Bridge control

Loss of bridge control in functioning systems

Effective control of a vessel can sometimes be lost even when equipment is working. In this article, we see how control settings applied by the crew can lead to serious accidents. In an era of increasingly sophisticated bridges and integrated systems, the accidents serve as a stark reminder of risks at the interface between humans and machines.

Written by

Image of Mark Russell

Mark Russell

Vice President, Global Claims Lead, Safer with Gard

Published 28 September 2026

The first article in this series examined accidents involving loss of bridge control due to a mechanical or electrical failure in conventional steering systems. However, accidents can also occur when systems are fully functioning. They can be triggered by wrong settings applied by the crew. Amidst the panic when control is lost, crew have only minutes or seconds to properly diagnose the issue and steps taken to try and regain control can make matters worse.

The following cases highlight how quickly things can go wrong.

Case 1: Full ahead while alongside

In the first accident we consider, there was virtually no time to react. The accident also occurred when least expected: when the vessel was moored alongside.
The fishing vessel had a controllable pitched propeller, on which the blade angles can be rotated for forward or reverse thrust without changing the direction of the engine's rotation. On the passage leading up to arrival in port, propulsion control had been transferred from the bridge to the engine room for maintenance. When that was completed the engine room pitch control lever was left in full-ahead position. The vessel berthed under bridge control and when all was secured, propulsion control was transferred back to the engine room for shut down. That transfer was accepted without checking the pitch control lever, which remained in the full ahead position in the engine room. The vessel moved forward, broke her moorings, and rammed into another vessel berthed broadside ahead. This caused serious damage, flooding and pollution. Fortunately, no one was harmed.
The investigation found no documented procedure for the changeover between control stations, such as prior confirmation of pitch lever positions. Fatigue after a long shift likely also played some part. Classification society rules were also analysed and unified rules required “means to prevent the propelling thrust from altering significantly when transferring control from one control to another”. However, individual class society interpretation and application of the rules can differ. In this case, class approval was based on a factory acceptance test and a system designed (as per the manufacturer’s manual) without interlocks or synchronised settings.

Case study 1

Case 2: Unintended transfer of steering

In a much more serious incident, a naval vessel veered into a commercial vessel she was overtaking, resulting in multiple deaths and severe injuries. The investigation focused on a bridge console which controlled steering and propellor thrust through a touch screen Integrated Bridge and Navigation System (IBNS). During the watch a decision was made to transfer the thrust control to an operator at an adjacent control station so that the helm person could concentrate on steering. Unfortunately, during this procedure there was an unintentional transfer of control of the steering, as well as thrust. This resulted in a perceived loss of steering, but there was no actual loss of steering. It was not understood that this was being controlled at the lee helm station on the same console.

Case study 2
Steering was transferred from the helm station to lee helm station.

To make matters worse, during the transfer of thrust control the thrust for each propellor became un-ganged or linked to provide equal thrust. When the lee helm person answered an order to reduce speed, thrust was only reduced on the port propeller and the unwitting mismatch in thrust caused the vessel to veer harder towards the vessel being overtaken. Control was re-established too late to prevent the collision which came only four minutes after the unintended transfer of steering.
The bridge team failed to observe the un-ganged thrust on the IBNS touchscreen, which could immediately have been matched to straighten the course. They also failed to press the “big red button” (shown in the above image) - an emergency override which would have reestablished control of steering to the helm station and have likely avoided the collision. The investigators found flaws in design of the IBNS as well as shortcomings in operating procedures and training. The bridge team mistakenly believed that the big red button transferred control to aft steering. They also found that there was fatigue amongst the bridge team impacting situational awareness.

Case 3: Change of steering settings in busy waters

Deciding to change control settings needs extra care and attention in congested waters. A strikingly similar collision took place in another busy traffic area, the problem this time on the vessel being overtaken.
The crew were investigating a water seepage in the steering gear room. The master, who was away from the bridge, relayed a request to the officer on watch to switch off one of the two running steering gear motors. The officer did so while the vessel was proceeding at around 10 knots, with another vessel relatively close on the quarter and overtaking at 16 knots. Steering was lost, and the two ships collided within minutes, according to the interim investigation. The collision caused significant damage to both vessels.

Case study 3

Case 4: A bridge joystick that was not in control

During a familiar port manoeuvre, a vessel struck and sank two unmanned vessels alongside. The vessel’s steering system comprised two schilling rudders installed symmetrically behind a single propeller. The rudders could be set at an angle to generate astern thrust even with the propeller rotating in the ahead direction. This meant that the ship could be slowed, stopped, or moved astern without the need to stop the engine and engage astern propulsion. This was all done through a joystick steering mode, with the joystick position controlling the rudder angle and desired direction of thrust (see image).

Case study 4

The accident occurred whilst the vessel was making its usual turn in a swing basin at a port she regularly called. As the vessel commenced a slow turn, the master (under pilotage exemption) advised that he was ready to take control on the bridge wing. The second mate confirmed that the bridge wing console was ready and so the master moved from the wheelhouse to control the ship at that console with the joystick. The master set the joystick to astern port which would set the rudders at angles to generate astern thrust as well as swinging the stern to port. This did not have the desired effect so the master set the joystick to astern (maximum rudder angle) and increased the main engine to half ahead. This was soon followed by full ahead, until the master realized from the rudder angle indicators on the bridge wing that the rudders were still amidships. There was not enough time to stop the ship before the collision happened around three minutes after the transfer had been initiated.

The investigation found that the steering mode selector located on the main console in the wheelhouse had not been changed from manual steering to joystick steering mode. Consequently, the master’s actions to increase propulsion, thinking it would increase astern thrust, had the opposite effect of increasing speed. It was also found that four out of five documented steps for transferring control had not been completed, including pushing the bridge wing joystick activation button on the bridge wing console. The master and bridge team had long experience of manoeuvring with the joystick system, which suggested that the perception of risk had probably diminished over time. Distractions associated with a watch hand-over and from VHF radio traffic were also cited. A factor that was found to increase risk was the illumination on the joystick panel, which gave a false impression that the joystick steering mode was activated whereas it only indicated it could be activated.

Case 5: Still in autopilot approaching a reef

The next two cases involve the use of autopilot close to shore. The first involves a naval research vessel that grounded and became a wreck.
The vessel was fitted with azimuth propulsion (propellers in pods that rotate horizontally providing both thrust and steering, eliminating the need for a conventional rudder). The officer of the watch (OOW) had the control of the ship, working under a supervisory in relation to survey operations around half a nautical mile off a coastal reef. The vessel was undertaking manoeuvres in a clockwise rectangle within the survey area south of the reef (see image). On the longer east/west legs the OOW engaged autopilot but switched to manual control for the turns to south/north legs.
After completing the turn for the northerly leg, the OOW once again engaged autopilot. This short leg put the ship on a direct heading towards the reef, necessitating a turn to starboard within two minutes. When the OOW initiated that turn using both thruster controls there was no change in the heading. Within a minute the ECDIS alarm sounded and the OOW increased demand on thruster angle and power. The OOW called out the lack of response and the commanding officer was called to the bridge. The thruster controls were turned for astern thrust and power increased to full astern. However, this resulted in an increase in speed. Within a further three minutes the vessel had started to touch bottom. It took a further 9 minutes to realize the ship was still in autopilot, by which time the vessel was firmly aground. The vessel was abandoned and some crew ended up in the water. Fortunately, all survived.

Case Study 5

The inquiry found that the crew mistakenly attributed unresponsiveness to a thruster control failure, when in fact the vessel remained in autopilot mode. They also failed to follow the bridge cards for a thruster control failure which would have required switching from autopilot to manual control and if that had failed taking all thrust off the affected thruster. The inquiry also found shortcomings in azimuth pod training and certification.

Case 6: Autopilot takes an unexpected turn

A similar scenario played out when a ferry grounded after recently being fitted with a new steering control system. The ferry had completed over 80 transits with the new system in the three weeks before the accident. The vessel left the berth in manual steering under the control of a master supervising an additional master onboard for re-familiarisation, having not sailed on the ship for some time. Despite being in a narrow waterway and increasing speed to 13 knots, it appears to have been the practice to engage autopilot early in the transit. The two masters agreed to use course mode so the autopilot would adjust the heading for the next waypoint allowing for the effects of wind and current. The helms person was released and stood by.
The waypoints for the ferry crossing were programmed into the ECDIS, together with wheel-over points and visible on the ECDIS display. In course mode, the autopilot would not automatically start the turn at the wheel-over point without an execute button on the console being pressed. Once pressed, the autopilot would start the turn for the course after the next waypoint and manual adjustments could be made with a toggle control.

Case study 6

The investigation found that the execute button was pressed after waypoint two had been passed. At that time, the autopilot system was locked onto the wheel-over for the next waypoint three. This therefore caused the autopilot to start a turn through 34 degrees for waypoint three which was much greater than the 3-degree turn for waypoint 2.

The team saw that the vessel was now heading towards shore and ordered the helmsperson to take the wheel at the central helm console and to turn hard over to port. He pressed the “takeover” button on the console and turned the wheel, but the vessel continued its starboard turn in autopilot. Further attempts failed and the investigation discovered that, unlike the old system, it was a requirement of the new steering system for the rudder commands to be aligned (within 2 degrees) between control modes. In other words, the manual steering command needed to align with the starboard helm being applied by the autopilot for manual takeover to be effective. Neither master was aware of this or that the new system had a feature allowing transfer despite misalignment by pressing a takeover button for around 5 seconds. Engaging full astern propulsion and regaining steering in NFU mode came too late to prevent the bow grounding in a matter of minutes.

Case 7: Misconfigured steering gear

Bridge settings are only part of the picture. In one accident a vessel’s steering started to behave erratically whilst transiting a narrow channel, resulting in her stern clipping a navigation beacon.

The investigation found that this most likely stemmed from a port state control inspection the day before the accident. The inspection included testing the emergency changeover of steering control from the bridge to the steering gear room. The manufacturer’s instructions for local control in the steering gear room differentiated between “normal operation” and “emergency operation”, with the latter applying where only one of two hydraulic pumps were to be used. For example, in the event of oil leakage in the circuit for one of the pumps, an isolation valve (painted red with no handle, see image below) would be closed and a bypass valve (painted red with handle) for the non-running pump would be opened.

Case study 7.1
Case study 7.2

This “emergency operation” set-up with a bypass valve closed appears to have caused confusion amongst the crew vis a-vis “emergency steering”. Normal operation for one or both running pumps required the by-pass valves closed. The confusion likely led the crew to unnecessarily open a bypass valve during the PSC inspection test and which was probably left open after the test. This did not reveal itself as a problem during pre-departure steering tests alongside or at low speeds. It only became a problem at higher speeds. Above about 8 knots the increased water flow over the rudder meant that the hydrodynamic forces overcame the hydraulic forces, adversely affected by the flow through the open bypass valve. This led to inconsistent, erratic response of the machinery and the steering gear not operating correctly.

Key takeaways

  • Confirm the active control station and mode. Understand what display panels are indicating and check that controls respond before committing to a manoeuvre.

  • Treat every transfer as a critical step. Follow the full changeover procedure, including any activation, acceptance and synchronisation steps.

  • Choose the time for changes carefully. Making changes in confined or congested waters leaves less time to recover if the vessel responds unexpectedly.

  • Practise recovery on the actual system fitted. Crew need to know how autopilot, manual steering, emergency overrides and propulsion controls interact. Changes to equipment require renewed familiarisation, even for experienced operators.

  • Understand the complete arrangement. The integration of critical control systems needs to be fully tested, practised and reflected in clear procedures.

A number of the accidents featured in this article involve sophisticated control systems. More traditional systems will however evolve and likely with greater levels of sophistication. Technology is moving fast and the high severity potential with critical bridge control systems cannot be ignored. Humans will still need to interact with these systems, and so system design takes on even greater importance.

We have seen how the interpretation of design rules can differ. Even clear rules are unlikely to eliminate interaction risks. A complicating factor on ships is an array of manufacturers for different systems, or parts of systems, which are increasingly being integrated to support greater automation and efficiency gains. This increases complexity. Increased cognitive loads can seriously inhibit the ability to restore control, especially in the agony of a moment unwittingly created by the crew’s own system settings. In our next article - the last in the series - we put the human element into context by considering performance influencing factors relevant to these accidents.

Related Articles

News and Insights

Stay updated

Get updates from Gard in your inbox. Read our latest news and insights.

Sign up
LinkedInFacebook

Gard is a member of

IGP & I company logoCefor company logoMACN company logo
Loss of bridge control in functioning systems | Gard's Insights | Gard