Chief Engineer Log · Subscribe Free
Real Maintenance Stories · 25+ Years in the Field
The Ten Minutes We Ran Without the Power Limiter
Every ship I have served on that carries an Engine Power Limitation system has an Onboard Management Manual sitting somewhere in a folder, approved, signed, correctly filed, and rarely opened outside of an audit. Mine had been exactly that document for three years, describing in careful regulatory language how to release the reserve power our main engine had been capped below for the sake of an efficiency index. I had read it once, at handover, and our company had circulated at least one industry bulletin about it since, which I remembered receiving and remembered forwarding to the deck department. What none of that paper amounted to was an actual rehearsal, and I did not understand the size of that gap until a squall put us in a position where the difference between reading about a procedure and having done it mattered within a matter of minutes.
The Situation That Actually Needed Full Power
We were mid-transit through a busy traffic lane when a squall line that had been forecast to pass well clear came through faster and harder than predicted, cutting visibility to under a mile within about twenty minutes and kicking up a short, steep sea that had nothing to do with the swell we had been watching all afternoon. Two other vessels in the lane, comfortably visible on radar and predictable on AIS an hour earlier, were suddenly holding courses and speeds that no longer matched what either system had suggested they would do in reduced visibility. What had been a weather problem became a converging-traffic problem within a few minutes, and the Master needed to accelerate clear of a developing close-quarters situation with a vessel whose next move we could not confidently predict.
He called the engine control room for maximum available power, immediately. What the engine could actually give him, for the first several minutes, was whatever our main engine had been permanently capped at years earlier to meet the Energy Efficiency Existing Ship Index for our ship’s size and type — an Engine Power Limitation system, a software-enforced restriction on the fuel index that held the engine below its full original rated output. That gap had never mattered on any ordinary voyage. It had never once been asked to close itself quickly. That night, for the first time, it had to.
I want to be honest about how ordinary the hours before that squall had felt. We had checked the forecast at the start of the watch and it showed the system passing well to the south of our track, nothing that changed the passage plan or warranted extra caution. That is not a complaint about the forecast so much as an observation about how these situations actually develop: not as a single dramatic warning sign but as a routine transit that stayed routine right up until it very suddenly did not, with almost no room in between to prepare for what came next.
What I Should Have Known Before That Night
The EPL system is not a hidden modification. It is a documented, IMO-approved method for meeting EEXI, and the guidelines governing it explicitly require that the limitation be overridable, precisely because the regulation itself recognizes a ship may genuinely need its full power back for safety. That override, the power reserve, is meant to be deliberate and authorized, not improvised. I knew that from the manual. What I had never done was walk through the actual sequence, and I had never once timed how long releasing it actually took on our specific system.
That second gap turned out to matter more than I expected. The regulation requires the Onboard Management Manual to state the time required to un-limit the power reserve, as a defined system parameter — not an estimate, an actual documented figure. Industry bodies have flagged, in submissions to the IMO itself, real concern that on some installations the power reserve is not available instantly at all, and that pre-emptive un-limiting, done before a hazard fully develops rather than during it, is sometimes the only realistic way to have the power ready in time. I had read that section of our manual. I had never once asked myself whether our own system’s stated release time was something I could actually meet under pressure, or only something I could meet if nothing else was going wrong at the same time.
I had drilled fire, flooding, and steering failure more times than I could count, on that ship and every one before it. Nobody needs convincing that a real fire will not wait for someone to find the manual first, so those procedures get rehearsed until they are closer to reflex than reading. Nobody had ever framed the power reserve the same way, and I understand now why: it arrived through a compliance certificate rather than a casualty response, and compliance certificates do not get the same instinctive respect that emergency procedures do, even when the guidance behind them explicitly exists for a safety reason. That distinction had always seemed reasonable to me before that night. It stopped making sense the moment I actually needed the reserve.
The Confusion Before the Ten Minutes That Mattered
What happened in the engine control room was not a clean, practiced sequence. It was me and my Second Engineer reaching for the same manual at the same time while an alarm neither of us immediately placed was already sounding on the panel, and the Master’s request for full power came down a second and third time over the radio, more urgent with each call. Part of the delay that followed belonged to the system itself — our installation’s documented release time was longer than either of us had appreciated, because neither of us had ever clocked it outside of that manual’s own printed figure. The larger part of the delay belonged to us: confirming we had the authority to proceed, finding the correct page, working through the steps in an order neither of us had ever executed for real.
From the Master’s first call for full power to the engine actually delivering it, roughly ten minutes passed. The situation resolved without a collision. The other vessel altered course as visibility improved, our own room to maneuver turned out to be enough, and nothing about that night became a casualty report of any kind. But a Voyage Data Recorder does not forget how a ten-minute delay actually looked from the bridge, and reviewing that playback afterward was a considerably less comfortable experience than living through the ten minutes had been in the moment, adrenaline included.
Two Kinds of Override Nobody Had Taught Me to Tell Apart
The paperwork afterward turned out to be its own education. I assumed that having genuinely used the power reserve in what felt like an unambiguous emergency, a full report to the flag Administration was automatically required. A conversation with our DPA corrected that. The regulation distinguishes between two different situations. If the limitation is un-limited pre-emptively, as a precaution when a hazard is anticipated, but the engine never actually exceeds the limited power threshold, the event only needs to be recorded in the bridge and engine room logbooks — no external notification required. But if the power reserve is genuinely used, drawing real power above the limited threshold for the purpose of safety, the ship must notify its flag Administration or Recognized Organization, and the competent authority of the next port, without delay, with specific details: the ship’s identifying information, the limited and maximum unlimited power figures, position and timestamp, the reason for using it, and the sea and weather conditions that justified it.
Our engine’s own data recording, which begins automatically the moment an override is activated, showed we had genuinely exceeded the limited threshold, which put us in the second category. Our first draft of the notification, written the next morning while everyone was tired and relieved rather than careful, referenced local time instead of UTC and understated the sea state compared to what the log actually showed. The DPA caught both errors before submission, but was blunt about what that told us: nobody on board, including me, had understood the reporting requirement well enough to get it right under any pressure at all, let alone the kind we had been under hours earlier.
Paper Awareness Is Not the Same as Muscle Memory
What bothered me most afterward was realizing the industry had already identified this exact gap, in writing, more than once, before it happened to us. Class societies had circulated bulletins in the years leading up to that night specifically about the distinction between precautionary un-limiting and actual power reserve use, and about the reporting obligations attached to each. I had received one of those bulletins myself. I remembered opening it, remembered forwarding it to the deck department with a short note, and remembered filing it in the same folder as the Onboard Management Manual it referred to. What I had not done, and what nobody in the company had followed up to confirm, was translate that circulated awareness into an actual physical rehearsal by the people who would need to execute the procedure under pressure.
Knowing a gap exists, in a bulletin everyone reads and nobody acts on, and closing that gap on your own ship turned out to be two entirely different things, separated by whether anyone had ever actually stood in the control room and run the sequence for real. Our company had done the first part well. It had not done the second part at all, and as far as I could tell from talking to colleagues afterward, neither had most of the fleet.
What Changed, On My Ship and Across the Fleet
The engine room fix here was never going to be mechanical, because nothing mechanical had failed. The fix was making sure the procedure lived somewhere other than a folder nobody opened, and this time it did not stop with my own habits. I made a point of raising it past the DPA rather than treating it as a private lesson to fix quietly on my own ship, because the same gap I had just found was almost certainly sitting unexamined on every other vessel running the same system, under the same reasonable assumption that reading a manual once was enough.
- I now run an actual timed walkthrough of the EPL override procedure with the bridge team and engine room watchkeepers at least twice a year, the same way we time a fire drill, specifically to know our real release time under realistic conditions rather than the printed figure in the manual.
- I keep a copy of the Onboard Management Manual in the engine control room itself, not only in the ship’s document management system, so it is reachable in the same minute it is needed.
- I brief every new Second Engineer and Officer of the Watch on the distinction between precautionary un-limiting and actual power reserve use, because that distinction determines whether a report goes external within hours or simply gets logged on board.
- I keep a notification template pre-filled with every static field so that during a real event, the only fields anyone has to complete under pressure are the ones specific to what just happened.
- After our report went in, our DPA did not stop at correcting our resubmission. The company issued a fleet-wide circular referencing the incident anonymously, and for the first time attached a mandatory drill requirement with a sign-off sheet that visiting superintendents now check, rather than another bulletin nobody would ever have to prove they had acted on.
What This Actually Costs
Nothing happened. No collision, no casualty report, no damage. It is tempting, months later, to file the whole night away as a non-event that briefly felt tense and turned out fine. I have resisted that temptation, because the Voyage Data Recorder playback did not let me. The reconstructed closest point of approach to the other vessel came out under a quarter of a mile — closer than either bridge team had judged by eye in the reduced visibility, and closer than I am comfortable attributing to skill rather than a favorable outcome.
If those ten minutes had gone even a little differently — a slower start on the override, a system release time a few minutes longer than ours, a Second Engineer alone in the control room instead of two of us working the problem together — the outcome that night would not have been an audit and a corrected report. It would have been an incident report of an entirely different kind. The gap between what actually happened and what could have happened was not earned by good technical management. It was luck, plainly, and I have no interest in finding out a second time what happens when the luck runs the other way.
I do not think there is a clean way to tell this story that makes the ending feel as serious as the ten minutes actually felt. Nothing broke. Nobody was hurt. The paperwork, once corrected, was accepted without further comment. Every honest measure of consequence available to me afterward said the same thing: this was a non-event, filed and closed. I have chosen to treat it as something closer to a warning shot instead, because the only thing that separated it from a considerably worse write-up was a margin I cannot take credit for, and I would rather change what I can control than trust that margin to show up again.