Simulating Dual Engine Flameouts and Emergency Restart Protocols

In aviation, the loss of both engines is one of the most daunting emergencies a flight crew can face. While such events are rare – the International Air Transport Association (IATA) reports that dual-engine failures account for less than 0.2% of all engine-related incidents – the consequences are severe if not managed correctly. Simulation-based training for dual engine flameouts has become a cornerstone of modern pilot proficiency programs. By immersing crews in realistic scenarios, these exercises build the muscle memory, decision-making skills, and procedural discipline needed to handle a multi-engine failure from initial onset through possible restart or forced landing. This article examines the technical underpinnings of dual flameouts, the simulation technology used for training, step-by-step restart protocols, and lessons from real-world events that continue to shape best practices.

Understanding Dual Engine Flameouts

An engine flameout is a complete loss of power due to the interruption of fuel supply, compressor surge, or failure of the combustion process. When both engines flame out simultaneously, the aircraft becomes a glider, reliant solely on piloting skill and aerodynamic efficiency. Common causes include fuel exhaustion, ingestion of foreign objects (volcanic ash, birds, ice), fuel system contamination, or catastrophic mechanical failures. Dual flameouts can also occur from a single root cause that affects both engines, such as a fuel management error or a widespread atmospheric phenomenon like volcanic ash clouds.

The physics of a flameout impose immediate constraints. Without thrust, the aircraft begins a descent governed by the lift-to-drag ratio – typically around 15:1 for transport-category jets. This gives pilots roughly 10–20 minutes of glide time from cruise altitude, depending on altitude, weight, and configuration. The initial priority is to establish an optimal glide speed (usually the “best range” speed or the QRH-recommended speed for dual engine failure) to maximize distance. Simultaneously, the flight crew must assess the situation, communicate with air traffic control (ATC), and execute restart procedures while preserving energy for a possible off-field landing.

Simulation Technology for Dual Flameout Training

Full-flight simulators (FFS) certified under FAA Part 60 or EASA CS-FSTD(A) provide the highest fidelity for flameout training. These simulators replicate the flight deck, motion cues, visual systems, and aerodynamic models with extraordinary accuracy. For dual flameout scenarios, several key elements are modeled to make the training experience as realistic as possible.

Aerodynamic Modeling

The simulator must accurately represent the aircraft’s behavior without engine thrust: drag increments from windmilling fan blades, control surface effectiveness at reduced airspeeds, and the relationship between pitch attitude, airspeed, and vertical speed. Modern simulators use non-linear aerodynamic databases derived from flight test data, allowing pilots to feel the precise handling characteristics during a power-off glide.

Engine and System Simulation

Flameout scenarios require realistic engine response. The simulator models fuel flow cessation, rotor spool-down, and the conditions under which a windmill start or cross-bleed start is possible. It also simulates the degradation of pneumatics and hydraulics, since engine-driven pumps lose pressure. Electrical generation shifts to the APU or battery, and the simulator reproduces the associated annunciations and EICAS messages.

Visual and Motion Cues

Without engine noise and vibration, pilots rely heavily on external visual cues to maintain situational awareness. Simulators project high-density terrain and airport databases, and motion systems impart the subtle buffet of aerodynamic stall or the yaw from asymmetric drag if only one engine fails. Studies by the Royal Aeronautical Society have shown that motion cues significantly improve pilot performance in upset recovery, making them critical for flameout training.

Regulatory Requirements and Training Standards

Civil aviation authorities mandate recurrent training for all airline pilots, with specific requirements for unusual attitudes and engine failures. For dual flameouts, the FAA’s Advisory Circular 120-109A emphasizes scenario-based training that includes “all-engine failures” as a designated maneuver. Similarly, EASA’s regulations under Part-OR require operators to incorporate “loss of thrust on both engines” into simulator training profiles. These exercises are typically conducted during initial type rating, recurrent proficiency checks (every 6–12 months), and as part of Crew Resource Management (CRM) workshops.

Training is not limited to the procedural steps; it also tests the crew’s ability to prioritize tasks, communicate under stress, and use all available resources – including the Quick Reference Handbook (QRH), ATC, and other aircraft systems. Check airmen evaluate the flight crew’s ability to maintain control, complete the appropriate checklist, and decide on a suitable landing site within the remaining glide range.

Emergency Restart Protocols in Detail

The exact restart procedure varies by aircraft type, but common principles apply across turbine-powered airplanes. Pilots are trained to use “memory items” – actions performed immediately without reference to the checklist – followed by the QRH procedure for dual engine failure. The following step-by-step outlines the general approach.

Memory Items

  1. Control the aircraft – Establish a positive climb or best glide attitude. On many aircraft, this means setting pitch to maintain a specific airspeed (e.g., 280 knots or the minimum drag speed).
  2. Autothrottle disengage – Ensure autothrottle is off to prevent unwanted thrust commands.
  3. Engine start levers to cutoff – On engines that are still windmilling, this step shuts fuel to prevent asymmetric restart attempts.
  4. APU start (if available) – Rapidly restart the APU to restore electrical and pneumatic power for engine starting.

QRH Procedure

After the memory items, the pilot flying (PF) continues to fly the aircraft while the pilot monitoring (PM) reads the checklist. Key steps include:

  • Check fuel quantity and balance – Ensure sufficient fuel in the tank selected for each engine. Cross-feed may be necessary if one tank contains fuel but both engines are drawing from an empty tank.
  • Attempt a windmill start – Move the engine start lever to idle or start, depending on the type. The engine must be within the start envelope (typically 12%–30% N2 for jet engines) for a successful windmill restart. Speed must be maintained; lowering the nose increases N2 but reduces altitude.
  • Cross-bleed start – If both engines are below start rpm, use APU bleed air or bleed air from a running engine (if one can be restarted) to drive the starter. This is often the most reliable method in a dual failure.
  • Monitor engine instruments – Look for EGT rise, N1 spool-up, and stable fuel flow. Abort the start if EGT exceeds limits.
  • If restart fails – Set the start lever to cutoff, maintain best glide speed, and prepare for a forced landing. Notify ATC, select an appropriate landing site (preferably a runway or suitable terrain), and configure the aircraft (flaps, landing gear) as published in the QRH landing gear extension procedure at the appropriate altitude.
  • Consider airstart – Some aircraft allow an airstart at higher altitudes; others require specific conditions. Refer to the AFM.

Throughout the procedure, CRM is paramount. The PF should communicate intentions clearly, and the PM should verify each step. ATC must be informed of the loss of both engines, the number of souls on board, fuel remaining (in minutes), and intentions. ATC will clear the airspace and provide vectors to the nearest suitable airfield.

Human Factors and Crew Coordination

Dual flameouts generate extreme stress, high workload, and compressed timeline. Effective crew coordination is often the difference between a successful restart and an accident. Key human factors considerations include:

  • Startle effect – The sudden silence and vibrations can disorient the pilot. Training helps normalize the response through repeated exposure.
  • Task saturation – With multiple system failures and no thrust, the crew must triage: first aviate, then navigate, then communicate. Use of checklists reduces cognitive load.
  • Communication with ATC – Pilots should state “MAYDAY MAYDAY MAYDAY, [callsign], dual engine flameout, [position], [altitude]” to receive priority handling.
  • Decision to restart vs glide – Not all flameout scenarios should be restarted. If the cause is volcanic ash or fuel starvation, attempting a restart may be futile and waste altitude. The crew must assess whether a safe restart is likely based on the suspected cause and altitude available.

NASA’s Aviation Safety Reporting System (ASRS) contains numerous reports where crews acknowledged that simulation training helped them remain calm and methodical during actual flameouts. One report stated, “The simulator sessions had conditioned us to go through the steps without hesitation. We didn’t waste time trying to analyze why – we just did the checklist.”

Lessons from Real-World Incidents

Several high-profile dual flameout events have shaped training and procedures.

Air Canada Flight 143 (Gimli Glider) – 1983

Fuel exhaustion due to a metric–imperial unit conversion error led to both engines failing at 41,000 feet. The crew executed an unpowered glide and landed safely on a former airfield turned drag strip. The incident highlighted the need for rigorous fuel management and crew cross-checking. Today’s dual flameout training emphasizes fuel quantity verification as a memory item.

British Airways Flight 9 (Jakarta) – 1982

The Boeing 747 flew into a volcanic ash cloud, causing all four engines to fail. The crew kept restarting engines but each relit and then flamed out due to ash ingestion. They eventually used a deep descent to exit the ash, after which all engines relit. The event led to the development of volcanic ash avoidance procedures and the implementation of visible ash detection systems. It also taught pilots that restarting in an ash cloud may be pointless – better to lower the nose, exit the cloud, then attempt a restart.

TACA Flight 110 – 1988

A Boeing 737 experienced dual flameout after encountering severe hail and heavy rain that ingested water into the engines, causing compressor stalls. The crew successfully restarted one engine using a cross-bleed start and landed safely. The case demonstrated the effectiveness of cross-bleed starts and the value of crew coordination under extreme weather.

These incidents underscore that no simulator scenario can perfectly replicate the surprise of a real flameout, but realistic training bridges the gap between theory and application. According to a Boeing Aero article on engine restart techniques, “The cockpit crew must be able to recall the drill immediately, and that recall can only be achieved through recurrent simulator training that includes realistic failures.”

Building Proficiency Through Advanced Simulation

Modern full-flight simulators can be programmed with hundreds of failure combinations, including dual engine flameout at critical phases such as takeoff, initial climb, or cruise. Instructors increasingly incorporate Threat and Error Management (TEM) by introducing additional complications: simultaneous system failures, poor weather, runway closures, or communication difficulties. This prepares crews for the cascading nature of real emergencies where one problem often leads to another.

Some airlines now use “scenario-based training” that places dual flameouts in the context of a full line-oriented flight training (LOFT) session. Trainees complete a normal flight from an A to B, but an event triggers a dual flameout, forcing them to integrate the restart procedure into a broader decision-making process. Research from the University of Texas at Austin suggests that LOFT improves retention and transfer of skills compared to isolated maneuvers.

Regulators are also exploring the use of virtual reality (VR) and desktop trainers for initial knowledge acquisition and CRM practice before full-demand simulator sessions. While VR cannot replace motion and visual fidelity for flying the aircraft, it can effectively train procedural steps and communication protocols at a fraction of the cost.

Conclusion

Simulating dual engine flameouts is more than a regulatory checkbox – it is a life-saving investment in pilot resilience. By combining realistic aerodynamic modeling, accurate system simulations, and structured restart protocols, training ensures that flight crews can respond to the most improbable failure with composure and precision. The lessons etched into aviation history from events like the Gimli Glider and British Airways Flight 9 continue to inform simulator programs and QRH design. As the industry evolves toward data-driven training and new technologies like VR, the goal remains unchanged: to give every pilot the skills, confidence, and muscle memory needed to turn a catastrophic event into a controlled outcome. Ultimately, the only way to guarantee that a crew can handle a dual engine flameout is to have them survive one – first in the simulator, where mistakes are lessons, and only later in the aircraft, where protocols take over.