After the final application of the work selection strategy, a total of 91 documents were identified: a total of 63 are primary studies (i.e., peer-reviewed indexed research papers), 2 are secondary studies (i.e., reviews), and 26 are classical sources, standards, and regulations. These selected works permitted the authors to critically assess the current state of research and address the proposed research questions.
2.1. European Models
Quantitative risk analysis models for third-party risk assessment have been developed in Europe, specifically in the UK [
25,
40,
41], Ireland [
26], and The Netherlands [
42,
43,
44]. These reactive models fall into the second (i.e., UK and Ireland) and third (i.e., the Netherlands) generations, focusing on accident probability assessment and accident location submodels. British and Dutch models apply certain criteria, such as including only medium and large airports (i.e., those with over 150,000 movements per year), assuming that 90% of flights meet “Western” standards and 70% are precision approaches, and excluding general aviation involving light aircraft. Accident databases extend from 1979 to 1995 for the British and from 1980 to 1997 for the Dutch model, while accident databases span from 1979 to 1995 for the British model and from 1980 to 1997 for the Dutch model. The Irish model follows similar criteria to the British approach but also includes a separate model for light aircraft.
All these models consist of three submodels: accident probability, accident location, and consequence (
Figure 1), which collectively estimate individual risk. Only the Dutch model incorporates societal risk [
15,
28], accounting for the risk across the area based on the actual population distribution around the airport.
All models consider flight maneuvers (i.e., landing undershoot (LDUS), landing overrun (LDOR), take-off overrun (TOOR), and take-off overshoot (TOOS)) and their accidents (
Figure 2). Veer-off accidents are overlooked in the standard Dutch, British, and Irish models.
The accident probability models estimate the probability of an event based on specific operational conditions, such as the yearly number of movements [
28]. None of these models include variance analysis to compare accident probability estimates against the actual statistical locations of accidents.
Table 4 presents the accident rates (per million flights) for third-generation aircraft according to the Dutch model [
28].
The accident probability model retained by the British and Irish models is empirical. It considers aircraft with a 4 Mg Maximum Takeoff Weight Authorized (MTWA). For the Dutch one, the MTWA is 5.7 Mg.
Table 5 presents the crash rates for different aircraft classes according to the British and Irish models [
41].
The accident location model determines the geographic distribution of accidents relative to runways and flight paths, based on historical data for aircraft overruns, veer-offs, and undershoots. A key distinction between the British/Irish and Dutch models lies in the wreckage location approach: the British and Irish models align accident distribution along the runway centerline, while the Dutch model uses the flight path route. In all models, risk assessment centers on the PSZ at each runway end.
The consequence model focused solely on ground impact, excluding passengers and crew, and defines the severity of an accident in terms of the impacted area. The risk at any point surrounding the airport is calculated as the probability of an accident occurring at that point, multiplied by the area affected (or destroyed), representing the risk of fatality for a person at that location due to an aircraft crash. Societal risk can be further evaluated by factoring in population density around the airport [
15].
Although acceptable levels of individual risk vary according to regulatory standards, criteria, and specific industry practices [
41], a risk threshold of around 1 × 10
−6 per year is typically regarded as acceptable [
2]. Based on this, zones are defined by threshold risk levels: 1.00 × 10
−4 (inner area), 1.00 × 10
−5 (intermediate area/Inner PSZ boundary), and 1.00 × 10
−6 (outer area/Outer PSZ boundary) yearly [
26,
40,
42]. Land use within these zones is outlined in
Table 6 and
Table 7 for proposed and existing developments, respectively [
26].
In the UK, recent updates to the Policy of the Control of the Development in airport PSZ are illustrated in
Figure 3 [
40]. This policy specifies the dimensions and configuration of PSZs, with an inner boundary, the PSRZ, in red, and an outer boundary, the PSCZ, in blue. The dimensions, particularly the length, of a PSZ are determined based on a risk appraisal that factors in the volume of airport movements. According to the policy, PSZ boundaries must be redefined if a runway is extended or if the landing threshold is adjusted. Local planning authorities are encouraged to apply this risk assessment methodology when PSZ compliance with [
40] is not achieved. The standardized PSZ shapes in
Figure 1 approximate iso-risk curves derived from risk assessments, aligning with the triangular configuration proposed by [
26].
Italian studies on the distribution of air accidents around runways [
45] from 1996 to 2022 examined 2508 events during landing, final approach, take-off, and initial climbing [
45]. These involved “Western-built and operated” aircraft, with data filtered to exclude companies operating under safety standards and technologies not aligned with Italian norms. The data filtration aligns with international standards [
46] but it is not adaptable for other uses [
37]. The software tool Spatial Distribution of Aircraft Crashes, SDAC [
45], facilitates the analysis and visualization of accident data. Each recorded accident is plotted using a coordinate system, with the
y-axis aligned with the runway centerline and the
x-axis perpendicular to it, offering a standardized framework for understanding accident locations relative to runway orientation.
The aircraft’s position following an accident is determined by the impact location (
Figure 4):
If the accident occurs before the aircraft has touched down on the runway, it is labeled “B” (Before). Here, the y-axis points outward, opposite the runway, with the origin of the coordinate system at the first threshold;
If the accident occurs between the two thresholds, it is marked “RW” (RunWay), with the y-axis aligned in the direction of the aircraft’s landing trajectory;
If the aircraft overruns and comes to a stop beyond the threshold, the impact point is designated “A” (After), with the origin of the Cartesian coordinate system set at the second threshold.
The accident probability model aligns with the frameworks in the UK, Ireland, and the Netherlands, comprising two probabilistic distributions: one for take-off (including initial climbing) and another for landing (including approach) accidents. The SDAC tool enables a detailed analysis of the accident distribution with respect to runway length and aircraft categories, including general aviation. The outputs support the development of risk plans for small and medium airports (
Figure 5). Conversely, a three-submodel approach is employed to assess risks in areas surrounding the busiest airports (
Figure 6).
A standardized individual risk assessment model has been developed, drawing from elements of both the Irish model (the probability distribution functions, based on the UK accident database) and the Dutch one (for the calculation of the individual risk and use of a curvilinear coordinate system) [
49] to delineate PSZ iso-contours. Consequently, this model is classified as third-generation. The accident probability model applies accident rates specific to each aircraft type, adjusted for the number of movements. For accident location, it uses two probability density distributions: a Weibull distribution coupled with a Gaussian distribution for overruns and landings, and a Gamma distribution for climbs and take-offs. The consequence model assesses impact severity based on third-party individuals on the ground, considering factors such as the affected area, aircraft weight, and wingspan. This model is implemented in the SARA v. 1.0 (Sapienza Airport Risk Analysis) software, which calculates iso-risk contours. SARA enables the definition and validation of PSZs for single-runway, high-traffic Italian airports [
48] by varying the traffic mix and volume. Its outputs, validated through previous risk analyses, are valuable for updating risk plans for small and medium-sized airports (fewer than 50,000 movements per year) [
50]. Notably, iso-risk contours produced by SARA show significant deviations from existing ICAO-based risk plans, often leading to risk overestimation for small airports or underestimation for small-to-medium airports. All currently available models establish PSZs solely at runway thresholds. In response, the Italian Civil Aviation Authority (ENAC) [
47] has proposed a land-use approach that includes a Risk Management Plan and risk assessment for areas around airports. The Risk Management Plan defines zoning and land-use restrictions according to ICAO Runway Codes (see
Figure 5), while the risk assessment incorporates a Third-Party Individual Risk Analysis with three defined risk thresholds: 1.00 × 10
−4 (internal airport area), 1.00 × 10
−5 (intermediate area), and 1.00 × 10
−6 (external area, extending beyond the designated outer limit if exceeded).
2.3. Comparison of ENAC/Sapienza (SARA) and ACRP Models
Following the review of risk assessment approaches, the Italian and ACRP models were analyzed and compared based on the accident probability model, accident databases used to develop the location probability model, accident location probability model, and calculation of the risk values through case studies.
2.3.1. Accident Probability Models
The accident probability model used in SARA relies on historical accident aircraft rates. It calculates the weighted average accident rate (
R) per movement according to Equation (1):
where
is the aircraft (
i) accident rate,
is the number of the ith aircraft movements, and
n is the number of aircraft in the traffic mix.
Then,
R is distributed according to the weight of each type of accident according to the phase of flight assumed from the Irish model [
26] and listed in
Table 8.
The ACRP probability model based on NOD considers weather conditions, aircraft performance, and runway characteristics and conditions. These independent variables are causal and contributing factors for accidents [
51]. TORA/LDA values and the aircraft runway distance required for operating conditions are key runway criticality factors. The model’s fundamental structure is based on the logistic Equation (2):
where
is the probability of an accident type under certain operational conditions (and variables),
represents independent variables (e.g., weather, aircraft type, criticality factor), and
represents regression coefficients,
i = 1, …,
n.
The models were developed by using forward stepwise logistic regression and backward stepwise regression [
53]. They provide the parameters of the 32 variables included in five frequency models, one for each accident type in
Table 8 and landing veer-offs (LDVOs).
2.3.2. Accident Databases
SARA’s accident probability model relies on data from the Irish model, which, in turn, is based on the British accident database. The British database includes 354 events from first-world airports between 1970 and 1995 [
41]. These data provide a longitudinal distribution of selected accidents up to 4500 m from the runway threshold and a lateral distribution within 500 m from the runway centerline.
In contrast, ACRP uses a database of 1414 events occurring between 1980 and 2014, collected exclusively from 78 U.S. airports [
54]. This dataset covers incidents within 2 miles (3.21 km) of the runway threshold and up to 4500 ft (1.2 km) laterally from the runway centerline, consistent with the RPZ definition (maximum length of 765 m) and focusing risk assessment within the RPZ. By limiting the spatial scope of accident data, the model produces smaller risk contours compared to those based on broader datasets.
2.3.3. Accident Location Models
The accident location model in SARA also adopts the Irish model’s approach and uses two PDFs [
57] to estimate accident probability density within the coordinate system in
Figure 8 where 1 and 2 refer to the runway thresholds.
The first distribution has y as the independent variable (ordinate) as a Gamma PDF (longitudinal distribution) (Equation (3)):
where
is Euler’s gamma function,
and
are regression coefficients (they assume different values for each type of accident considered: LDUS, LDOR, TOOR, TOOS), and
is the fraction of movements that have
according to
Figure 8.
The second distribution has
x as the independent variable (abscissa) as a Weibull PDF (transversal distribution) (Equation (4)):
where
, and
c are regression coefficients for each type of accident considered (LDUS, LDOR, TOOR, TOOS), and
and
are the coordinates of a given location (the point of interest in
Figure 8).
The ACRP approach is based on historical accident data. Four sets of complementary cumulative probability models have been developed for the longitudinal distribution (Equation (5)), and the veer-off has been omitted from the model:
where
is the probability that the overrun/undershoot distance along the runway centerline beyond the runway end is greater than
;
is a given location or distance beyond the runway end; and
a and
b are regression coefficients.
The non-linear exponential functions achieved an excellent fit to the data, with R
2 values exceeding 0.99 for all accident types [
52]. For the lateral distribution, regression models were applied to fit the data (Equation (6)):
where
and
are the coordinates of a given location, and
,
,
,
and
are regression coefficients.
R2 values of all the accident location models exceed 0.97, except LDUS, which has an R2 equal to 0.88.
In both models, the accident probability density is determined by multiplying the longitudinal and lateral distributions (i.e.,
g and
h, respectively), as in Equation (7):
where
L is the accident likelihood,
is the distance from the runway threshold, and
is the distance from the extended runway centerline.
Compared to SARA, ARCP demonstrates a stronger fit to the data, with notably high R2 values. This is largely due to the higher concentration of accident data near the runway in the ACRP database. However, the fit of each model is influenced by the differences in accident data dispersion across databases. Furthermore, boundary conditions, such as aircraft performance and operational weather conditions, are specifically considered in the ACRP model, while the SARA model estimates accident probability based on historical accident data alone.
2.3.4. PSZ/RPZ Dimensions
The PSZ/RPZ dimensions impact risk calculations in each model. SARA calculates iso-risk contours (i.e., 1.00 × 10−4, 1.00 × 10−5, and 1.00 × 10−6) according to the Italian regulation, whatever the PSZ dimensions. In contrast, ACRP applies FAA-defined RPZ dimensions and assesses the risks solely within the specified RPZ boundary. Conversely, SARA determines the assessment area automatically based on the statistical distribution of accident data, while ACRP allows users the flexibility to expand the RPZ for a more comprehensive risk analysis. Both models require updates to the accident databases to ensure accuracy when applied to different geographical regions.
2.3.5. Case Study
Finally, the outputs from the SARA and ACRP tools were compared for two airports herein not disclosed for privacy reasons. In the case studies, the American RPZ was selected to match the area of the Italian PSZ, allowing for comparable risk assessment areas.
The first analysis involved a third-party risk assessment for an airport with a 3330 m runway, handling around 70,000 yearly movements across 58 aircraft types. The iso-risk/crush likelihood contours generated by SARA and ACRP are shown in
Figure 9a,b, respectively. Although the calculated risk magnitudes are comparable, the contour shapes differ significantly. SARA calculates risk from the runway end, while ACRP bases its calculations from the start of the Runway Safety Area (RSA), aligning with ICAO Annex 14’s Runway End Safety Area (RESA) definition [
3]. Moreover, ACRP considers the runway required distance versus aircraft performance via NOD, and the runway’s declared distances such as ASDA and LDA. In contrast, SARA uses the total runway length for the take-off movements and the LDA for landings.
The second case study examined third-party risk for two parallel 3900 m runways, accommodating 260,000 yearly movements across 86 aircraft types [
60]. The results in
Figure 10 confirm similar trends: contour shapes differ as in the first case study, and dimensions are similar at Runway End 1 but diverge at Runway End 2. This variation results from the different analytical approaches: SARA’s contours are based on movement numbers, while ACRP also incorporates climatic conditions. Favorable wind conditions at Airport 2 contribute to smaller contours in ACRP’s analysis.
Table 9 details the maximum dimensions (width and length) of each contour calculated by SARA for both case studies, providing a basis for comparison with ACRP’s predefined assessment area. Indeed, ACRP evaluates risk only within a user-defined area, which, in these case studies, was set to the maximum dimensions of the 1.00 × 10
−6 iso-risk previously calculated by SARA.