Ten people lost their lives when coach 4666MO rolled over at Greta in the NSW Hunter Valley on 11 June 2023. The other 25 passengers suffered significant physical and psychological injuries. Any discussion of the investigation must begin by recognising the people, families, first responders and community who continue to carry the consequences.

The Office of Transport Safety Investigations has now published its final report. OTSI makes clear that its findings should not be read as assigning blame or liability. Its purpose is to explain what happened, identify the safety factors and support changes that may prevent another tragedy.[1]

The report is extensive: 287 pages, 34 recommendations to named organisations and another seven recommendations to the bus and coach industry. Its findings extend across speed, driver impairment and health, passenger containment, seatbelts, vehicle glazing, road design, driver oversight, training, event recording and emergency response.[1]

One finding deserves attention in every safety-critical organisation, regardless of industry.

OTSI found that the operator's risk-management system had been assessed as complying with the Bus Operator Accreditation Scheme. It also found that the system was likely of limited effectiveness because known risks relevant to the incident had not been identified.[1]

Both statements can be true.

OTSI report finding stating that the operator's system was assessed as compliant but was likely of limited effectiveness because known relevant risks were not identified
OTSI's risk-management finding: the system was assessed as compliant but was likely of limited effectiveness because known risks relevant to the incident were not identified.

A system can satisfy an audit framework and still fail to identify the risks that matter.

Compliance answers a narrower question

An audit normally asks whether arrangements conform to defined requirements. It examines the scope, criteria and evidence available: policies, registers, procedures, records, responsibilities, training and assurance activities.

That work is necessary. But it does not automatically establish that the organisation has identified every material pathway to fatal harm, that its controls address those pathways, or that the controls remain effective under real operating conditions.

The distinction is critical:

  • Compliance asks whether the required system exists and operates as specified.
  • Risk effectiveness asks whether the system is finding and controlling the conditions capable of producing serious harm.

If the audit criteria, risk register or organisational boundary is incomplete, the audit can provide a correct conclusion about the evidence it tested while leaving a material risk outside the frame. The danger begins when leaders interpret “compliant” as “safe”.

The report describes a system, not a single failure

The direct contributory factors identified by OTSI included speed, impairment and passenger containment. The coach entered the tightening part of the roundabout above the calculated rollover speed. Post-incident analysis found the driver was under the influence of tramadol that would likely have impaired driving ability. The report also found that not all passengers were wearing the available seatbelts and that broken windows did not contain passengers during the rollover.[1]

Those findings are important, but they are not the whole system.

OTSI also identified limitations in how driver health information moved between the driver, medical practitioners, employers and the licensing authority. It found that routine industry drug testing was not designed to detect every medication capable of influencing driving and that testing for tramadol required a specific request to the laboratory.[1]

Aerial diagram of the Branxton Interchange with critical heavy-vehicle rollover regions and risk-rated vehicle movements
OTSI report Figure 54: risk ratings for movements at the Branxton Interchange. Figure source: Safe System Solutions Pty Ltd.

There was no NSW-wide system for the bus industry to track where a driver's authority was being used or to monitor performance information such as incident history, infringements and customer feedback. Operators therefore relied on declarations and reference checks, creating opportunities for at-risk behaviours to remain undetected.[1]

The operator's safety-management arrangements did not contain specific thresholds for consistently responding to overspeed, harsh braking, harsh acceleration and fatigue-management breaches. Known risks relevant to the incident, including driver health and fitness and hazardous driving such as speeding, were absent from the risk register.[1]

The report then moves beyond the operator. It identifies issues involving seatbelt communication and enforcement, window glazing and occupant containment, restraint design, emergency exits, roundabout guidance, heavy-vehicle rollover education, event recording and automatic crash notification.[1]

This is what serious incident learning looks like. It does not search for one convenient explanation. It examines how multiple systems created, transferred, amplified or failed to control risk.

When information depends on declaration

Several controls described in the report relied on information being declared or passed between people and organisations.

Declarations are sometimes unavoidable, but they are a vulnerable control. Their effectiveness depends on the person recognising the relevance of the information, understanding the reporting requirement, being willing to disclose it and knowing where it must go. The receiving organisation must then interpret it correctly and act.

Whenever a critical control depends on declaration, leaders should ask:

  • What makes the required information visible?
  • What independent source could confirm it?
  • What happens when information is incomplete, delayed or ambiguous?
  • Which organisation owns the risk while the information crosses a boundary?
  • What evidence demonstrates that the declaration process works in practice?

The absence of an answer does not mean the risk is controlled. It means the control relies on an assumption that has not been tested.

Testing only proves what the test can detect

The report's discussion of drug testing illustrates another common assurance problem.

A test can operate exactly as designed and still be incapable of detecting the condition that matters. OTSI found that the routine testing regime was intended to detect specified substances; it was not intended to detect every medication that could influence driving.[1]

This principle applies far beyond medication testing. An inspection may not examine hidden degradation. A dashboard may not capture work performed outside the formal workflow. A permit audit may confirm that fields were completed without testing whether the isolation was effective. A culture survey may measure willingness to speak up without showing whether reported concerns change operational decisions.

Before treating a test result as assurance, ask:

  • What can this test detect?
  • What is outside its detection boundary?
  • What false confidence could a negative or compliant result create?
  • Which additional controls address what the test cannot see?

The question is not whether the test passed. It is whether the combined controls manage the risk.

Audit control effectiveness, not just compliance

The most valuable response to this report is not another generic instruction to improve compliance. It is to test whether material risks have been identified, whether the controls address those risks, and whether those controls remain effective under real operating conditions.

Boards, officers and operational leaders should ask for evidence that:

  • the highest-consequence events have been identified from credible scenarios, not only historical incidents;
  • critical controls are linked to those scenarios and have defined performance requirements;
  • information crossing organisational boundaries has a clear owner and an independent verification pathway;
  • monitoring thresholds trigger consistent action before exposure becomes an incident;
  • audit scopes test for missing risks and weak assumptions, not only conformity with documented processes;
  • assurance activities disclose their detection limits; and
  • changes in technology, work, people and external knowledge are used to challenge the risk register.

This is not an argument against compliance audits. It is an argument against asking them to prove something they were not designed to prove.

The sentence leaders should not misuse

“The system passed the audit” may be factually correct. It is not the end of the safety conversation.

The next questions should be: What did the audit test? What was outside its scope? Which assumptions remained unchallenged? What evidence shows the controls are changing exposure in the real operating system?

OTSI's report shows why those questions matter. It issued 34 recommendations to relevant organisations and seven to the wider bus and coach industry. The recommendations address driver health, medications, seatbelt use, occupant protection, road design, emergency arrangements, performance oversight, training, event recording and crash detection. At publication, all 34 recommendations to named organisations had been accepted or accepted in principle.[1]

The lesson is not that systems and audits have no value. It is that compliance is a baseline, while effectiveness must be demonstrated against the risk.

Take the last audit report presented to your board and ask: did it confirm that our system exists, or did it test whether we have found and controlled the risks that could change people's lives forever?

This article provides general information and does not assign blame or liability. It draws on the independent safety findings published by OTSI for the purpose of organisational learning.

References

  1. Office of Transport Safety Investigations, Bus safety investigation report: Rollover of coach 4666MO – Greta, NSW, 11 June 2023, Investigation Reference I02039, published July 2026. See Executive summary, pp. iii–vi; Findings, pp. 187–191; and Recommendations, pp. 192–198. OTSI states that its findings should not be read as apportioning blame or liability. OTSI reports and publications.
  2. Office of Transport Safety Investigations, Interim Factual Statement: Rollover of coach 4666MO – Greta, NSW, 11 June 2023, published June 2023. The July 2026 final report supersedes the interim statement for findings and recommendations.