Finnhawk. The recovery platform worked that morning.
When a man needed it, it would not come back up.
At about 1300 on 8 January 2023, a Humber pilot was climbing the pilot ladder of Finnhawk.
He fell without warning.
The ladder was inspected after the accident. It was approved, in good condition and correctly secured.
The investigation found that the pilot probably suffered a cardiac event.
He struck the deckhouse and safety rail of the pilot vessel Humber Saturn, then fell overboard.
His lifejacket kept his head above water.
The recovery platform was lowered. The pilot was brought onto it.
But the platform could not be raised.
He remained partially immersed in cold seawater for over 40 minutes before being transferred to a lifeboat.
The report found that this prolonged semi-immersion significantly reduced his chance of survival.
The immediate defect was mechanical.
A solenoid valve jammed after the platform was lowered. Loose bolts were also found on a limit switch.
Yet the important history started much earlier.
More than 20 defects had been reported on that platform during the previous five years. They involved lifting wires, limit switches and sticking solenoid valves.
The maintenance management system did not identify them as safety significant.
The platform had also been checked that morning without issue.
That is how false assurance develops.
A test confirms that equipment operates now.
It does not explain what recurring defects say about emergency availability.
Each repair can appear complete. Each test can produce a pass. The defect history can still describe equipment that cannot be relied upon when the operating conditions change.
On Humber Saturn, that reliability mattered because there was no independent alternative for recovering an unconscious person from the water.
One platform carried the whole recovery function.
When it failed, the crew could keep the pilot on the partially submerged platform. They could not lift him back on board.
This is not an argument against testing.
It is an argument against treating the latest successful test as the whole assurance case.
For a DPA or Technical Manager, emergency equipment needs a second review.
Look beyond its current status.
Review defect recurrence. Failure modes. Repeat repairs. Availability during drills. The consequence if it fails after deployment.
Then define the escalation point.
When does another defect stop being routine maintenance and trigger a review of the equipment's safety significance?
And if the primary recovery method fails under load, what independent method can your crew use immediately?
#MaritimeSafety #MarineAccidentInvestigation #Pilotage #EmergencyPreparedness #Maintenance
