in a single steering pump. Three seconds later, at 127 and 7 seconds, generator 2 reached a rated speed, and the power management system automatically connected it.
Repowering the high voltage bus. One diesel generator alone could run all of Dali's power needs at this time. Generators 3 and 4 remain running in a degraded state and were unavailable to be connected. On the navigation bridge, the pilot ordered the port anchor let go, and increased the rudder command to Harport for 35 degrees.
At 127 and 36 seconds. The vessels engineering crew manually close Breakers HR2, and LR2, restoring power to the low voltage bus. This time through Stepdown Transformer number two. Again, similar to the recovery from the initial underway loss of power, much of the equipment that had shut down due to the 2nd loss of power began to automatically restart, including most of the vessel's lighting and 2 additional steering homes.
Unlike the fuel pump for generators 3 and four, which required a manual restart, January 2's fuel pump was set to automatically restart following the restoration of power. The ship was now on a heading of 155, 1200 feet from the bridge and closing at 7.5 knots. The runner was hard over, which had little effect without any propulsion. The right southbound lane of the bridge had previously been closed, and MDTA officers were stationed on either end of the bridge to assist with traffic.
About this time, they were told of the emergency and instructed to close both ends of the bridge to all traffic. About a minute before the contact, the crew mainly restarted the fuel supply pumps for generators 3 and four. The generators return to a normal speed. Displayed as the configuration of the system, when the ship contacted the bridge, at 129 in 9 seconds.
So Dali's bow contacted Pier 17 at 6.4 knots. The A-frame columns collapsed. This infrared camera looking north, captured spans 17, and the main span, span 18 collapsing, spans 19, 20, 22, and 21 fall. The last southbound vehicle clear spans 17, 31 seconds before it collapsed.
Shown here as the last vehicle to safely cross the bridge in the left lane. Dali can be seen on the right, as indicated by the Yellow Circle seconds before the 2nd blackout. Although vehicle through traffic was stopped, the 7 highway workers fell in their vehicles into the water. The inspector, who was out of his vehicle and walking the length of the bridge, ran to safety on the north side as the bridge class behind him.
One crew member on board Dali was injured by falling debris. An MDTA police boat rescued one seriously injured highway worker who had escaped from his truck. The remaining six fatally injured workers were recovered over the next several days. All were found in their vehicles.
Shown here is an extract from the dash cam of the last southbound vehicle to safely cross the bridge. Traffic can be seen stopped by MDTA officers on the opposite side by the time this truck reached them. Staff believes the following items were not factors in this accident. The environment or waterway conditions, the vessel's complement, and mariner credentialing.
The impairment of the Dali crew or pilots due to alcohol or other tested for drugs, fuel quality or the switchover of fuels. The ship's ability to get underway after an import blackout, and bridge construction with non-redundant steel tension members. Staff will discuss the following safety issues. The improper placement of wire labeling, banning on terminal connection wires.
The lack of specific guidance for inspecting terminal connections. The configuration of machinery and electoral systems needed to prevent the loss of propulsion. The lack of effective means of emergency communications to warn motorists and notify highway workers. Inadequate standards for marine safety management systems.
The inadequate standards for the specifications and performance of voyage data recorders. The increasing vessel sizes and traffic destiny in US ports. And the vulnerability of bridges over Napula waterways to strikes by large oceangoing vessels. This concludes my presentation, Engineering Group, Engineering Group's my presentation, Engineering Group, Engineering Group's co-chair, Mr.
Janet Aloni, will now discuss engineering aspects of this accident. Thank you, Mr. Muise. In this presentation, Ms.
Lamb, Mr. Barnum and myself, we'll discuss the engineering related findings of this accident, including the causes of the two underway vessel power losses. It's part of the post accident investigation, the engineering group focus efforts on determining why HR1 unexpectedly opened, causing the initial underway, low voltage blackout. After several weeks of electrical examinations and troubleshooting, a loose signal wire associated with breaker, HR one was discovered.
This wire referred in this presentation, and in the giraffe report is wire one, was found to be loosely connected to an electrical connector, identified as terminal block 381. creating an intermittent electrical connection. We will now play a short animation that discusses the control wiring and terminal blocks aboard the Dali. The Dali electrical system distributes power and control signals throughout the vessel.
The control circuits contain hundreds of terminal blocks that organize thousands of wires. The wires on the Dali were terminated with metal sleeves called ferrels that allowed for easier assembly into the terminal blocks. Each wire was identified with a labeling band. This image shows several terminal blocks on the Dali with wires connected.
To assemble a wire into a terminal block, a tool inserted into a side port opens a spring clamp, which allows the wire's feral to slide into place. Removing the tool closes the spring clamp, securing the faro firmly against the terminal block's internal conductor bar. Labeling bands identify wires and are typically positioned on the wire insulation. However, many labeling bans on the Dali wires were placed partially on the ferrels, which increased the ferrels overall circumference.
As a result, during vessel construction, some of the ferroes could not be fully inserted in the terminal blocks, including the ferro on wire one from terminal block 381. On that wire, the labeling band prevented full insertion of the feral. So the spring clamp gripped only the feral's tip, resulting in an inadequate connection. Due to this unstable connection, over time, the feral on wire one slipped out of the spring clamp to rest atop the spring clamp face, resulting in a precarious electrical connection.
When a gap occurred between the feral and the spring clamp face, the electrical circuit was interrupted, leading to a blackout on the Dali. Staff found that the initial March 26, low voltage blackout, was caused by Wire 1, electrically disconnecting from Terminal Block 381 within the HV Switchboard, which resulted in high voltage breaker, HR1, opening, interrupting power to step down Transformer, TR1, and the LV bus. Further, staff believes that the position of the wire label banding on the feral of terminal block 381s, wire one, prevented wire one from being fully inserted into the terminal block spring clamp gate, causing an inadequate connection, and leaving wire one loose, enrollment, to becoming electrically disconnected. Staff proposes one recommendation to HD Hyundai heavy industries, and one recommendation to Wago Corporation, and one recommendation to Class NK.
Synnergy, the vessel operator, required the crew to complete high voltage switchboard inspections periodically. However, the work instructions for these inspections did not provide practical guidance for inspecting the individual signal wires and terminal connections within the switchboard, including wire one. Wire 1 was one of thousands of signal wires within the switchboard and throughout the vessel, checking thousands of wire connections by hand would be extremely labor intensive, and would also prove operationally challenging, as the vessel's electrical systems would often have to be turned off, while crew members inspected the individual connections. Furthermore, continued manual manipulation of the small and delicate signal wiring and terminal connections could introduce additional risk due to human error and could lead to premature failure over time.
Infrared, thermal imaging, or thermography, is an inspection and maintenance technique, that allows inspectors to identify possible points of failure. They may not be visible to the human eye, without touching the electrical components being examined. It was not being used aboard the Dali prior to the accident. Thermography uses an infrared camera to observe the surface temperature of a wire.
It can be used to help identify inadequate termination of conductors, such as wire 1 in the terminal block 381, as well as overloaded circuits by detecting increased local temperatures and electrical systems. It can also help detect faults early before they come to serious problems. Infrared thermal imaging is used widely for inspections in the maritime shipping industry, and is a condition-based monitoring technique approved by various classification societies. The National Fire Protection Association, as well as Marine Insurance groups, recommend thermal imaging surveys of electrical systems, be conducted periodically.
Further, Wego Corporation, the manufacturer of terminal block 381, uses thermal imaging during their production and quality assurance processes to ensure that its components are not defective. Staff believes if infrared thermal imaging had been used to inspect wire connections within the HV switchboard, before the accident, as part of the Dali's preventative maintenance program, the loose signal wire may have been identified. Step proposes one recommendation to Class NK, and one recommendation to Synergy Marine Group. Mr.
Barnum will now continue. Thank you, Mr. Giannelloni. Modern oceangoing vessels are complex pieces of engineering.
They are essentially floating cities designed to spend years continuously operating in challenging environments, transporting goods and people around the world. Like most modern equipment, vessels are dependent on electricity to maintain their functionality. Therefore, an unexpected blackout has broad implications for the vessel. Although blackout events are rare, they do occur for various reasons.
Given the complexity of a vessel's machinery, recovery from an unexpected blackout is factored into vessel design. However, full machinery recovering can still be complicated and time consuming. When the Dali initially lost low voltage power, while underway, most of the vessel's lighting and equipment essential for operation were also lost. The vessel's alarm monitoring system did not provide the engineering crew members with any warnings or initiating alarms that alerted them of the impending blackout.
Despite this sudden blackout, which resulted in numerous alarms sounding immediately, simultaneously, and continuously, the crew members in the engine control room were able to determine relatively quickly within 58 seconds that breaker HR1 had opened, causing the low voltage blackout, and were able to manually restore power. Staff found that the loss of power to the low voltage bus led to a loss of lighting and machinery, including the main engine cooling water pumps and steering gear pumps, which resulted in a loss of propulsion and steering. Staff believes that the engineering crew's initial response to restoring LV power after the first underway blackout was timely. In the review of the Dali's machinery and electrical systems, the NTSB identified 4 safety concerns that, although not causal in the initial blackout, are related to preventing a loss of propulsion and recovering fully following a blackout.
First was the configuration of the main engine to shut down due to low cooling water pressure. This automatic shutdown was configured during the construction of the vessel to meet the classification society rules at the time. However, current classification rules no longer require this shutdown, and the main engine designer does not specify or encourage it to be an engine shutdown. For the crew of the Dali to effectively steer the vessel, the main engine had to be operating, rotating the propeller and providing wash across the rudder.
When the main engine cooling water pumps shuttle off, due to the initial underway blackout, the main engine automatically shutdown moments later and was not restarted. severely limiting the vessel's ability to maneuver. Due to the dependence on vessel machinery, with maintaining maneuverability, system redundancy is essential and is factored into vessel design. As cargo vessels evolve over time, it is important that technology keeps pace.
Staff found that the as built configuration of the Dali's main engine to automatically shut down due to low cooling water pressure met classification standards at the time the vessel was constructed. However, it endangered the vessel because it prevented the main engine from being available, following the initial underway blackout, thus reducing the vessel's maneuverability. Staff proposes one recommendation to Synergy Marine Group, and one recommendation to the U.S. Coast Guard.
The 2nd safety concern that, although not causal in the initial blackout was the use of the flushing pump as a fuel oil service pump for the 2 online diesel generators. Well, the Dali was in Baltimore prior to the accident, and during the accident events, diesel generators 3 and 4 were supplied fuel from a single standalone fuel pump, the fuel oil flushing pump. This pump shut off and stopped supplying fuel to the generators on March 25th, when a blackout occurred due to human error, while the vessel was alongside the dock. And then again, on March 26th, while the vessel was underway, following the initial underway blackout.
As a result of this insufficient fuel press supply, the online diesel generators began to stall and were automatically disconnected from the high voltage bus, which resulted in a 2nd vessel blackout on both days. The Flushing Pump was not capable of restarting automatically when power was restored and required a manual restart. Something that was not quickly done. According to the vessel's Classification Society, the operation of the pump as a fuel oil service pump did not meet classification requirements because it did not was not able to restart automatically.
Staff found that the 2nd underway blackout on March 26th and the 2nd import blackout on March 25th, during which both the high and low voltage buses were lost, were caused by insufficient fuel pressure to the online diesel generators, resulting from the inability of the flushing pump to automatically restart following a loss of power. Further, staff believes that the cruise operation of flushing pump as the service pump for the online diesel generators was inappropriate because the necessary fuel pressure for diesel generators 3 and diesel generator 4 would not be automatically reestablished after a blackout per the fuel systems design. Synergy provided technical oversight, assistance, and guidance to its vessel operators through several means. The Dali was equipped with a remote equipment monitoring system, which allowed synergy's technical superintendents and managers to monitor real-time vessel operations, data, and analytics.
Also, these synergy experts were in touch with the Dali's crew, at least daily, via email or phone. Further, a team of experienced synergy technical managers and superintendents provided oversight to synergies vessels through biannual vessel inspections. These comprehensive inspections lasted a week or longer and covered a broad range of areas and topics, including the vessel's machinery and electrical systems. Despite this, synergy was unaware that the flushing pump was being used as a standalone fuel oil service pump on the Dali and at least one other synergy operated vessel.
Staff found that synergy's operational oversight was inadequate because it did not discontinue cruise, ongoing use of the flushing pump as a service pump for the diesel generators aboard the Dali and at least one other vessel. Staff proposes one recommendation to synergy Marine group. The 3rd safety concern related to the recovery from a loss of power was the operation of the vessel's low voltage, step down transformer, high voltage breakers, and manual mode rather than automatic. The Dali's low voltage bus was connected to the high voltage bus via 2 redundant step down transformers.
The high voltage breakers, HR1 and HR2, which linked to these step down transformers, had 2 control modes, manual and automatic. Synergy left the configuration of these breakers to the vessel crew's discretion. As did the classification society of the vessel, and the original equipment manufacturer, who provided no specific requirements or guidance on which control mode should be normally used. In practice, the 2 control modes were used to assist the crew in seamlessly changing over transformers for routine maintenance or operational purposes, without having to black out the low voltage bus.
An ancillary outcome of operating both HR breakers in automatic control mode, which was tested and confirmed by investigators following the accident, was that upon an unexpected trip of the connected HR breaker, such as the Dali's initial underway blackout on March 26th. The vessel's other step down transformer would automatically connect after about 10 seconds, restoring power to the low voltage bus. During maneuvering situations, response time is critical to avoiding an accident. Therefore, vessel systems should be configured to ensure maximum redundancy and the quickest possible recovery from the failure of critical systems.
In this accident, the crew may have had critical systems available to aid in maneuvering sooner if the HR breakers had been an automatic. Staff believes that keeping the high voltage breakers control modes set to automatic rather than manual would not have prevented either underway blackout, but it would have shortened the duration of the initial underway blackout from 58 seconds to 10 seconds, providing more time for the crew to attempt to recover critical systems, such as propulsion, as the vessel approached the key bridge. Staff proposes one recommendation to Synergy Marine Group. Mr.
Giannelloni will now continue. Thank you, Mr. Barnum. The 4th safety concern, related to recovery from a loss of power, was the effect of the emergency diesel generator, radiator damper positions on the generator's ability to start.
The Dali was equipped with an emergency diesel generator able to power essential onboard systems during a loss of low voltage power. Regulations required the generator to be able to automatically start, empower the emergency bus within 45 seconds of the loss of normal, low voltage power. However, during the accident, it took 70 seconds. For the generator to automatically start and power the emergency bus.
It had to be in standby start configuration, something that the crew, in pre departure paperwork, confirmed to investigators following the accident. Additionally, once the start sequence was initiated, for the generator to successfully start, the radiator damper, which was opened and closed automatically, by means of a mechanical actuator, had to be fully open. The position of this damper was relayed to the starting controls of the generator by means of a limit switch. If the limit switch did not indicate fully open, the generator would not start.
Staff found that it is likely that the emergency diesel generators failure to connect and power the emergency switchboard within 45 seconds, as required by international maritime organization regulations, was due to the emergency diesel generator, radiator damper, actuators, limit switch, not indicating open in the required time. due to unknown circumstances. Step proposes one recommendation to Synergy Marine Group, and one recommendation to Class NK. This concludes the engineering group's presentation.
Ms. Quinn will now discuss nautical operational aspects of the accident. Thank you, Mr. Ginalone.
This presentation will address the nautical operations group investigative findings. Wire one, the NTSB found, was one of many signal wires in the high voltage switchboard. Its label band covered the blue collar of the ferrule, so the ferrule could never be pushed fully into the spring clamp of terminal block three hundred and eighty-one. The clamp held only its tip.
The NTSB materials laboratory's photographs follow. NTSB Materials Laboratory Factual Report 24-080 (docket item 26). NTSB Engineering Factual Report (docket item 23). This presentation will address the nautical operations group investigative findings.
This is a photo of the Dali Underway, viewing the vessel's starboard side. The vessel's length overall, with 984 feet, and the vessel's beam was 158 feet. Dali's design was a split house configuration. The forward house contains the navigational bridge, and accommodation areas.
The aft house contains the engine room and exhaust stacks. The anchors are located forward on the bow and must be operated locally. This hallmarking indicates the bow thruster's location below the water. The graphic on the left shows the approximate locations of all personnel stationed on the navigational bridge.
The bridge team consisted of the master, 2nd mate, and helmsman. Two pilots were also on board for departure. The picture on the right is Dali's Bridge. The arrow points to the helm where the helmsman steers the vessel.
Despite the actions to control, the vessels heading, its path towards Pier 17 remained unchanged. The graphic on the left shows the vessel footprints from the 1st blackout to the pure contact. On the right, the waterway depths they're shown. The dark blue is the channel, surrounded by shallow areas beyond the channel's boundaries.
The vessel tended to starboard due to external forces acting on the vessel's hull, such as bank effect and the residual rate of turn from steering prior to the blackout. These forces were unable to be counteracted effectively, using available resources, as the propeller was not providing wash over the rudder. Staff found that the actions of the pilots in the bridge team, in response to the emergency, were executed in a timely manner, but the vessel's loss of propulsion close to the key bridge rendered their actions ineffective. On the left, there is a graphic comparing the size of a cargo vessel, which struck the key bridge in 1980 to the size of the Dali.
When the smaller vessel struck the bridge, it destroyed the pure fendering system and caused minimal damage to the pier and the vessel. The expansion of global trade is a major driver of increased vessel size. As the volume of goods transported across the ocean grew, the demand for larger vessels to accommodate the increase also grew. Operational environments exposed these vessels, import, and waterway infrastructure that was not designed to accommodate or withstand impact with the vessels of such size, pier protection and emergency shutdown procedures were discussed by port stakeholders as early as 2 decades prior to the casualty.
Staff found that larger vessels pose risks and challenges to maritime safety due to their reduced maneuverability and restricted waterways. The pilots had emergency shutdown protocol for the bridges in their waterway. The protocol was amended 23 days prior to the casualty. The active protocol instructed pilots to contact the Coast Guard as the single point emergency contact for shutting down bridges in the event of a potential strike.
However, during the emergency, the former plan was followed. The senior pilot called his dispatcher. Then the dispatcher called the MDTA in the Coast Guard. This system proved to be effective.
Staff believes that the quick actions of the pilots, their dispatcher, and MDTA to Stopbridge traffic prevented a greater loss of life from the bridge collapse. Staff proposes one recommendation to the harbor safety committee's national steering team. I will now discuss safety management system aspects of this investigation. A safety management system or SMS is a systematic approach to managing safety, including the necessary organizational structures, accountabilities, policies, and procedures, and effective SMS can help organizations reduce and prevent accidents, the loss of lives, time, and resources.
Proactive safety management, when done correctly, is predictive and designed to anticipate and address safety issues before they occur. And utilizes continuous data analysis to improve policies and procedures. In the maritime industry, the International Maritime Organizations, International Safety Management Code, or ISM code, establishes the standard for safety management systems. The code prescribes 6 functional requirements.
Under the code, vessel operators must define and document responsibilities and authorities relating to safety. They must develop detailed policies and procedures for key shipboard operations, including procedures for responding to emergencies and reporting accidents for all crew members to follow. Regular audits are required. In the aviation industry, the International Civil Aviation Organization established the framework for an aviation SMS.
The 4 elements are safety policy establishes senior management's commitment to continually improve safety and defines the methods and organizational structures needed to meet safety goals. Safety risk management determines the need for new or revised risk controls based on the assessment of acceptable risk. Safety assurance evaluates the continued effective effectiveness of risk control strategies and supports the identification of new hazards through data collection and analysis. Safety promotion includes training and communication regarding the SMS and other actions to create a positive safety culture within all levels of the workforce.
When comparing the 2 models, some elements of the 4 component aviation SMS framework are not included in the Maritime ISM code requirements. For example, safety risk management component of the aviation SMS code is a proactive obligation, while the ISM component for safety risk management is reactive. Proactive risk mitigation strategies in the SMS programs have been proven to increase safety by identifying hazards prior to their occurrence. The safety assurance element in the aviation model includes a change management model.
The ISM model does not. Monitoring organizational change management helps mitigate risks by assessing how changes may affect safety. The safety promotion component and the aviation model includes a detailed communication and training requirements associated with implementing an SMS. The Maritime ISM model does not prescribe a formal means of safety communication.
This means the ISM model does not require a model for how to communicate safety actions or changes in safety procedures. Because the ISM model does not specifically include this element, the possibility exists that mariners may not receive critical safety information. Staff found that the requirements of the ISM code includes some elements of a comprehensive proactive safety management system. However, the code does not fully encompass all 4 critical components of safety policy, safety risk management, safety assurance, and safety promotion.
Staff has proposed one recommendation to the U.S. Coast Guard. This concludes my presentation, Mr. Payne will now discuss vessel voyage data recorder related findings.
Thank you, Miss Quinn. This presentation will discuss issues related to the usage of voyage data recorders. Voyage data recorder known as a VDR is an electronic system installed on large vessels that continuously records navigational data, radar images, chart plotter information, basic engine operation, alarm statuses, bridge audio recordings, and VHF radio communications. VDR is mainly 3 parts.
A VDR cabinet, which is the VDR's main computer and storage system. It is inside the ship and contains at least 30 days of data. A VDR protective capsule is stored on the exterior of the vessel, which is designed to survive damage and sinking. It records a minimum of 48 hours of vessel data.
Last, newer ships are required to have a float free combination rescue beacon, which also functions as an additional VDR storage. During the investigation, we encountered several problems that made it hard to extract and use the VDR data efficiently. Key issues included, unrecorded data during the vessel's 1st underway blackout, the lack of recording of communications between the Dali's Bridge and the Dali's engine room, the digitally destructive mixing of recorded bridge audio channels, inadequate VDR playback software. The inability to download the full data set on board the Dali.
And the complex workflow for processing proprietary VDR data in the common formats. Overall, current VDR performance standards don't fully address how required software should function for users who review the data, which creates delays to investigation, and limits the usefulness of the VDR to make a timely impact on safety issues. VDR standards mandate that only bridge audio is to continue to be recording during a power loss. Under normal power, the VDR records information streams, such as bridge microphone audio, the ship's engine and rudder operation, GPS position, AIS, automatic identification information system, and chart plotter information.
However, when the ship blacked out, Only bridge audio was recorded. The other signals, like GPS position, were still sending data, but their own requirements state that they must remain powered by their own batteries during a blackout. The VDR did not record these powered signals. As a result, investigators had to rely on other external shore side data to plot the Dali's movements.
When asked about this issue, the manufacturer of the VDR stated that, quote, the other items are not recorded because they are not required to be recorded. During the accident, the Dali Bridge and the Dali's engine room teams communicated via an internal telephone system that stayed powered during the blackout. The VDR did not record and was not required to record this communications line. Only the Dali Bridge side of the conversation was captured by the microphones.
Because the crew had survived. Investigators were able to corroborate the details through crew interviews and these one-sided recordings. During the blackout, the VDR continued to record audio from the Dollies Bridge microphones, but the quality was degraded by numerous alarms that were triggered. VDR's record audio and mono format.
Mono mixes audio channels in a way that can't be reversed. This is called destructive mixing. Alternatively, stereo mixing mixes audio channels in a way that can be reversed. This is called nondestructive mixing.
The diagram shows the placement of the microphones on the Dali, and the color line show how the mics were connected digitally. Microphone sharing a color were mixed as mono. Because mono audio cannot be separated. Alarms near one microphone can obscure conversations elsewhere, making it difficult or impossible to determine what the crew said during an incident.
Current VDR standards allow destructive mono mixing. A lack of defined specifications for playback software creates challenges for safety related users. For example, the Dali's VDR, the software on the Dali's VDR, could not perform a full download of the VDR data set, forcing the removal of the VDR and for download at the manufacturer's facility. VDR software also lacks many basic features to review data.
The audio playback features primitive and does not allow the user to rewind in short increments. Recorded vessel data cannot be displayed in basic graphs either. Because the software lacked these features, analysts are forced to export the data, but the VDR standards do not define any acceptable methods to do this either. For instance, the Dali's VDR exports audio, in 10s of 1000s of short files, instead of a simple continuous recording.
The VDR standards allow these types of illogical protocols. Because of these issues, investigators must rely on alternative means of playing back VDR data. The practice has become so commonplace that investigative authorities around the world share and maintain a database of alternate VDR software. The standards for VDRs are 2 parts.
First, performance standards, which generally outline VDR specifications. And second, technical specifications, which address the technical details of the VDR systems. The International Maritime Organization, IMO, sets the overall VDR performance standards. The international electrotechnical commission, the IEC, develops the VDR technical specifications for VDR manufacturers to follow.
The IEC develops technical standards that the member states or countries agree meet the IMO standards. In the United States, the U.S. Coast Guard is the U.S. representative to IMO.
On the technical side, the American National Standards Institute, or Ansi, is the US representative to IEC. Staff has found the VDR was designed to shut off data during the blackout, despite the availability of important incoming data streams. Bridge and engine room communication were not required to be recorded. The VDR standards allow independent bridge audio recordings to be destructively mixed, which worsens the quality of the audio.
VDR standards do not define any performance requirements for VDR software to be useful in a real-world environment, and VDR users often seek alternate methods of playback. Staff has proposed one recommendation to the American National Standards Institute, and one recommendation to the U.S. Coast Guard. This concludes the recorder's group presentation.
The Bridge Structures group chair, Mr. Parent, will now discuss the bridge aspects of the accident. Thank you. Thank you, Mr.
Payne. My presentation will 1st discuss the urgent recommendation report and recommendations issued in March 2025, including the lack of vulnerability assessment for the key bridge including the lack of vulnerability assessment for the key bridge and the more widespread issue of the lack of vulnerability assessments for other bridges frequented by oceangoing vessels. Next, I will discuss the need for motorist warning systems on bridges. And lastly, I will address the highway workers on the bridge when it collapsed, and the need for effective and immediate communication.
The overall length of the continuous steel through trust bridge was 9,086 feet, and the bridge had a maximum vertical clearance of 185 feet within the main navigational channel over the Fort McHenry Federal Channel. The key bridge was designed according to the 1969 American Association of State Highway and Transportation Officials, or AASHTO, Standard Specifications for Highway Bridges. These specifications predated the regulatory requirements for bridge protection systems from vessel contacts. Despite not being a requirement, the key bridge was originally designed with pier protection systems for Pier 17 and 18, including 4 dolphins shown by the yellow circles, and peer fendering systems shown by the yellow rectangles.
However, the pier protection systems had not been evaluated to consider impacts by today's ocean going vessels. The bridge and pier protection were subjected to regular safety inspections in accordance with the national bridge inspection standards, and the most recent inspection prior to the collapse resulted in a satisfactory rating. As a result of the NTSB investigation and recommendations after the 1980 collapse of the Sunshine Skyway Bridge in Florida, the Federal Highway Administration, or FHWA, drafted a proposed design code to evaluate bridges for vessel collision, which led to the 1991 adoption of the AASHTO guide specification and commentary for vessel collision design of highway bridges. While FHWA requires that new bridges on the national highway system be designed to minimize the risk of catastrophic bridge collapse from vessel pollution.
They can only recommend these vulnerability assessments be performed on bridges designed before the release of the guide specifications. It's important to note that the intent of performing vessel collision vulnerability assessments on existing bridge systems is to identify structures that are particularly vulnerable to catastrophic collapse, thereby allowing bridge owners to be aware of the high risk safety needs, requiring immediate or short-term action, as well as information to prioritize the long-term needs for bridge rehabilitation or replacement. The guide specifications references 3 methods for conducting vulnerability assessments, method 1, method 2, and method 3. Bridges over navigable waterways with commercial barge and ship traffic should be evaluated using a vulnerability assessment in accordance with method two.
The Maryland Transportation Authority, or MDTA, had not performed the AASHTO method 2 calculations prior to the collapse of the key bridge to determine the bridge's vulnerability, as recommended by AASHTO and the guide specifications. As part of the NTSB's investigation, we performed the AASHTO method 2 calculations to determine vulnerability to collapse for the key bridge, and found that prior to its collapse, the key bridge was nearly 30 times above the AASHTO acceptable risk threshold. As a result of our vulnerability assessment for the key bridge, we were concerned there might be other bridges that could be vulnerable to catastrophic collapse from impacts by Oshikoing vessels. We worked with the FHWA and identified bridges across the nation that crossed navigable waterways used by oceangoing vessels.
Ultimately, we identified 68 bridges over navigable waterways frequented by oceangoing vessels within 19 states as having an unknown level of risk of collapse. In our March 2025 urgent recommendation report. We found that if the MDTA had calculated the risk of collapse for the key bridge prior to its collapse, the MDTA would have identified that the bridge's risk level was almost 30 times greater than the AASHTO acceptable risk threshold for critical or essential bridges. further.
The MDTA would have had information to proactively identify strategies to reduce the risk of a collapse and loss of lives associated with a vessel collision with the bridge. The 30 owners of the 68 bridges over navigable waterways frequented by oceangoing vessels are likely unaware of their bridges risk of catastrophic collapse, and a potential need to implement countermeasures to reduce the bridge's vulnerability. In that report, we issued 2 urgent safety recommendations to the FHWA, the US Coast Guard, and the US Army Corps of Engineers. These 2 recommendations called for the formation of an interdisciplinary team comprised of experts from the 3 agencies to provide guidance to bridge owners on evaluating and reducing the risk of a bridge collapse from vessel collisions.
We also issue 2 urgent safety recommendations to the 30 bridge owners to calculate their bridge's vulnerability to catastrophic collapse and inform the NTSB if their risk is above the AASHTO threshold. And if above, to develop and implement a risk reduction plan with guidance and assistance from the interdisciplinary team that includes short and long-term strategies to reduce the probability of collapse from a vessel collision. I am pleased to report that we have received positive responses from every recipient of the urgent safety recommendations. The next issue area I will discuss is the need for a motorist warning systems on bridges.
Since the 1970s, the NTSB has investigated multiple bridge collapses involving injury and death to motorists that were either on a bridge when it collapsed or drove into the void created after the collapse. Three examples are shown here, including the 1980 collapse of the Sunshine Skyway Bridge in Florida, the 2001 collapse of the Queen Isabella Causeway in Texas, and the 2002 collapse of the I 40 Bridge in Oklahoma. In 1983 in response to NTSB recommendations after the Sunshine Skyway Bridge collapse, the FHWA issued a technical advisory titled Peer Protection and Warning Systems for Bridges Subject to Ship Collisions. The advisory acknowledged the need to consider protection for bridge prayers, as well as warning systems to alert motorists in the event of a collapse.
AASHTO incorporated motors warning systems into their 1991 guide specifications. Technologies identified in the technical advisory were included in a motorist warning system installed on the repaired Queen Isabella Causeway Bridge after its collapse. The system included a continuous fiber optic cable for signal transmission, as shown by the arrows. In the event of a collapse, a loss of signal would be detected, and the motorist warning system would activate.
Primary motorist warning is accomplished through a series of flashing red traffic signals circled in yellow, which are configured to notify motorists who have not reached the site of the bridge collapse to stop and to allow those who have already passed the site to exit the bridge. Warning mechanisms marked by the yellow arrow includes signs alerting motorists when they approach the bridge, traffic gates, dynamic message signs, and preemption of nearby traffic signals. Staff found that in lieu of police officers or highway workers charged with traffic control and capable of quickly stopping traffic, motorist warning systems designed to warn and stop motorists from entering onto a bridge are a possible countermeasure that can be quickly implemented to save lives and may be a component of an effective bridge protection strategy. For this reason, staff proposes one recommendation to bridge owners with bridges above the AASHTO threshold, or who have not yet completed their method 2 calculations.
Staff also found that the owners of bridges over navigable waterways, frequented by oceangoing vessels, would benefit from updated guidance on motorist warning systems, including incorporation of hazard alert, and sentencing technologies capable of detecting errant vessels, and bridge movements that would indicate a need for a bridge closure, and systems that would both warn and prevent motorists from entering a bridge once a thread is detected. For these reasons, staff proposes 2 recommendations, one to AASHTO and one to the FHWA. My last issue area will address the highway workers that were on the bridge when it collapsed. There were 7 highway workers and one inspector on the key bridge performing roadway repairs as part of an MDTA contract.
Prior to the collapse, the inspector was walking on Span 22 near his vehicle, and the highway workers were on a break, and were all sitting in vehicles. Two of the vehicles were on span 20 and 4 were on span 18. Although unknown to the workers, spans 16 and 23 where the closest points of safety for them to escape to before the bridge collapsed. The shaded area shows the portion of the bridge that collapsed into the water below.
As a result of the collapse, the 7 highway workers, and all vehicles fell into the water, along with the collapsed section of bridge. Six of the workers were fatally injured, and one sustained serious injuries. The inspector was able to run to the safety of span 23 before the collapse. The highway workers on the bridge did not receive advance warning of the impending impact between the ship and the bridge.
The MDTA contract for the work being conducted included a traffic control plan that required the contractor to provide a means of communication to the MDTA police detachment as a safety requirement. The contract specified acceptable forms of communication, such as a mobile telephone, citizens band radio, or a portable two-way radio. Prior to the start of the maintenance activities, the inspector exchanged cell phone numbers with the MDTA police officers that were providing traffic control for the work being conducted, thereby meeting the requirements of the contract. Staff examined the timeline of events leading up to the workers becoming involved in the collapse of the bridge.
We found that 2 minutes and 25 seconds before impact, the pilot's dispatcher called the NDTA duty officer. to notify them of the need to shut down the key bridge. One minute and 16 seconds before impact, the MDTA duty officer radioed the police officers performing traffic control to shut down all traffic lanes. 48 seconds before impact, the police officers blocked all traffic from entering the bridge.
At 129-09 a.m. the starboard bowel of the Dali impacted pier 17. 13 seconds later, the pier collapsed and shortly after the other piers and spans collapsed. Despite previously exchanging cell phone numbers.
The police officers did not call the inspector to warn him of the Dali's emergency. Instead, one of the officers planned to drive to the workers' location on the bridge to advise them once he was relieved by another officer. Had the highway workers been notified of the Dali's emergency at the same time as the MDTA police officers, there would have been about one minute and 29 seconds to evacuate before Pier 17 collapsed. All of their vehicles were parked facing south within the closed right lane of the bridge.
Therefore, their likely route to evacuate from the bridge would have been to drive south, as shown by the arrow. Unknown to the workers, span 16 would have been the closest point of safety, which was 2928 feet away from the northernmost highway worker. The American National Standard Institute's standard A 1047 applies to workers engaged in construction, utility work, maintenance or repair activities on any area of roadway. This standard includes provisions for pre-job planning to determine appropriate needs, such as safety controls, equipment, and traffic control plans.
However, there are no anti standards for highway workers to receive emergency information before or during dangerous or life-threatening events within work zones. Staff found that had the inspector and highway workers been notified of the Dali's emergency situation about the same time the MDTA police officers at each end of the bridge were told to block traffic. The highway workers may have had sufficient time to drive to a portion of the bridge that did not collapse. Effective and immediate communication to evacuate the bridge during emergency is critical to ensuring the safety of bridge workers.
For this reason, staff proposes one recommendation to the anti A10 committee. Thank you. This concludes my presentation, the staff is ready to answer any questions you may have. Thank you very much, Captain Muise, uh, Mr.
Giannelloni. Mr. Barnum, Captain Quinn, Mr. Payne, and Mr.
Parent for your excellent presentations. We are going to take, and you know, I'm sorry, there's some issues with these streaming. So people who are tuning in virtually are unable to watch. So we're going to take a 20 minute break so that we can reset the system.
And so, I mean, we'll just do 5 after 11. So a little lesson. 20 minutes, and then we'll come back and deliberate. Thank you very much, and thank you for your patience, everyone.
And thank you again to the staff for NTSB Bridge Structures Group Chair's Factual Report (docket item 116). NTSB, Key Bridge post-collapse damage (docket item 121). NTSB Survival Factors Factual Report (docket item 136).
And thank you again to the staff for your excellent presentations. We're going to get into some of your work. We'll turn to board member questions now, focused on the major safety issues that we identified in the investigation. For the 1st round, we're going to discuss engineering.
In the 2nd round, we're going to cover ship handling and communications. In the 3rd round. We're going to focus on Bridge vulnerability and highway workers safety. In the 4th round, we're going to discuss voyage data recorders and safety management systems, we'll have a final round for any other questions we want to ask about any other safety issue or additional questions on the safety issues we discussed.
And the purpose of this discussion is to highlight those areas where we believe we can make the biggest difference to improve safety. So with that, I'm going to begin with a discussion, we're going to begin the discussion on engineering. And I'm going to start with Mr. Barnum.
And just for you all, our our investigators routinely accomplish the impossible. And this investigation is no different. Certainly our parties are also key to our investigation. The Dali is almost a 1000 feet.
And it's as long as the Eiffel Tower. is high, with miles of wiring and thousands of electrical connections, locating a single wire that is loose among thousands of wires, is like looking for a loose bolt in the Eiffel Tower. So, uh, Mr. Barnum, can you talk about uh, your work, certainly your work with a party, but the extensive and meticulous work, to find a loose wire, and you can have my entire 5 minutes, I see my clock, uh, wasn't started, you can have the entire time.
Thank you, chair. And, um, you are correct. This was an extremely challenging investigation. Myself and Captain Quinn were among the 1st people on board directly following the casualty.
That's where the work really began. But, you know, the nature of international shipping. This is rather typical, this type of vessel. The vessel was owned by a Singaporean company.
It was registered to a Singaporean flag state. It was managed by a company predominantly composed of Indian nationals, as well as the crew were from India. The vessel was built in Korea. The vessels classed in Japan.
The engine manufacturer, the license sewer, was a German company. The engine controls were a Konsberg company. In the accident, obviously, was in America. So that was the 1st challenge to overcome is setting up our parties, our groups.
We were able to do that, and it's really a testament, I believe, to our party system, which is crucial, which was crucial in this incident. Everybody within the party was extremely helpful and supplied expertise. So, um, that's his, that's that part. And then naturally we moved to the, uh, trying to determine why the vessel blacked out.
It was a mystery to the crew on board at the time. They were extremely helpful. Often in these types of casualties. The vessel was moved to a dock or it's, you know, it's sinks or is damaged, but in this instance, the crew remained on board, the vessel had to be continually manned and operated.
So they were there the entire time, they were able to assist us in our troubleshooting. Um, when we initially formed our group. We didn't necessarily have the appropriate people, but because we didn't know what happened. But as we narrowed our search into HR one, trying to determine why it unexpectedly opened.
We were able to coordinate with Hyndi-Heavy Industries, the manufacturer, the vessel, and the high voltage switchboard, and they were able to get us the technical experts that they needed. They face challenges getting their people here. But eventually we're able to do that. Another impediment to determining the cause of the blackout was the manner in which it failed.
This was an intermittent electrical issue, failure. So meaning it didn't fail all the time. Um, we saw in the animation that once the um, breaker opened and the wire became disconnected, um, again, reconnected. So, uh, following the blackout, we attempted to reclose HR1.
It actually did not reclose, most likely because the wire was disconnected at that time. So we ended up getting additional support from HHI, high voltage breaker experts. And when they came, we tried the test again and it worked. So we were chasing chasing the fault for a while.
We ended up having to leave the system configured the way that the system was configured during the casualty events. We set, we let it set for a couple days and sure enough, the fault occurred. The wire became disconnected again, and we came back on board and tried to identify why that happened. It took another team of specialists from Hyundai that came over and we hooked up specialized equipment to monitor the electrical outputs of the switchboard.
And we tested again the functionality of HR1 and other electrical circuitry. The fault didn't reoccur. The system worked. So again, we were left trying to trouble suit it.
We let it set again, and again, it failed a couple days later. Eventually, we were able to analyze that data that we had received from the specialized equipment that was hooked up and another visit. We were able to, with the help of naturally HHI, the crew, synergy, and our other parties, find this single, you know, loose signal wire in a cabinet that was not directly associated with HR1. It was actually in an ancillary cabinet, several cabinets away, just for convenience, most likely during construction that was the closest spot where they could connect these 2 wires.
But the HHI technician was checking each wire point to and he was able to identify that this wire had become disconnected and was loose. He reinserted the wire, and we tested the functionality to the breaker, and tested satisfactory, and we also, we simulated a disconnection. So we actually removed the wire while the breaker was closed and simulated a blackout. It occurred.
The same thing that occurred during the casualty events occurred again. The breaker open and the LV bus blacked out. So I hope that answers your question. of the complexity and the challenges that we faced and why it took us so long to determine the probable cause there.
we certainly feel that they should not have been using it. We also feel that synergy should have been aware that they were using it. And at the time, synergy did not have any policies or procedures related to the use of the flushing pump, and we have a proposed recommendation that states that they should, and should incorporate it within their SMS. Well, in fact, we had found in the investigation that they had likely been using it, the flushing pump for at least 7 months, but also synergy should have known it was being used, but the crew, I have some concerns, that how they would have known.
This was the 1st contract with the Dali for this crew, they did not indicate their awareness at all, that it shouldn't be used. There's no policies. There's no standards. And then the engineer, the chief engineer that preceded this crew also didn't know.
So I do have some concerns about that, but I'm running out of time. So very quickly, I will ask, now that synergy knows this was being used. They had a technical manager briefed the crew, right? Don't use it.
Are there any corporate wide policies or procedures saying don't use it. Have they written those? No. No, it's been 20 months, right?
I mean, that's the reason you're a party to our investigation. So you should take that action. It's been 20 months. We're not talking about a regulation.
We're taking talking about a corporate wide policy to stop using the flushing pump, which has no redundancy whatsoever. Sorry, I went over time memogram. Not a problem, chair, and I'm going to jump on that too. Thank you.
Now let's go to the night of the 26th. So the 1st blackout that night, how did the crew respond to that blackout? How did they identify the issue that caused the blackout, and how did they address it? after they identified it?
So, like we spoke to earlier, we feel like they responded in a timely manner, they were able to ascertain that it was just a low voltage blackout, not a complete vessel blackout, and they were able to manually close HR1 and LR1 to restore power to the low voltage bus. how quick did they do that? 58 seconds, 8 seconds with 100s of alarms going off. Yes, sir.
Was there anything that the crew missed that they stated in their stated policies or procedures that indicated they should have done in a response to the initial blackout, anything different? Uh, no, other than, uh, you know, we feel that the flushing pump should not have been being used. And there was nothing to in their SMS, indicating or provided to them, stating that it should not be used. Okay, now how about the 2nd blackout while underway?
How did the crew respond and was it appropriate and timely? Yes, the automated power management system, aided in the recovery, the 2nd blackout was a high voltage blackout, the power management system automatically connected the standby generator within a couple seconds. So HV power was restored extremely quickly. LV power was restored.
I think within 30 seconds. So quicker than the 1st blackout. Okay, so it was timely. Yes sir.
And for that configuration, was it appropriate? Um, No, the flushing pump is what caused the 2nd blackout, so no, it was not an appropriate configuration. Thank you. We keep hammering that home, don't we?
All right, thank you. Thank you, member Chapman. We'll be and coordination committee ever raised concerns about the vulnerability of the key bridge? Yes, in 2006, an MDTA representative had mentioned that the pier protection was inadequate.
Was any meaningful action taken? No. No. Um, MDTA states in their party submission, uh, the following.
The increased risk to bridges posed by vessel strikes does not come from any deterioration of existing infrastructure. The bridges are strong and resilient as ever, rather, the increased risk comes directly from the ever increasing size of commercial vessels. The reason why we look at bridges is because we look at everything that could have prevented a tragedy, which was the tragic death of several highway workers on the bridge. and the need to constantly evaluate what sort of, as a state, what sort of vessels are transiting underneath your bridges and act accordingly.
In fact, when I was there on scene, I noted, and I'm sure you all did too, that it seemed that the fender system and protection in place from a utility pole next to the Dali was more sufficient than what existed around the piers of the bridge. It was pretty extensive, probably because it was constructed under newer regulations at the time. with National Bridge inspection standards, the Key Bridge and its pier protection systems, we're subject to regular safety inspections. Mr.
Parent, what do these inspections look for? Essentially, they're looking for structural deficiencies that may affect the safety of the traffic on the bridge. and to identify any new changes to the previous inspection. When uh, Maryland was in compliance with Bridge and Inspect.
There was nothing structurally wrong with the bridge. What was the rating on them? Satisfactory? Satisfactory.
Does the inspection look at the probability of collapse from a vessel strike? No, it does not. Was Maryland aware that the blue Nagoya had hit Pier 17 in 1980? Yes.
Yes. Okay. And what was the difference between Blue Nagoya in 1980? And the Dali.
Well, the biggest factor would be the size. Um, the Dali is much bigger, much heavier, um, wider and longer, uh, will provide a lot more force to the pier than the blue Nagoya. Yeah, and, you know, I think that goes back to using some of your data and past incidents to inform some of these dolphins and the size of the dolphins in after the sunshine, Skyway Bridge collapse, and redesign and the size of the dolphins in Delaware, correct? That's correct.
Can you talk a little bit about the size difference? Sure. Yeah, in terms of, I get, the Francis Scott Key Bridge, where the 25 foot diameter dolphins, they were not compatible in order to. take a size of the Dali.
They were woefully inadequate. The 80 foot diameter dolphins in the Delaware Memorial Bridge. Depending on looking at the different aspects of the vessel itself, they will puncture a bowel in the vessel before striking a pier. And did the Dali even hit these dolphins at all?
any dolphin at all? They did not. Right? Yeah.
So placement and size, uh, here, uh, make a big difference. That's correct. Ms. Baldwin.
Yes, thank you, chair. And thank you for the extra time. Uh, so the bridges uh, that we have had reports that are over the threshold are the Walt Whitmiden and Betsy Ross Bridge in the New Jersey Turnpike, the Seaway International Bridge, Detroit Avenue, and Carnegie Carnegie Avenue Bridges in Ohio. The Vincent Casiano, Newark, Bay Bridge, the Huey Pilong, Greater New Orleans, Crescent City Connection, Gramercy, and Sunshine Bridges in Louisiana, and both spans of the Chesapeake Bay Bridge.
Great. Thank you very much for that. I appreciate that. Figures, NTSB MIR-25-40.
Bye. All right, chair, all in favor. Thank you, Mr. Curtis, will you please read the proposed probable cause?
Staff proposes the following probable cause. The National Transportation Safety Board determines that the probable cause of the contact of the container ship Dali with the Francis Scott Key Bridge was a loss of electrical power, blackout, due to a loose signal wire connection to a terminal block stemming from the improper installation of wire label banding, resulting in the vessel's loss of propulsion and steering close to the bridge. contributing to the collapse of the key bridge and the loss of life was the lack of countermeasures to reduce the bridge's vulnerability to collapse due to impact by oceangoing vessels. which could have been implemented if a vulnerabilities assessment had been conducted by the Maryland Transportation Authority, as recommended by the American Association of state highway and transportation officials.
Also contributing to the loss of life was the lack of effective and immediate communications to notify the highway workers to evacuate the bridge. Chair. Thank you, and member Graham has an amendment. I'll recognize member Graham.
Thank you, chair. I move to amend the probable cause to add a additional contributing. This would start. I won't read the whole thing, but I'll start at the end of the 1st sentence where it says close to the bridge, period.
I would like to add, contributing to the crews inability to recover propulsion from the loss of electrical power was the limited time available due to the Dali's proximity to the bridge, period. And then the other contributing would start after that. Thank you very much. Is there a second?
Second for the purpose of discussion. Recognizing membergram for the start of the discussion. Thank you, chair. I just, with all my discussions with the team, it just, they seem to really harp on the point that the cruise actions were as timely as they could be.
And they were appropriate and also impressive, considering the circumstance, but they're just because of the proximity to the bridge, they just couldn't get everything started back up again and avoid from hit the bridge. So I think this contributing factor states that point, which I personally believe you have told me over and over again, so I think it really fits in the probable cause. Thank you. Remember Chapman?
No discussion. I would like to hear what the staff has to say. Thank you. Okay.
All right. Yeah. Steph, can curse with you a minute. No further discussion.
Thanks. Okay, great. We'll go to a roll call vote. All right, this is a vote in favor of the amendment to the probable cause proposed by membergram.
Membergram. Hi. Remember Chapman? Hi.
Member and man by proxy? Remember, Grant, that would I, sorry. And Chairman Chair Hondy. Hi.
All right, chair, all in favor. Thank you. Is there a motion to adopt the probable cause as amended? So move?
Second. Okay. And council, you will call the roll and tally the book. Yes, board, this is a vote in favor of the probable cause as amended.
Member Graham? Hi, member Chapman. Hi. Member Inman by Proxy.
Hi. and chair homody. Hi. All in favorite chair.
Great. Mr. Curtis, will you please read the proposed recommendations?
The probable cause, as adopted: a loss of electrical power, due to a loose signal wire connection to a terminal block, stemming from the improper installation of wire label banding, resulting in the loss of propulsion and steering close to the bridge. Contributing to the collapse and the loss of life: no vulnerability assessment of the bridge by the Maryland Transportation Authority, and no effective way to tell the highway workers to leave. The Board's March twenty twenty-five report named sixty-eight bridges, owned by thirty authorities, in nineteen states, that may never have been assessed against the ships that use them now. By November, every owner had replied.
Some had found their bridges above the threshold, among them both spans of the Chesapeake Bay Bridge. The replacement is designed as a cable-stayed bridge, redundant by design, with two hundred and thirty feet of clearance and piers set further from the channel, protected to current standards. It is expected to open in late twenty thirty. Are there any final remarks from board members before I close?
Just briefly, chair. I want to begin by, again, expressing my deepest condolences to the families of the individuals who were lost, or were harmed in this tragedy. Your loved ones should still be with us today. Please know that as a result of this investigation, we will continue to advocate for the full implementation of all the safety recommendations adopted today.
Our goal is to ensure that no other family must endure the pain and the loss that you have experienced. Our thoughts will remain with each of you. And I also want to commend the NTSB team for their exceptional work on this investigation. I am just truly impressed with our colleagues' results and the multimodal collaboration.
As board members, we all appreciate your commitment to safety, and we are especially grateful for your efforts during the challenging times you faced over the last month and a half . We thank you for that. Thank you, chair. Thank you very much.
I would like to start by thanking member Graham, member Chapman, and member Inman, for their preparation in advance of today's meeting. As I stated at the start of the meeting. This was a complex investigation. We all too often get pushed in the early stages of an investigation.
In fact, while we are still on scene, to determine the cause of an accident, or in this case, the cause of the 2 blackouts that led to the loss of power, propulsion, and steering on the Dali. Our investigations take time. Our findings in this investigation are a perfect example of why. Frankly, you want to know what happened and then it's right.
Identifying that one signal wire among thousands of others in the main switchboard, and determining it was disconnected because the label on it, prevented the wire from being fully inserted in the terminal block, was no small task. It took weeks of meticulous work, and a great deal of expertise. I certainly want to thank Mr. Barnum for that.
You, along with the parties, to our investigation, including Hyundai, Heavy Industries, did tremendous work, and identifying that. I'd like to also extend our deep appreciation to all of Team NTSB, including our colleagues, throughout the Office of Marine Safety, especially our investigator in charge, Marcel Muise, Captain Muise, the Office of Highway Safety, the Office of Research and Engineering, the Office of General Counsel, and the Office of the Managing Director, for their work over the course of investigation. And then in the development of an excellent report. And while not often recognized, We focus so much on investigators.
I want to recognize Miss Christopher. You did an excellent job drafting this report. These are complex issues. They're very technical.
When people read it, I think they're going to understand it. You were there on scene working with everyone to make sure what you were putting together, reflected what the investigators were finding. And I want to thank you for your excellent work. That was no small task.
So great job. I also want to express our appreciation to our colleagues in the following offices for their vital support of our meeting, which is the office of the chief information officer, the investigative support division, support services division, and the Office of Safety Recommendations and Communications for its diligent work and advocacy to improve safety. When acted upon, the recommendations we've issued today will save lives. Thank you also to the following organizations for their collaboration with us on scene and their role as parties to our investigation, the association of Maryland pilots, the Federal Highway Administration, Grace Ocean Private Limited, the vessel's owner, Hyundai Heavy Industries, the manufacturer of the vessel, Nippon, Kaiji, Kyokai, the Vessel's Classification Society.
The Maritime and Port Authority of Singapore, the Maryland Transportation Authority, Synergy Marine, the vessel's operator, and the United States Coast Guard. Parties are technical experts that help us gather and develop the facts around the investigation, and as I mentioned earlier, they are not part of the analysis or development of the findings, probable cause or safety recommendations, but they are absolutely critical to helping us obtain information we need to carry out our vital safety mission. I'd also like to thank Mersk and the port of Newark for accommodating my visit, and Mr. Barnum's visit, to the Surak, one of Dali's sister ships, just a few weeks ago, I thought that was extremely helpful.
Finally, we look forward to working with all the organizations that were previously listed when we went through the recommendations to implement our recommendations. We will also continue working with the organizations we listed on implementation of our urgent safety recommendations. With that, I'd like to once again offer our sincerest sympathies to those who lost loved ones in this terrible tragedies. tragedy, and those who were injured.
Please know that our hearts are with you as we work diligently over the next several days, weeks, months, and years to make sure our safety recommendations are implemented, and to ensure that this never happens again. So another family, never has to suffer the same pain, that you all have suffered. We stand adjourned. The police at either end of the bridge stopped the traffic forty-eight seconds before the ship struck, and the NTSB found that saved lives.
Seven highway workers and an inspector were already on the bridge. Nobody had a way to tell them.





