The release of the Final Report on Voepass Flight 2283 has once again brought attention to one of the most complex hazards affecting turboprop operations: performance degradation caused by ice accretion and the crew’s ability to recognize, understand, and respond to that condition before safety margins are exhausted.
The accident occurred on August 9, 2024, involving the ATR 72-500 registered PS-VPB. Brazil’s Aeronautical Accident Investigation and Prevention Center — CENIPA — released its Final Report on July 23, 2026.
One of the systems examined during the investigation was the Aircraft Performance Monitoring — APM, designed to assist flight crews in identifying abnormal aircraft performance degradation.
The investigation not only examined how the system operated during the accident flight, but also issued recommendations concerning its alerting logic and the procedures associated with degraded performance.
The APM system was not created after the Voepass accident
An important technical distinction must be made from the outset: the Aircraft Performance Monitoring system was not developed as a consequence of the Voepass accident.
ATR had developed the function several years earlier. In August 2009, the European Union Aviation Safety Agency — EASA — issued an Airworthiness Directive requiring its installation on several ATR 42 and ATR 72 aircraft.
According to EASA, the system was designed to improve flight crew situational awareness when aircraft performance deteriorates under icing conditions.
It would also be inaccurate to state that the entire APM V2 project originated from the Flight 2283 investigation.
A technical safety presentation previously published by ATR had already included APM V2 within the manufacturer’s development and certification program, with implementation associated with the 2026 timeframe.
This confirms that development of the improved system had begun before the Voepass Final Report was issued.
The accident, however, increased the relevance and urgency of reviewing some of the system’s characteristics.
How Aircraft Performance Monitoring works
The APM monitors several flight parameters to determine whether the aircraft’s actual performance remains consistent with the performance expected for its configuration, weight, power setting, speed, and operating conditions.
When the system detects abnormal performance degradation, it provides alerts to the flight crew.
In practical terms, APM serves as an additional technological safety barrier. It seeks to transform an aerodynamic deterioration—which may initially be gradual and difficult to perceive—into objective information presented to the pilots.
This is particularly important in icing conditions.
Ice accretion can:
significantly increase aerodynamic drag;
reduce lift;
alter the aircraft’s aerodynamic behavior;
increase stall speed;
reduce climb performance;
require additional power to maintain speed and altitude;
affect aircraft controllability.
The system does not replace pilot judgment, operating procedures, appropriate training, or the requirement to exit meteorological conditions that may exceed the aircraft’s certified capabilities.
It adds another layer of awareness and warning.
CENIPA recommendations concerning the APM
The Flight 2283 Final Report resulted in nine safety recommendations addressed to EASA and Brazil’s National Civil Aviation Agency — ANAC.
One of these recommendations called for EASA to work with the manufacturer to reassess the APM alert levels.
The objective is to improve crew situational awareness regarding the severity of performance degradation and the need to promptly carry out the applicable procedures.
CENIPA recommended evaluating whether the “INCREASE SPEED” alert should be upgraded from a caution to a warning.
This distinction is not merely a matter of terminology.
Within an aircraft alerting philosophy, a warning represents a condition requiring a more immediate response than a caution.
The recommendation suggests that the way in which performance degradation was presented might not have communicated the seriousness of the situation strongly enough to the flight crew.
Degraded performance procedure
Another important recommendation concerns the Degraded Performance procedure.
CENIPA recommended that EASA and the manufacturer consider revising the procedure to require immediate crew action to restore a speed margin equivalent to the Icing Bug plus 30 knots.
The intention is to prevent the aircraft from continuing toward the limiting condition represented by VmLBO ICING.
This point deserves particular attention.
During icing operations, indicated airspeed should not be interpreted as an isolated number. What matters most is the remaining margin between the current speed and the operational boundary below which the aircraft’s aerodynamic behavior may become critical.
An aircraft may still be maintaining flight and altitude while progressively consuming its safety margin.
Waiting for a more severe degradation before taking action may make recovery considerably more difficult.
Alerts must communicate the urgency of the condition
An alerting system is effective only when it performs three essential functions:
attracts the crew’s attention;
correctly communicates the severity of the condition;
prompts a response consistent with the urgency involved.
When an alert appears intermittently, is assigned a lower priority than the actual threat, or can be interpreted as a momentary indication, the crew may not react as quickly as necessary.
This is a fundamental human factors issue.
Pilots operate in an environment involving a substantial flow of information: communications, navigation, weather, automation, system management, traffic, operational control, and decision-making.
A warning may be technically correct but still fail to produce the intended response if it does not communicate urgency effectively.
The discussion should therefore not be limited to whether an alert was generated.
It must also consider:
how the alert was presented;
how long it remained visible;
what priority it received;
how the crew interpreted it;
which procedure was associated with it;
whether training adequately reproduced the condition.
What cannot yet be presented as confirmed fact
Some social media reports have claimed that APM V2 has already been fully certified by EASA and includes three specific improvements:
continuous performance monitoring throughout all phases of flight;
a new alert logic based on the actual margin above VmLBO in icing conditions;
a minimum alert display time of 60 seconds.
These features may be technically plausible and consistent with the safety issues raised after the accident.
However, the official sources examined for this article did not provide sufficiently clear technical documentation confirming that all these functions have already been certified and made available for operational use.
No conclusive official confirmation was identified regarding a mandatory 60-second display period for specific alerts.
These claims should therefore not be presented as definitively established facts without an official ATR or EASA document describing the final APM V2 configuration.
Caution is particularly important when discussing a recently completed investigation and design changes that remain subject to formal certification processes.
APM V2 may become part of the accident’s safety legacy
Although development of APM V2 began before the loss of PS-VPB, lessons from the investigation may still influence the system’s final configuration.
This is both normal and necessary in aviation.
Aircraft systems evolve based on:
operational data;
crew reports;
previous incidents and accidents;
investigation findings;
human factors studies;
safety recommendations;
technological developments.
The fact that an improvement program already existed does not prevent an accident investigation from influencing its final design.
An investigation may change priorities, lead to revisions in alert logic, or accelerate the implementation of certain functions.
In this sense, the Flight 2283 accident may contribute to shaping the APM evolution around the way crews identify and respond to performance degradation in icing conditions.
Technology does not replace training
Even an improved monitoring system cannot, by itself, prevent future accidents.
Flight safety depends on the coordinated performance of several barriers:
aircraft design and certification;
proper system maintenance;
quality of training;
standard operating procedures;
flight dispatch and operational monitoring;
meteorological information;
company supervision;
risk management;
regulatory oversight;
appropriate crew response.
The APM can inform pilots that the aircraft is performing below expectations.
The outcome, however, will depend on whether the crew recognizes the seriousness of the condition, understands the alert, and applies the required procedures without delay.
It also depends on an organizational culture that does not normalize deviations, recurring technical failures, or operations conducted with reduced safety margins.
More than a software update
The discussion concerning APM should not be reduced to a software update or a change in the color of an alert.
What is at stake is the aviation system’s ability to identify a critical condition before it becomes irreversible.
This involves the manufacturer, the operator, the certification authority, the regulatory authority, training organizations, and flight crews.
When an investigation recommends upgrading an alert from a caution to a warning, it is indicating that the information may need to reach the pilots more forcefully.
When it recommends immediate action to recover the speed margin above the Icing Bug, it suggests that delay may represent an unacceptable risk.
These recommendations deserve serious consideration.
Conclusion
The Voepass Flight 2283 accident did not create the Aircraft Performance Monitoring system, nor did it originate the APM V2 development program.
The original system had been in service for years, and its evolution was already included in ATR’s development plans before the investigation was completed.
However, CENIPA’s Final Report raised specific questions about the presentation of performance degradation alerts and the urgency assigned to procedures related to flight in icing conditions.
The accident may therefore influence the system’s final improvement.
That is one of the main purposes of an aviation accident investigation: to transform tragedy into recommendations capable of preventing the same safety barriers from being breached again.
Future versions of the APM should provide information that is increasingly clear, timely, and proportionate to the seriousness of the condition.
Nevertheless, no technology can replace adequate training, operational discipline, effective maintenance, organizational oversight, and robust regulatory surveillance.
In flight safety, the alert is only the beginning.
Prevention depends on what the crew and the organization do after it appears.
Sources
Brazilian Aeronautical Accident Investigation and Prevention Center — Final Report A-116/CENIPA/2024, aircraft PS-VPB;
CENIPA — Safety Recommendations issued under Report A-116/CENIPA/2024;
European Union Aviation Safety Agency — Airworthiness Directive 2009-0170;
ATR — Aviation System Flight Safety Enhancements.
Marcuss Silva Reis
Fixed-wing Commercial Pilot, general aviation pilot, aviation expert witness, economist, and optical technician. Postgraduate in Aeronautical Sciences, Civil Aviation Safety, and Higher Education. Former civil aviation school flight instructor, university professor, founder and professor at Instituto do Ar.

Nenhum comentário:
Postar um comentário
Obrigado pelo seu comentário!!!!
Marcuss Silva Reis