ENERGY COMPLIANCE, INC. Rigorous Compliance. Defensible Programs. HomeWhitepapers › EC-WP-104

Foundations · EC-WP-104

NERC Compliance Monitoring & Enforcement (CMEP)

CMEP is the gear that turns mandatory standards into actual compliance pressure. It is how Regional Entities and the ERO Enterprise determine whether registered entities are doing what the standards require — and what happens when they are not.

CMEP is the gear that turns mandatory standards into actual compliance pressure. It is how Regional Entities and the ERO Enterprise determine whether registered entities are doing what the standards require — and what happens when they are not. Every Generator Owner, Transmission Operator, RC, BA, and DP operates inside this framework, whether they think about it daily or only when an audit notice arrives. Your last clean audit doesn't mean you have a good compliance program. It might mean the Region hasn't looked at the right thing yet. There are five monitoring methods. Each carries a different procedural footprint. Knowing which one is happening to you on a given day is the difference between preparation and reaction. Self-Reports are the cheapest violations to mitigate. Audit findings are the most expensive. The difference is who found it first. Risk-based oversight isn't random. Knowing what makes you a higher-risk target lets you reduce the target. Mitigation that addresses symptom and ignores cause buys you the same finding next cycle. Causation is the audit-defensible response. Penalties scale to risk and to behavior, not to paperwork. The same finding produces different penalties depending on what you did before, during, and after. From the Field Practitioner perspectives that frame the chapter ahead. CMEP isn't paperwork.

Contents

  1. Foreword
  2. Purpose of Compliance Monitoring and Enforcement
  3. Roles of NERC, Regional Entities, and FERC in Oversight
  4. Risk-Based Oversight Philosophy and Reliability Impact
  5. Compliance Monitoring Methods and Tools
  6. Audits and Spot Checks Explained
  7. Self-Reporting, SelfCertifications, and Event-Based Reviews
  8. Investigation and Enforcement Process
  9. Mitigation, Corrective Action, and Risk Reduction
  10. Penalties, Sanctions, and Regulatory Review
  11. Due Process, Transparency, and Appeals
  12. Common Misconceptions About Compliance and Enforcement
  13. Compliance Oversight in Practice and Ongoing Evolution
  14. Glossary
  15. About the Author
  16. About Energy Compliance, Inc.

Read offline

The complete reference is on this page. The PDF is for circulation inside your organization.

Download the PDF

Foreword

Foreword

This professional reference is one of a series Energy Compliance, Inc. publishes for registered entities and the people who run their compliance programs.

I’ve spent more than thirty years on every side of the bulk electric system. I’ve operated control centers as a Reliability Coordinator, Transmission Operator, and Power System Operator. I’ve audited grid facilities and signed off on findings as a senior compliance auditor. I’ve worked enforcement matters from inside the regulator’s process. For the last several years I’ve advised registered entities directly through the firm I founded.

The entities that do reliability well share a common habit. They take the standards seriously without confusing them with reliability itself. They know that a NERC Reliability Standard is a floor, not a ceiling. They know that compliance is something an auditor evaluates, but reliability is something a system either delivers or doesn’t. They prepare for audits by building programs that survive real questions, not binders that look thick.

That’s the perspective these references try to share. Each one focuses on a single topic. A standard family, an operational function, a regulatory framework, or an emerging industry challenge. Each one walks through how the topic actually works.

These references are written for the compliance manager who wants to understand the system, not just memorize requirements. For the legal counsel who has to brief a board honestly. For the senior operator who’s been told that compliance and reliability are the same thing and suspects they aren’t. And for the new compliance hire who got handed a binder and told good luck.

These references aren’t marketing material disguised as content. They’re the result of three decades of doing this work and watching it succeed and fail. I’ve written them in the same voice I use in a control room or in front of a Regional Entity audit team. Direct, evidence-grounded, honest about what the standards do and do not require.

Energy Compliance exists because most of the consulting offered to registered entities today is structured for billable hours rather than for outcomes. Every engagement is led by one senior practitioner. We don’t bring five people to a meeting that needs one. We automate the work that should be automated. We apply senior judgment to the work that requires it. If that approach matches what you’re looking for in a compliance partner, the back of this reference has our contact information.

If not, the reference still belongs to you. Take what’s useful. Apply it well. And remember the only test that ultimately matters: when the system needs to perform, does it?

Rob Smith, Founder, Energy Compliance, Inc.

EC-WP-104 NERC Compliance Monitoring and Enforcement Explained

Chapter 1

Purpose of Compliance Monitoring and Enforcement

End-of-Chapter Summary

Compliance monitoring and enforcement activities are intended to enforce mandatory Reliability Standards and to otherwise ensure reliable operation of the bulk electric system. Compliance monitoring and enforcement activities ensure that there is accountability, transparency and due process, and at the same time clearly distinguish compliance from issues related to grid reliability. The enforcement framework will focus on risk-based enforcement and remedies to reduce reliability risk as efficiently as possible while also ensuring that any enforcement actions are properly focused on deterrence and not solely on punishment.

Chapter 2

Roles of NERC, Regional Entities, and FERC in Oversight

Within the NERC Compliance Monitoring and Enforcement Program there is an allocation of responsibilities among the Standard Setting Body (SSB) – the North American Electric Reliability Corporation (NERC) – the Monitoring Body (MB) – the Regional Entities – and the Law Enforcement Body – the Federal Energy Regulatory Commission (FERC). This allocation was specifically established to achieve effective monitoring and enforcement of grid reliability while providing checks and balances to ensure accountability for compliance and due process for all parties involved. NERC is the Electric Reliability Organization (ERO) for North America. As ERO, NERC is responsible for implementing the overall compliance monitoring and enforcement program, the Rules of Procedure and regulating the Regional Entities. In addition, NERC performs reliability studies, disturbance analysis and technical research in order to determine the focus of its oversight activities and to develop reliability standards. One of the key functions of NERC within the compliance oversight framework is to ensure consistency. By prescribing uniform compliance monitoring and enforcement mechanisms for all the registered entities, NERC achieves the desired level of consistency in terms of audit methodologies, investigation procedures, expected mitigation measures and penalty criteria. This achieves compliance oversight consistency at the regional level, thereby ensuring adherence to continental reliability standards and norms prescribed by ERC. NERC delegates day-to-day compliance monitoring and enforcement authority to Regional Entities (REs) in specific regions of the grid. As such, REs are responsible for, among other things, performing audits; reviewing self-reports and self-certifications; investigating alleged noncompliance; and working with registered Entity personnel to address mitigation and corrective actions necessary to correct a noncompliance. Although REs operate directly in their respective regions, they act only as agents of NERC. Regional Entities (REs) undertake market education and outreach activities. In particular they run seminars, hold information discussions with market participants and do liaison work with accredited Certifying and Registration Bodies in

order to enhance awareness of the compliance and assurance regime without introducing any additional administrative burden. Federal Energy Regulatory Commission (FERC) Regulations The Federal Energy Regulatory Commission (FERC) retains ultimate regulatory authority over the reliability framework. FERC has certified NERC as the Electric Reliability Organization (ERO), approved the Reliability Standards, and reviews enforcement actions and penalty determinations. This FERC oversight of compliance monitoring

and enforcement ensures the public interest is served and that enforcement activities are carried out in accordance with FERC regulations and federal law. It’s important to note that FERC has an approving role in enforcing decisions made by NERC. When enforcement actions are proposed by NERC, FERC has the right to review and approve them. This level of oversight adds an extra layer of accountability to the enforcement actions as well as providing a level of objectivity to the decision-making process. FERC can also order NERC to revise standards or alter their monitoring procedures if FERC determines that there are gaps in reliability that need to be addressed. The separation of responsibilities among NERC, the Regional Entities, and FERC is an integral part of the reliability framework. The development of reliability standards is an industry activity, the compliance with these standards is enforced by the Regional Entities to whom FERC has delegated this responsibility, and FERC exercises overarching regulatory authority. This separation of responsibilities serves to mitigate the potential for conflict of interest and to enhance the legitimacy of the reliability framework. The oversight of the activities of audits conducted on other premises is coordinated by means of formal procedures, reports and reviews. Compliance trends, audit findings and enforcement experiences are used to refine and develop standards and processes for this coordination in order to provide an ongoing improvement process while maintaining the separateness of the individual audited organizations. NERC, Regional Entities, and FERC all have distinct roles in the compliance monitoring and enforcement process. It is helpful to understand the overall balance of expertise, independence and accountability that each provides to ensure that bulk electric system reliability is addressed appropriately.

End-of-Chapter Summary

The compliance monitoring and enforcement process is achieved through a delegation of Reliability Monitoring and Enforcement responsibilities from FERC to NERC and to the Regional Entities. NERC provides the rules for Reliability Monitoring and Enforcement, the Regional Entities perform the reliability monitoring and enforcement on a day-to-day basis, and FERC provides the delegated regulatory authority.

Chapter 3

Risk-Based Oversight Philosophy and Reliability Impact

Risk-based oversight is a core of the NERC Compliance Monitoring and Enforcement Program. Rather than applying broad brushstroke scrutiny to each and every Standard, Rule, or policy and to each and every registered Entity, the FERC decides which requirements and which aspects of compliance to scrutinize closely based on the FERC’s assessment of the risk to the reliability of the BES if the applicable requirement(s) are not met. The structure of the BES supports a riskbased approach. Resources cannot be spread uniformly to address every potential issue if the BES is to operate efficiently and effectively to provide reliable service to its customers. Reliability Standards may address a wide range of risk including but not limited to catastrophic failures, loss of synchronization, major degradation, unusual transfers and other events determined by the FERC to be risk-related. Some requirements will pertain to real time operating conditions posing an immediate risk to the reliability of the Bulk Power System (BPS). Other requirements will address ongoing planning processes and/or programmatic measures that may not have an immediate risk, but instead have the potential to introduce risk at a later date. Risk-based monitoring would focus on providing FERC with insight regarding the severity of risk at a particular entity, taking into account both the number and the nature of individual Reliability Standards violations for a given entity. Such insight can inform the determination of enforcement actions necessary to mitigate risks to BPS reliability. Violation risk factors and time horizons are indicators that help convey the expected reliability impact of non-compliance with the material listed in tables A.1 and A.2. The violation risk factors represent the extent of potential impact on reliability as a result of non-compliance, while the time horizons indicate whether the reliability effects are near term, intermediate or long term. They are used to help focus compliance verification efforts in accordance with Table I, but do not in any way change the mandatory nature of the requirements. Risk-based oversight that takes into account the system context The reliability impact of noncompliance may differ depending on the system conditions, the entity’s role within that system and the environment in which it operates. The commissioner considers the system context and the entities’ circumstances when carrying out activities to assess reliability impact in a manner that is appropriate to the situation. One of the main elements of the risk based oversight system is efficient use of resources. Oversight activities in areas with high risk to public health are prioritized in relation to minimum necessary regulation and administrative tasks, thereby minimizing unnecessary workload while maintaining a high level of monitoring and surveillance activities in areas where the consequences of reliability failures are the highest, and thereby ensuring both

efficient and effective regulation and good stakeholder relations for the regulated activities. Risk-based supervision does not reduce accountability: all regulatory requirements remain binding and any non compliance is evaluated. The difference is that risk-based approaches affect the prioritization and treatment of individual events or situations, and do not alter the overall nature of supervisory responsibilities. A risk-based approach does therefore not diminish in any way the need for and effect of regulation on market conduct and firm practices. Reliability performance data, disturbance analysis and compliance trends are used to update risk-based focus areas for Reliability Monitoring, audit scope and enforcement activities in accordance with the FRR Compliance Plan. NERC and the Regional Entities will use the results of this analysis to make adjustments to their Reliability Monitoring focus areas, audit scope and enforcement activities as risks in the transmission system evolve. This fact sheet is designed to help you understand how the risk-based oversight (RBO) philosophy influences NRC enforcement actions for potential noncompliance. It explains why enforcement actions or penalties may vary significantly with respect to specific compliance issues and licensees. The RBO philosophy recognizes that enforcement actions relating to compliance issues involving reliability risks should be based on differences in reliability risks, not because of any inadequacy in Commission regulations or inconsistent enforcement. In other words, the RBO philosophy is more focused on outcomes and less on forms and procedures.

End-of-Chapter Summary

Risk-based oversight involves exercising NERC’s compliance monitoring and enforcement authorities in a manner that is focused on the potential reliability significance of NERC violations. The tools of violation risk factors, time horizons and contextual evaluation are used to allocate resources to those activities and actions where they will have the greatest reliability benefit while at the same time providing appropriate incentives, protections and safeguards for fairness. In other words, risk-based oversight is about

taking a system-wide view of risk and implementing enforcement procedures that differentiate between violations on a risk-sensitive basis rather than on the basis of adherence to specific procedures.

Chapter 4

Compliance Monitoring Methods and Tools

As part of NERC’s Compliance Monitoring and Enforcement Program, Monitoring is accomplished through the use of a variety of methods to verify that Registered Entities are complying with applicable Reliability Standards. The methods are designed to accomplish several goals, including providing flexibility, proportionality, effectiveness and to support risk-based enforcement and due process principles. The methods used for compliance monitoring will depend on the requirements being checked, the role of the registered facility, and the potential reliability risk associated with non compliance. There is no single method that will be applicable in all circumstances. A combination of methods will be used to assess overall compliance performance in a risk-based manner. Audits are the most detailed form of compliance monitoring. This activity entails examining records and other evidence of compliance with multiple standards and requirements at varying times, which may be on a scheduled basis or in response to a specific issue that has been raised. Audits allow a thorough assessment of compliance programs, processes and activities over a given time frame. A spot check is an audit procedure that focuses on a limited aspect of the audit. Rather than looking at the audit scope as a whole, a spot check examines one or more specific standard, requirement or issue. Use a spot check to monitor emerging issues, follow-up on previous audit findings or look at specific compliance issues in greater detail. Self-certifications are statements provided by an Accredited Bonding Organization (ABO) and other registered entities attesting to their compliance with a specified condition or standard. Self certifications contribute to the ongoing awareness of compliance by the registered entity and may assist in the early detection of matters requiring investigation outside of the regular audit cycle. Self certifications are based on an ABDO’s/government authority’s reasonable assurance of the registered entity’s compliance and are validated/verified by the relevant audit authority. Self-reporting is an important element of the compliance framework. All registered entities are expected to report instances of noncompliance if they become aware of any. The purpose of self-reporting is to enhance a culture of compliance without imposing heavy penalties for non-compliance. The reporting of self-identified breaches assists in resolving issues

in a timely manner and enables the regulator to develop a more informed response. An event-based review is performed after a reliability event has been identified as the result of a system disturbance, misoperation, etc. It is to be used to try to determine if a compliance issue played a role in the observed

system behavior. The event-based monitoring system is intended to foster learning and provide a means of accountability when non-compliance is suspected. Each monitoring method has associated processes, evidence expectations and review criteria. These provide a framework to provide regional consistency while allowing for flexibility to accommodate varying reliability conditions. These monitoring methods are subject to the policies and procedures as outlined by NERC and are developed using risk based methodologies. Our compliance monitoring activities are not mutually exclusive. Results obtained from one activity can often be used to enhance the effectiveness of other compliance monitoring activities. For example, if the audit findings indicate the need for an increased number of spot checks, or if a company reports a number of non-compliances that warrants an audit. Once you have a broad understanding of compliance monitoring methods, you can better appreciate how field operations may be carried out. Having a variety of monitoring tools at your disposal helps to balance the compliance monitoring program so that enforcement is both strict and fair, yet also as efficient as possible while always being risk-based.

End-of-Chapter Summary

Our Compliance Monitoring activities make use of a number of audit, inspection, selfvalidation, self declaration and ad-hoc review techniques as required for the specific circumstances. Again the combination of techniques and the frequency with which they are performed depends on a number of factors including risk, complexity and the context of the operation. Ultimately they provide assurance for Accountability, Transparency and Reliability (ATR) across the business.

Chapter 5

Audits and Spot Checks Explained

Audits and spot checks are compliance monitoring tools used in the NERC Compliance Monitoring and Enforcement Program to verify compliance with Reliability Standards. While both are forms of compliance verification, audits and spot checks are distinct in terms of focus, objectives, and application, and the utilities need to understand these differences in order to understand how the compliance verification activities are tailored to the specific reliability risk and individual circumstances. Audits means audits of a registered entity’s compliance with one or more Reliability Standards over a designated audit period. The audits are structured, evidence-based evaluations of registered entities’ activities and practices to determine whether relevant processes were in place and activities were performed as needed. Audits may be conducted on a regular cyclical schedule or on an ad hoc basis in connection with identified reliability issues. A list of requirements assessed during an audit, together with the evidence provided by the registered entity to demonstrate compliance with each requirement. The audit process involves a number of stages including: a pre-audit notification; submission of required documents and records; interviews with key personnel; and a post-audit review of audit documentation. Audits are not concerned with operational efficiency or best practices. They are concerned with whether mandatory elements of the standard have been addressed. Audit findings record only whether each requirement has been met or not. This clarifies the focus and the limits of compliance auditing. Spot checks are used for a specific audit task in respect of an identified requirement, standard or reliability concern. They are not a full audit but a validation against a number of criteria in a specific instance at a specific time. They can be used to target a number of reliability concerns as they arise, or to validate the effectiveness of corrective action undertaken or to formally audit specific aspects of compliance. A spot check is generally understood to be of a more limited scope and nature than an audit. It allows the monitoring body to deal in a focused manner with specific issues arising in relation to the operation of a Subsidiary, or to investigate in a more limited fashion a particular matter, thereby reducing to a minimum the burden on the Subsidiary concerned. It is an important tool of risk-based supervision as it enables the monitoring body to focus on areas of particular risk or where there are time constraints. The Audit and Compliance Division applies due process standards in its performance of audits and spot checks of registered entities. This involves giving registered entities sufficient notice of a review or audit and an opportunity to produce documentation and to make comment on any draft conclusions that are formed. In carrying out audits and spot checks, the Compliance Division records its findings in detail, and

according to stated criteria, in order to determine the appropriate conclusions to reach in relation to a particular entity. The results of the audit and/or spot check could be: - No noncompliance was detected Recommendations for increased awareness - Potential noncompliance was detected and would require enforcement activity to confirm compliance. It is often through the early detection of potential risks, however, that significant mitigation and risk reduction can be achieved. Audits and spot checks also contribute to the broader reliability learning. Trends that emerge from an accumulation of audits and spot checks across different market participants or regions can feed into guidance development, outreach activities and standard revision. These accountability mechanisms hence contribute to learning and improvement. Audits and spot checks are critical components of a compliance program and are formal, independent and documented activities to verify certain aspects and are therefore a type of structured evaluation in relation to reliability risk. The purpose of these activities is to ensure consistency of enforcement activities while providing flexibility to accommodate the variety and diversity of the BES.

End-of-Chapter Summary

Audits and spot checks are compliance monitoring tools used by auditors to assess compliance with NERC Reliability Standards. An audit is a retrospective review of a specific time period. A spot check is a limited review of specific aspects of a Reliability Standard or related to a condition identified during a risk-based audit. Audits and spot checks are an important risk-based compliance monitoring tool that helps ensure compliance with NERC Reliability Standards in a manner that provides due process and timely notification of potential reliability-related compliance issues.

Chapter 6

Self-Reporting, SelfCertifications, and Event-Based Reviews

Self-reporting, self-certifications and event-based reviews are a key component of the NERC Compliance Monitoring and Enforcement Program. These provide an additional tool to complement audits and unannounced spot checks to ensure on-going compliance monitoring, the timely identification of compliance issues and adherence to risk-based procedures. Self-reporting is the underlying principle for registered entities being responsible and proactive in reporting instances where potential non compliance is discovered. Once a registered entity discovers a potential non-compliance condition affecting a Reliability Standard, the condition should be reported using established procedures. This encourages high levels of disclosure and enhances the risk of non-compliance being addressed as quickly as possible. Note that self-reporting, by itself, is not an admission of fault or intent. The purpose of self reporting is to provide an early indication to regulatory bodies of an event that may have the potential to cause reliability impact such that the regulatory bodies can determine if further investigation is required. As stated by NERC and the Regional Entities, self-reporting is a key aspect of a reliability culture that values learning and improvement. Self-certifications are a way to encourage on-going awareness of compliance issues. In this context, a self-certification is the declaration of compliance with selected provisions for a specific period by the entity itself. These self-certifications encourage the entities themselves to assess their internal controls, accountability and encourage the supervisory authority to gain a broader understanding of on-going compliance trends throughout the year as opposed to during the regular on-site audits. Self-certifications are generally limited in scope and are selected on a risk basis. Self-certification involves a risk-based assessment by the AEOI reporting obligation related-party Registered Legal Entity and any certifications should be verified. Inaccurate or incomplete self certifications may lead to further scrutiny or actions. Event-based reviews occur in FRR/ VRR/SHR/ESS when a disturbance in the power system occurs, protection misoperates or any other reliability event is detected. These reviews consider the extent to

which non-compliances may have contributed to the observed system performance. Event-based reviews are not limited to determining whether the events described contain non-compliances; they are also intended to aid reliability learning and improvement. At the event-based review, the regulatory body will focus on operational data, protection system performance, and regulatory requirements to look for any non-compliance that needs correction and/or enforcement action. The activity will be co

ordinated among the registered entities and personnel involved. Reviews conducted on an event-driven basis identify differences between compliance and performance. A reliability event does not necessarily mean noncompliance and noncompliance does not necessarily mean an event. Event-driven reliability monitoring provides a mechanism for examining these distinctions without confusing the consequences of nonperformance with the nonperformance itself. Self-reporting, self-certifications and event-based reviews complement each other in a dynamic risk-based assurance framework. Non-routine issues can be reported outside of scheduled audits, the risk-based audit plan can be adjusted and individuals can be held accountable for reliability. These monitoring tools give a better understanding of how the compliance oversight process occurs between assessments. These metrics are included in a broader system to enhance transparency, efficiency and continuous improvement of activities which support the reliability of the bulk electric system.

End-of-Chapter Summary

Self-reporting, self-certifications and event-based reviews complement audit and spot checks to ensure a continuous and risk-based compliance monitoring regime. The tools promote transparency, early detection of potential non-compliance and lessons learned from system events. These tools and procedures are essential for maintaining accountability and fostering a reliability improvement culture.

Chapter 7

Investigation and Enforcement Process

When a potential noncompliance with a NERC Reliability Standard is discovered, the Compliance Monitoring and Enforcement Program is responsible for carrying out a formal investigation and enforcement activity to assess the nature of the potential noncompliance and its corresponding penalty, in accordance with the FERC regulations and procedures set out in the CMEP Process Document. The CMEP process is characterized by transparency, procedural fairness, and due process, all the while remaining focused on ensuring that the enforcement activity is proportionate to the level of reliability risk posed by the alleged noncompliance. The Investigation procedure outlines the activities required to assess whether an incidence of non-compliance with ICAO Annex 19 regulatory requirements occurred in accordance with the procedure provided in Part VI, Division I, Section 6.4.3 (3) An investigation will be carried out when audit or spot check findings, self-reports, self-certifications, or reports resulting from the analysis of a specific event or phenomenon are deemed credible on reasonable judgement by the Management as providing valid information that may have been gathered through the audit and/or spot check process or through the collection of self-reported or self-certification information or results of analysis of events and phenomena. The commencement of an investigation should not be construed as a determination that non-compliance occurred. It is a determination of the need to verify the accuracy and merit of the information gathered. within an investigation, regulatory bodies will collect and examine the data they have gathered to determine if any infringement occurred and if so, for how long and under what conditions. A registration body will also ask the applicable entity for information, to get an explanation for the circumstances and to provide an opportunity for it to provide comment on the data it has been asked to provide. The investigation process involves evaluation of reliability risk. When NERC determines that the condition posed an actual or potential reliability risk to the BES the Commission determines whether to take enforcement action, what orders if any should be imposed, and what corrective actions should be required and when they should be accomplished. Reliability Standard Enforcement Proceedings Once a determination is made that a violation has occurred, enforcement proceedings will establish the procedures and methodologies to be followed to remediate the noncompliance. The reliability standard enforcement proceedings will establish the criteria to be considered in connection with determining the appropriate remediation in response to the nature of the violation as it relates to the risk to reliability, extent of noncompliance and other relevant factors. The primary focus is expected to be on mitigation and corrective actions as opposed to punitive actions, in

line with the emphasis on managing reliability risk and preventing future disruptions. Information related to enforcement actions are recorded in enforcement notices and enforcement resolutions. Enforcement notices and resolutions document the violation, the applicable standard and the agreed to corrective actions for the violation. Enforcement notices and resolutions are an important tool to ensure enforcement actions are properly documented and serve to ensure enforcement actions are conducted in a transparent manner and that there is some consistency among enforcement actions in the event of multiple enforcement actions for the same violation. Due process protection is maintained throughout the investigation and enforcement activities. Our processes provide sufficient notice to the registered entity, who is given an opportunity to review the materials upon which the determination is based, to present its views and provide additional information. The timeframe and process for determining compliance or imposing penalties are clearly set out to provide fairness and certainty. Violation investigations and enforcement proceedings are subject to oversight and audit. Regional Entity determinations are audited by NERC and FERC reviews and must approve any enforcement actions that result in penalties. This section of NURE-0757 helps the readers understand the investigation and enforcement process of NRC regulatory procedures. The enforcement and investigation process can be misunderstood as an ad - ministrative process, causing confusion concerning how NRC views non compliance. A key goal of the enforcement and investigation process is to be as educational and non punitive as possible. It balances the need for accountability and a certain level of visibility (transparency) with a desire to learn lessons that will help improve reliability while minimizing punishment.

End-of-Chapter Summary

The investigation and enforcement process is a structured, risk-based process to assess potential non compliance with NERC Reliability Standards. Investigations focus on the facts of the situation and the reliability implications, while enforcement focuses on compliance, remedial actions and due process. This process contributes to accountability and reliability enhancements within the compliance framework.

Chapter 8

Mitigation, Corrective Action, and Risk Reduction

Mitigation and corrective action are key components of the NERC Compliance Monitoring and Enforcement Program. When noncompliance is discovered, the goal is to minimize reliability risk and prevent similar events from occurring in the future rather than to determine fault. Mitigation activities are scrutinized to determine if the underlying cause of the noncompliance has been addressed and reliable system performance restored. Mitigation plans are developed by registered facilities for each instance of noncompliance that is identified. Mitigation plans describe the measures to be taken by the facility to correct the noncompliance, address its root causes, and prevent the noncompliance from occurring again. The oversight body determines that the mitigation plans are adequate to address the nature and level of risk presented by the noncompliance. All corrective actions are targeted at the root cause of the identified violation or exception rather than the symptoms. Corrective actions may include revisions to procedures, training, or system components, as well as realigning data or procedures to fit established practices or increasing the level of regulatory oversight. As stated by NERC, corrective actions are to be meaningful in terms of their impact on reliability risk, rather than simply being a paper exercise. Time is of the essence in the mitigation of reliability impacts related to non-compliances. The level of urgency varies according to the reliability impact and time frame related to the non-compliance. Those presenting more urgent (immediate or short term) reliability risks need to be addressed more quickly, while those that present more longer term risks may be dealt with more simply through a more gradual or a program-based approach. Verification of mitigation activities Compliance verification for mitigation activities shall be provided by the registering entity. The entity shall verify that the mitigating actions have been implemented and shall document that the associated effectiveness claims have been verified. Verification of corrective actions Verification of reliability risk mitigation of corrective actions shall be implemented in accordance with Table 2.3. Mitigation and enforcement are related but different. Enforcement is about dealing with non-compliance whereas mitigation is about reducing risks and improving standards. A good mitigation effort can lead to a more favourable enforcement outcome as it demonstrates a pre-emptive and proactive approach to addressing problems that have been identified. As reliability work is performed to mitigate potential future problems, lessons learned become part of the overall body of reliability knowledge. Trends and problems identified in mitigation work may also impact and guide future guidance documents, outreach activities or standard revisions. Mitigation and Corrective Action covers in detail the mechanisms that support reliability outcomes

whether or not a generator is formally determined to be in compliance. It provides a strong risk reduction and learning focus to promote accountability.

End-of-Chapter Summary

Mitigation and Corrective Action is aimed at reducing reliability risk and is designed to ensure that non compliances do not occur again. It ensures that the mitigation activities get to the source of the problem, is commensurate to the risk involved and can be verified and audited. The Mitigation and Corrective Action process supports the reliability improvement aspect of the compliance framework as opposed to being a punitive measure.

Chapter 9

Penalties, Sanctions, and Regulatory Review

Penalties and sanctions are one element of the Compliance Monitoring and Enforcement Program, but they are not the focus of the NERC effort. Instead, penalties and sanctions serve a purpose to reinforce the accountability of all entities and behavior of concern that impacts reliability of the bulk electric system, while being proportionate to the level of risk presented by non-compliance. This step determines the enforcement outcome(s) following a confirmed noncompliance. This determination will take into account various considerations, including but not limited to, the reliability impact or potential reliability impact of the violation, its duration, whether the noncompliance was self-discovered, and whether the violating entity implemented corrective measures to mitigate the noncompliance. This enforcement outcome is based on a risk-based approach rather than penalty based on a formula. Monetary penalties are not always the consequence for violating critical infrastructure reliability standards. While monetary penalties can be imposed in certain cases, it is not always the consequence for non-compliance. For low-risk reliability failures or where the risk is quickly rectified, FERC and NERC typically require mitigation, correction or non-monetary penalties. FERC and NERC also reiterate that monetary penalties should not be the normal or first response to compliance with regulations that ensure the reliability of critical infrastructure. Non-penalty sanctions are any penalties that are not monetary, such as requiring the licensee to provide more detailed reports, to be under closer observation, or to accomplish specific corrective actions. Non-penalty sanctions are designed to directly mitigate reliability risk and to serve as a tool to encourage improved performance. All penalty determinations are subject to review by the regulatory body. For example, the Regional Entities enforce Reliability Standards, but the NERC Executive Board reviews penalty determinations to ensure that Enforcement Actions for Violations of Reliability Standards are in accordance with the Enforcement Procedures and guided by risk-based principles. Enforcement Actions for Violations of Reliability Standards that include penalties are also subject to review by the FERC. The FERC’s review role provides an important check on enforcement discretion. FERC has the authority to ensure that any penalties proposed by the staff are reasonable

and are not inconsistent with the statute or the public interest. This role enhances the transparency, fairness and consistency of FERC’s enforcement efforts. The determinations of penalty and the enforcement resolutions for alleged non-compliance are recorded and are often disclosed to the public.

Disclosure serves to enhance accountability and accountability within the reliability framework, while protecting critical system information. It also serves to educate the industry regarding potential vulnerabilities and enforcement actions. Penalties and sanctions The purpose of penalties and sanctions will be clearer to all concerned if a view is taken of their place in the compliance picture as a whole. A penalty or sanction is part of the system to induce behaviour conducive to accountabiilty and reliability and cannot therefore be a measure of a system’s performance, or an indication of a utility’s quality of supply. Penalties and sanctions would be imposed in relation to assessments of risk, with appropriate considerations of scale and governance.

End-of-Chapter Summary

While penalties and sanctions are an important part of the enforcement process to ensure compliance and act as a deterrent, enforcement action is not solely focused on the imposition of penalties. The FRR focuses on enforcement outcomes that will most likely help to achieve reliability, based on the reliability risk associated with non-compliance, the individual circumstances involved, and the effectiveness of any steps taken to mitigate that risk. NERC and FERC provide the regulatory oversight necessary to ensure that any enforcement action is appropriate, consistent and aligned with the broader public interest.

Chapter 10

Due Process, Transparency, and Appeals

The Commission has established due process and transparency as cornerstones of its Compliance Monitoring and Enforcement Program. Fair, consistent and impartial enforcement of reliability standards with transparency promotes public trust in the reliability standard system. It also serves to protect RTO/ ISO and bulk power system stakeholders by providing fair procedures, rights and an opportunity for review. Due process is a critical component of compliance monitoring and enforcement activities carried out by the regulatory body across all aspects of the enforcement process. Notice will be provided to registered entities affected by compliance monitoring activities that identify noncompliance or enforcement action. In addition, an opportunity to: Present evidence to address compliance monitoring or enforcement findings; Reply to enforcement action notices or compliance monitoring findings ; Comment on operational circumstances and mitigating factors will be provided in order to ensure objectivity and a defensible enforcement process. Transparency fosters fair processes by providing all stakeholders with a clear understanding of requirements and outcomes. NERC and the Regional Entities have published the Rules of Procedure, Compliance Guidance and Enforcement policies on how monitoring and enforcement are conducted, thereby providing transparency of processes without imposing new or regulatory authority enforced requirements. FERC Order No. 841 requires Regional Transmission Organizations (RTOs) and Independent System Operators (ISOs) to provide detailed information on enforcement action taken against Market-Based Rate sellers that are found to engage in conduct that creates Reliability Risks that threaten the high reliability of the Transmission Grid. Some enforcement actions and penalty determinations are made public to the extent that the disclosure of specifics does not compromise the security and reliability of FERC’s systems. Transparency in Enforcement Actions promotes accountability, clarifies how market rules are enforced and how reliability risk is characterized. Appeal processes provide an additional layer of protection and accountability. A Registered Entity that disagrees with a determination made by a Reliability Manager, ERO or Regulatory Authority, or an enforcement action taken by an ERO Enforcement Authority, may challenge that determination or enforcement action through an established appeal process. Some appeal decisions may be reviewed by NERC and/or FERC. The enforcement process having an appeal component is designed to provide an additional layer of review and to add accountability to the actions of the ERO enforcement authority. The presence of appeals does not diminish the importance of enforcement responsibility. In fact, enforcement responsibility is enhanced with an appropriate appeals process to ensure that sound,

logical, and defensible decisions are made. Enforcement agencies should be able to provide a clear and succinct documentation of their enforcement findings and make determinations based on credible technical evidence and applicable standard requirements. Ensuring appropriate balance between confidentiality and transparency is an essential aspect of all compliance monitoring and enforcement activities. While it is often necessary to keep information confidential in order to ensure the integrity of stakeholders, encourage full participation, or in order to protect information about critical infrastructure, full disclosure is required to achieve appropriate accountability and lessons learned. Understanding due process and transparency explains the reasoning behind the detail required in the Compliance Framework in relation to operational procedures and record keeping. This framework supports the reliability objectives and the rights of registrants and promotes trust in the regulation.

End-of-Chapter Summary

Due process and transparency are core elements of the NERC Compliance Monitoring and Enforcement Program. Defined procedures, notice and opportunity to respond, as well as, appellate procedures all support due process. In addition, public reporting and Regulatory review of enforcement action provide another layer of transparency that enhances public confidence in enforcement activities while preserving necessary levels of confidentiality to ensure system security.

Chapter 11

Common Misconceptions About Compliance and Enforcement

Confusion exists, both within and outside of the reliability community, regarding the scope and function of the NERC Compliance Monitoring and Enforcement Program. Correcting these misconceptions is important to fully understand the role of compliance monitoring and enforcement in relation to the reliability framework and to effectively interact with the framework. Many people seem to equate compliance with reliability. These are not the same thing. Compliance generally means that an organization has implemented rules or standards that are required by regulatory bodies or other governing authorities. Reliability has to do with the actual performance of the BES under real conditions of use. Problems can still occur frequently in a system that was built in compliance with the relevant grid standards. Conversely noncompliance does not necessarily affect reliability since a large number of near misses or instances of noncompliance do not necessarily affect the delivery of power to consumers. What the compliance process attempts to ensure is the minimum level of safety and/or performance at a given point in time. It is not a guarantee against all reliability risks. Most people mistakenly think enforcement is punitive. While penalties and fines are part of the enforcement model, they serve as deterrents and to make non-compliance more expensive. The vast majority of non-compliances that result in enforcement actions are handled with mitigation, remediation and prevention of future failures. Fines are rarely assessed and are then commensurate to the level of risk associated with any reliability failure. The Rule also frequently misconstrues the effect of Guidance Documents, Audit Examples and other informal Communications. The applicable law is clear: only Reliability Standards and Formal Interpretations are binding. Guidance Documents, Technical Reports and Outreach Communications are provided for informational purposes to assist stakeholders and promote consistency and understanding of the Commission’s Reliability Standard requirements. Some believe that reporting a violation increases the risk of an enforcement action being taken. Reporting a violation is seen as a hallmark of a transparent and reliable compliance culture. Reporting a violation early in the process can reduce the severity of any enforcement action that may be taken and can help VIATRA to minimize the impact of any potential non-compliance. This is another one of those myths that have evolved from misinterpreting certain rules and regulations. The intent or purpose of non-compliance is not what is to be determined, but rather whether the requirements of the standard or regulation have been met. Enforcement action focuses on the impact of the reliability on safe and efficient operation and the required corrective actions, not on the intent or fault of the personnel involved. Audits are not performance audits. The

common perception that audit findings represent the overall performance of an organization is a misconception that should be corrected. Audits cover specific standards for specific time periods. They are not a measure of the operational effectiveness of an organization’s engineering practices, nor are they a measure of the competence of individuals and organizations involved in any aspect of a facility beyond the scope of the audit standards. Resolving these misconceptions will correct the expectations concerning compliance monitoring and enforcement. It will ensure that the Framework acts as a risk management and governance tool for reliability rather than an attempt to measure performance comprehensively. It is helpful to understand what is included and excluded from the concept of compliance oversight. Effective engagement from registered entities and stakeholders is only possible if they have a clear understanding. Compliance oversight should concentrate on achieving real risk reduction, enhanced transparency and a more dynamic and accountable AFCA.

End-of-Chapter Summary

There are a number of misconceptions about the purposes of compliance monitoring and enforcement. Examples include the ideas that compliance with the Standard necessarily means reliability, that enforcement activities are about punishing violators, and that guidelines are enforceable provisions. Dispelling these myths supports the principles of minimum requirements, risk-based enforcement, transparency, and the promotion of reliability through the reduction of fault rather than penalty.

Chapter 12

Compliance Oversight in Practice and Ongoing Evolution

The NERC Compliance Monitoring and Enforcement Program operates in a dynamic reliability environment that is constantly changing in response to a wide range of factors, including system conditions, new technologies and lessons learned from operating experience. While the underlying factors driving the compliance monitoring and enforcement program remain stable, the way in which compliance monitoring and enforcement activities are conducted must evolve in response to new risks and lessons learned by industry. Compliance oversight in practice is closely tied to other reliability activities. That is, instead of being done in isolation, reliability activities such as conducting vulnerability assessments, operational monitoring, disturbance analysis as well as compliance oversight activities interact with each other. So that lessons learned from audits, investigations and mitigation activities are actually used to determine the overall impact of reliability risks and how to adjust and improve the focus of the compliance oversight activities. Regulatory changes and risk-based oversight have driven a significant evolution of grid operations. Our oversight focus areas, audit scopes and monitoring priorities are reviewed and changed on an ongoing basis using performance and compliance data and disturbance analysis. This allows for focused oversight without overburdening operational activities and uniform scrutiny is only applied where it adds value to grid reliability. In addition, consistency and clarity in the application of oversight is a lesson learned from the experience of the regional blackout that occurred on 14 August 2003. NERC oversight of the Regional Entities, along with FERC review of the enforcement of the orders for each of the Regional Entities, provides a consistency across the regions and demonstrates to all others in the industry that there will be consistent application of compliance standards, enhancing the reliability of the interconnecting system. Consistency in this context is important in order to prevent variations in interpretation from creating a basis for potential disagreement. As it always does, technology continues to impact the compliance oversight function. More reliance on automation, smart grid controls, and other data-driven

operations practices have changed the way we as Reliability Managers determine and mitigate risks to the grid. Although the reliability standards remain technology neutral, our oversight function must also evolve to recognize changes in grid operations and the related risks. Our work is constantly evolving as a result of discussions with industry. Lessons learned from compliance monitoring and enforcement activities are shared through workshops, technical conferences and our reports. This promotes

transparency and mutual understanding of the role of regulation in ensuring safe and reliable operations. It is important to realise that compliance oversight is not simply about enforcing past expectations. Rather, it is about an ongoing cycle of checking learning from previous compliance monitoring activities, evaluation and adaptation. As system conditions or other circumstances change the ongoing Compliance Oversight Framework has to be adapted in order to continue to properly manage reliability risks in a fair, proportional and efficient way. Identifying where compliance oversight is “alive” in practice reveals that compliance oversight is a dynamic element of the reliability framework. It serves as a key accountability mechanism while also serving an educational purpose in a complex, dynamic and evolving BES.

End-of-Chapter Summary

Reliability of the Compliance Oversight Function The reliability of the compliance oversight function can change over time and is affected by risk-based priority, learning and experience. Alignment with the reliability activities in place at the time as well as regional consistency and the ability to adapt and adjust the compliance oversight activities also supports the reliability of the program. Enforcement of compliance as a governance tool to help ensure long-term reliability of the BES is thereby enhanced.

Glossary

Glossary

Audit - A comprehensive and structured Regional Entity review of a registered entity’s compliance with one or more NERC Reliability Standards for a particular audit period.

Bulk Electric System (BES) – The facilities and control systems that comprise an interconnected electric energy transmission network, and do not include facilities that become involved in the local delivery of electric energy to consumers. (NERC Glossary of Terms)

Compliance Monitoring and Enforcement Program (CMEP) A program of NERC and the Regional Entities that is intended to monitor, assess, and enforce compliance with the NERC Reliability Standards through established procedures and risk-based enforcement mechanisms.

Corrective Action Actions taken by a registered entity to address the cause of nonconformity and its own actions to prevent its recurrence; often referenced in the mitigation plan.

Enforcement Action - The formal process used to correct violations of a NERC Reliability Standard, including enforcement actions that may be mitigation, non-penalty, or penalty-based.

Federal Energy Regulatory Commission - An independent federal agency that is responsible for reviewing and approving NERC Reliability Standards as well as reviewing the FERC’s enforcement of Reliability Standards under the Federal Power Act.

Mitigation - measures implemented by a registered entity to address noncompliance and thereby to reduce reliability impact, as verified by the relevant regulatory authority.

NERC - The North American Electric Reliability Corporation, the Electric Reliability Organization (ERO) designated and certified by FERC to develop and enforce Reliability Standards for the bulk electric system in North America.

Regional Entity A Reliability Entity designated and appointed by NERC to perform monitoring and enforcement services within a defined region, under the direction of NERC and subject to FERC approval.

Risk-Based Oversight (RBO) Focuses compliance monitoring and enforcement efforts on those activities where noncompliance could have the greatest impact on power grid reliability, rather than evenly enforcing all standards.

Self-Certification is a compliance monitoring activity in which a registered entity certifies to NERC that it is in compliance with select Reliability Standard requirements for a defined period of time.

Self-Report - A disclosure submitted by a registered entity to report potential noncompliance with a Reliability Standard.

Violation Risk Factor - The VRF is assigned to a particular Reliability Standard requirement to reflect the Reliability Organization’s judgment as to the expected reliability impact of noncompliance.

This glossary is intended to convey a general understanding of terms and terminology as they may be referenced in NERC Reliability Standards, Rules of Procedure, or in other NERC public reliability documents. It does not change or supersede the definitions as contained in the NERC Glossary of Terms.

About the Author

About the Author

Rob Smith is a senior electric industry professional with over thirty years of experience across every major function of the North American Bulk Electric System. His work spans reliability coordination, transmission operations, regulatory compliance, and cybersecurity reliability.

Rob has worked directly in real-time grid operations as a Reliability Coordinator, Transmission Operator, and Power System Operator within RTO/ISO and utility control center environments. He has also held senior regulatory and oversight roles, including senior compliance auditor and subject matter expert for NERC Reliability Standards. In those roles he audited grid facilities for compliance with applicable standards, evaluated the adequacy of mitigation actions, supported the development of violation notifications and settlements as part of FERC-directed enforcement actions, and participated in risk based oversight of utility mitigation activities.

Rob founded Energy Compliance, Inc. to bring senior, regulator-side compliance authority to registered entities directly, without the layered staffing, billable-hour overhead, and generalist advice typical of larger consulting firms. Every Energy Compliance engagement is led by Rob personally.

About Energy Compliance, Inc.

About Energy Compliance, Inc.

Energy Compliance, Inc. is an independent consulting and advisory firm focused exclusively on electric reliability, cybersecurity reliability, and regulatory compliance for organizations connected to the North American Bulk Electric System.

Our work supports registered entities, including Generator Owners and Operators, Transmission Owners and Operators, Reliability Coordinators, Balancing Authorities, and Distribution Providers. We work across NERC Reliability Standards, FERC orders, RTO/ISO market participation rules, Regional Entity oversight, and state regulatory frameworks.

We do this work differently than larger consulting firms. Engagements are led by a single senior practitioner with regulator-side experience. We don’t staff for billable hours. We staff for outcomes. Our deliverables are written to be operationally executable and audit-defensible, not to manufacture activity. Where automation can replace manual work, we build the automation. Where senior judgment is required, the senior is in the room.

Energy Compliance is not affiliated with, sponsored by, or endorsed by the North American Electric Reliability Corporation, the Federal Energy Regulatory Commission, or any Regional Entity.

Services Provided

Our services are written to be clearly defensible. Operationally executable in real time. Audit-defensible at compliance review. Every deliverable is structured for the auditor’s question, not the consultant’s binder.

Energy Compliance services include, but are not limited to:

  • NERC reliability and compliance advisory support
  • Reliability governance and program assessments
  • Registration and applicability analysis
  • Operational and engineering reliability alignment
  • Compliance program design and improvement
  • Audit and enforcement support (non-advocacy)
  • Mitigation planning and Self-Report development
  • Training and executive briefings on reliability frameworks
  • Regulator-perspective program reviews

Each engagement is scoped to the entity’s role, function, and bulk system impact.

ENERGY COMPLIANCE PROFESSIONAL REFERENCE

Rigorous Compliance. Defensible Programs. Energy Compliance, Inc. partners with registered entities on the institutional and technical questions that define strong reliability and cybersecurity programs, from classification through audit through enforcement response.

N ERC CO MP LIANC E S ENIO R ADV ISO RY Program support, interpretation, and audit Direct engagement on complex reliability preparation. questions.

I ND USTRY ENGAGEMENT AUD IT D EFENSE Standards development and working-group Notice of Penalty response and settlement participation. posture.

CONNECT WITH US Scan to visit

E N E RGY COMPL IAN CE , IN C. · EC-WP-104 · © 2026 · AL L RIGHTS RES E RV E D

Foundations