Substations aren't passive. They are dynamic operational control points where transmission decisions get implemented, voltage transformations occur, fault clearing takes place, and protection schemes engage. Most reliability events trace back to substation behavior — equipment, protection, switching. Programs that treat substations as static infrastructure miss where the action is. A power transformer is one of the most consequential pieces of equipment in the substation. Aging is slow. Failure is sudden. Circuit breakers are how the system isolates faults. A breaker that doesn't operate correctly is the difference between contained event and propagating one. Bus configuration determines flexibility. The configuration that worked in 1985 may not match today's loading and contingency profile. Instrument transformers are the eyes and ears of protection. CTs that drift change protection behavior, often invisibly. Switching is the most common substation operation. It's also one of the most consequential. A switching error de-energizes loads, grounds equipment, or initiates cascades. Maintenance is reliability work. Programs that defer maintenance to control budget produce findings and accelerate equipment failure.
Contents
- Foreword
- The Substation as an Operational Control Node
- Power Transformers: Functional Behavior and Reliability Consequence
- Circuit Breakers: Fault Interruption and Operational Exposure
- Bus Configurations and Operational Flexibility
- Instrument Transformers: Measurement Integrity and Protection Dependence
- Protective Relays: Fault Detection, Selectivity, and Misoperation Risk
- Capacitor Banks, Reactors, and Voltage Control Dynamics
- Station DC Systems and Control Power Integrity
- SCADA, RTUs, and Telemetry Integrity
- Switching Exposure and Configuration Risk
- Misoperations, Cascading Pathways, and Situational Awareness
- Glossary
- About the Author
- About Energy Compliance, Inc.
Read offline
The complete reference is on this page. The PDF is for circulation inside your organization.
Download the PDFForeword
Foreword
This professional reference is one of a series Energy Compliance, Inc. publishes for registered entities and the people who run their compliance programs.
I’ve spent more than thirty years on every side of the bulk electric system. I’ve operated control centers as a Reliability Coordinator, Transmission Operator, and Power System Operator. I’ve audited grid facilities and signed off on findings as a senior compliance auditor. I’ve worked enforcement matters from inside the regulator’s process. For the last several years I’ve advised registered entities directly through the firm I founded.
The entities that do reliability well share a common habit. They take the standards seriously without confusing them with reliability itself. They know that a NERC Reliability Standard is a floor, not a ceiling. They know that compliance is something an auditor evaluates, but reliability is something a system either delivers or doesn’t. They prepare for audits by building programs that survive real questions, not binders that look thick.
That’s the perspective these references try to share. Each one focuses on a single topic. A standard family, an operational function, a regulatory framework, or an emerging industry challenge. Each one walks through how the topic actually works.
These references are written for the compliance manager who wants to understand the system, not just memorize requirements. For the legal counsel who has to brief a board honestly. For the senior operator who’s been told that compliance and reliability are the same thing and suspects they aren’t. And for the new compliance hire who got handed a binder and told good luck.
These references aren’t marketing material disguised as content. They’re the result of three decades of doing this work and watching it succeed and fail. I’ve written them in the same voice I use in a control room or in front of a Regional Entity audit team. Direct, evidence-grounded, honest about what the standards do and do not require.
Energy Compliance exists because most of the consulting offered to registered entities today is structured for billable hours rather than for outcomes. Every engagement is led by one senior practitioner. We don’t bring five people to a meeting that needs one. We automate the work that should be automated. We apply senior judgment to the work that requires it. If that approach matches what you’re looking for in a compliance partner, the back of this reference has our contact information.
If not, the reference still belongs to you. Take what’s useful. Apply it well. And remember the only test that ultimately matters: when the system needs to perform, does it?
Rob Smith, Founder, Energy Compliance, Inc.
EC-WP-305 Operator Series Volume I
Chapter 1
The Substation as an Operational Control Node
The industry standards we’re asked to adhere to include topics like situational awareness, disciplined switching operations oversight and understanding configuration risk. Those standards aren’t meant to make us all engineers – they’re more about awareness of the interaction between SCADA systems and the operational decisions we make every day.
This book covers in detail the substation equipment from the Real Time Operations point of view. It provides a detailed description of the function of the various pieces of equipment in relation to power system reliability, how they interact with other system components and the impact on reliability due to
failures or misoperation. This is not a procedure instruction book. It is designed to provide an operational understanding of the functions of the various pieces of substation equipment.
Understanding the Bulk Electric System (BES) requires a good dose of sound judgment. And sound judgment requires a good understanding of the BES infrastructure. Substations are the hubs of the BES infrastructure. Increasing operator knowledge of substation components and their functions is necessary to maintain situational awareness and to effectively practice disciplined reliability monitoring.
From a field perspective, a substation is nothing more than the aggregation of pieces of equipment within a bounded area. From a control room perspective, it is a nexus (connection point) in the transmission grid at which various functions come together, such as electrical connections, protection functions and operational flexibility.
Ultimately all transmission interfaces are a form of substation buswork and breakers. All voltage transformations take place in transformer banks located in substations. All the reactive devices that affect the system voltage are also in substations, as are all the protection relays that monitor fault conditions on system lines. Because changes in system switching configuration result in changes in substation equipment, understanding substation arrangements is important to transmission operations.
A substation’s topology refers to its structural redundancy. While a radial structure may concentrate the risk of a breaker position, a ring bus provides some redundancy. And, in many cases, a breaker-and-a-half structure gives more operating flexibility and fault isolation. Each structure contributes to how the system behaves in case of failures, or maintenance outages.
Operational awareness involves understanding that the substation is a centre of connection and exposure. A bus fault can affect multiple transmission lines. A breaker failure can magnify the effects of a single event. A mis-operate on a transformer differential can affect entire segments of the network that include large amounts of load or generation. The operational impact of a fault in the substation rarely affects a single piece of protection.
Public disturbance analyses have shown that a number of incidents have occurred when the bus protection misoperations or breaker failures have acted as a catalyst to create a cascading condition of trouble. In some cases the initial fault of the piece of equipment involved was not so serious as the after effects caused by protective relays
or design configuration. These incidents drive home the importance of realizing not only the design purpose of a piece of apparatus, but also its operational interaction with other apparatus.
Operators often look beyond the simplistic one line picture of a substation. A substation is a functional node that can impact a great number of post-contingency parameters, such as contingency sensitivity, load transfer capability, restoration sequences, emergency action limits, etc. Knowledge of the bus arrangement, the location of normally open points and protection boundaries, as well as an
understanding of how alarm messages are derived from the monitoring system will allow an improved interpretation of the alarm messages and their relation to system behavior.
An electric substation not only serves as a geographical boundary but also an operational boundary between different systems. The lines of authority can get very confused at the substation. An individual may be responsible for the operation of certain pieces of equipment while having no authority over other pieces of equipment. Knowledge of who controls what, and how their piece of equipment interacts with other pieces of equipment in the substation and with other substations is vital for the protection of the power system. This knowledge is necessary for the coordination of mutual protection during abnormals.
This is a critical infrastructure element that forms a link between the generation, transmission and distribution networks. It is one of the nodes in the network controlled in real time and reliability of power delivery from such nodes has to be effectively managed. Understanding how equipment configuration impacts on normal and emergency states of the power system is critical for effective management of power delivery reliability.
End-of-Chapter Summary
Substations are critical operational control points where multiple elements intersect such as connectivity, protection and flexibility of operations. Understanding substation topology and relationships between equipment is key for control room personnel to develop a comprehensive awareness of their system and make informed operational and reliability centered maintenance decisions under both normal and abnormal operating conditions.
FROM THE FIELD
Substations aren't passive. They're operating equipment. The decisions made at and about them shape system reliability in real time.
A substation is where the transmission system is configured, switched, and protected. The configuration determines what the system can do.
Most reliability events trace back to substation behavior — equipment, protection, switching. Programs that treat substations as static infrastructure miss where the action is.
Chapter 2
Power Transformers: Functional Behavior and Reliability Consequence
Power transformers are one of the most valuable components of any substation. They are used to step up and step down voltages from the transmission level and sub-transmission level, to provide the interconnection for bulk generation sources to the grid, and to deliver load from one voltage level to another. However, a transformer is more than a simple voltage converter. They are also one of the most critical reliability components in the system. Their loading, cooling and protection responses can significantly impact the overall stability of the power system. Transformers are defined by interface capacity. Nameplate ratings provide a base capacity, but seasonal capacity ratings, cooling capacity and system operating conditions can provide effective limits. IEEE and other standards organizations have identified ambient temperature, time of day and cooling capacity as affecting transformer capacity. Therefore, when overloaded, load is that which is causing the transformer alarm to appear and caution should be exercised in interpreting the alarm in relation to cooling capacity and time that the transformer is operated in this condition. Load tap changers are another system complicating factor. Automatic changes to the tap on a load tap changer are made to control voltage levels; however, changing the position of the tap also changes the impedance of the transformer and the amount of reactive power being delivered and/or received by the transformer. Experience has shown that, during periods of stressed system conditions, a particular set of voltage control actions may affect the reactive load and power flow in the system in a manner that exacerbates adjacent transmission constraints. A key understanding is that changing the position of the tap on a load tap changer is not a benign or neutral action – it has system-wide implications. Cooling system degradation is an operational signal that should not be ignored. Loss of cooling stages can decrease a transformer’s loading capability and increase thermal stress. Several industry event analyses have documented transformer failures due to the combination of sustained overload and cooling system degradation. In each case, the alarm messages were received prior to the actual failure, but
were not always recognized and responded to appropriately. By recognizing the reliability consequences of cooling system degradation, the operational situation can be improved. Transformer protection is used to detect internal faults in the transformer and clear them as quickly as possible. All protection can be by means of differential relays, sudden pressure relays and over current relays, acting independently or in conjunction with each other. When any of the protection of a transformer operated, its effect on
the system is quite severe. In case of an autotransformer of substantial size, the loss of a transformer can affect two voltage levels in the system and the transferring of the load from the tripped transformer to the neighbouring system requires careful considerations of load transfer and system stability aspects. Most Transformer failure modes are as a result of internal faults, insulation breakdown, bushing failure or external fault contribution. A review of public disturbance reports indicate that failures of the bushings can sometimes result in explosive discharge of energy released as a result of the fault occurring inside the transformer, resulting in structural damage to surrounding equipment within the substation. Although rare, their impact is always high. Operational efficiency is achieved when knowledge of transformer failure modes and their related alarm and fault conditions are known, especially where some alarms or conditions can occur for some time before a major failure takes place. Transformer energization and de-energization is also a major R reliability factor. Inrush current can cause unwanted relay operations if the protection setting is not correct for that particular condition or if the system condition is not normal. Several near miss cases have been reported, and power system instability has been observed when a transformer is switched on under weak system conditions. It is thus important to know the system strength while switching transformers. Large transformers are very important transfer paths between different voltage levels in a power system. Disconnection of a large transformer can alter system load flow paths and cause overloads on other transmission lines. These effects are reflected in contingency analysis results which are used to assist in deciding the most appropriate action. Some knowledge of transformer behavior is therefore useful. Restoration of complex devices such as large transformers is a major contribution to the complexity of power restoration. Bringing a large transformer in after an outage may require considerable effort in supporting voltages, reactive control and load management to avoid secondary problems with over voltages and inrush current maloperations. These errors can make a bad situation created by the initial fault much worse. Power transformers are much more than just static equipment. They represent a
class of dynamic reliability components whose performance can directly affect loads, voltage configuration and also contingency analysis. Their awareness to the operator about the operating conditions, protection operating conditions and potential impact in case of a fault enhances the operator ability to understand the impact of alarms in the system, anticipate potential system behavior during unexpected situations and prevent system instability.
End-of-Chapter Summary
Power transformers are always the high-impact reliability components in the power system, affecting system stability by their loading capacity, cooling capacity, protection action and voltage regulation performance. Knowing their operating condition and the impact of potential failures on power system
operation will clearly improve the operational staff’s situational judgment in dealing with overloaded transformers, protection tripping and during removal of faults.
FROM THE FIELD
A power transformer is one of the most consequential pieces of equipment in the substation. Its failure removes a transmission path; its loading shapes the system's operating envelope.
Transformers age slowly and fail suddenly. The asset management discipline that catches the slow degradation is what prevents the sudden failure.
Transformer ratings drive operating limits. A transformer rated conservatively in 1995 may have margin today; one rated aggressively then may not. Ratings have to keep current.
Chapter 3
Circuit Breakers: Fault Interruption and Operational Exposure
Circuit breakers are the mechanical and electrical isolation devices that define the boundaries of the transmission system in a controllable way. Essentially, every switching activity in a substation is a breaker operation. Breakers are not the common, everyday type of component and, from an operating point of view, are the means of performing fault clearance, isolation of faults, changes in operating configuration under normal and emergency conditions. Transmission Class Circuit Breaker A transmission class circuit breaker is a device used primarily for fault current interruption. When a fault is detected by the protection system, a trip command is sent to one or more breakers in an attempt to interrupt the fault and isolate the faulty section of the power system. If the fault can be successfully interrupted, the rest of the system will remain operational. However, if the fault cannot be interrupted, the effects of the fault will be transmitted further away from their point of origin. In today’s systems of power transmission, modern circuit breakers can utilise any of a number of different systems to discharge currents. In the case of SF6 (sulfur hexafluoride) and vacuum switch breakers, SF6 gas and the vacuum itself serve as the interruption media. For other breakers using alternative interruption media, the rules do not change at all. The rule is: a breaker should open when commanded to open and remain closed when commanded to remain closed. Exposure to Reliability Risk is only present when the breaker fails to obey the rules in one direction or the other. Breaker failure protection schemes are intended to recognize a breaker failure and allow the system to clear the fault by tripping out adjacent breakers. A number of disturbance studies have verified that breaker failure protection schemes have extended the duration of power outages to other lines or busses, by isolating the power flow to the affected line or bus. What the operator is actually seeing is that the initial fault was contained, but that the breaker failure protection isolation of the other facilities, although effective in isolating the fault, was unnecessarily extending the duration of the outage to the affected lines and buses. Breaker misoperations can also introduce operational risk, e.g. when a
breaker is tripped without a valid fault being reported, and important transmission lines are suddenly and unnecessarily lost. Several reports have been made public, detailing issues caused by incorrect relay settings, incorrect wiring and relay failures that caused an inappropriately tripped circuit breaker. Another aspect to the breaker operation is recognizing when a circuit breaker is tripped without evidence of a persistent fault, thereby reinforcing the operating team’s diligence in assessing the nature
of each disturbance. Reclosing schemes are a bit more complicated than the rest. The purpose of an automatic reclosing circuit is to restore power as quickly as possible to a location after a transient fault such as a lightning strike has tripped the line. While reclosing is generally very effective, there are instances where trying to reclose into a fault can actually make an existing system disturbance worse. It is therefore very important for wiser utility operators to take into account whether or not an attempt to reclose would be sensible at a given time. Such times might include bad weather or a system that is otherwise on the weak side. The status and condition of Breakers that are under maintenance and therefore not available for operation will also impact flexibility. A breaker that is out of service for maintenance may affect the robustness of the bus configuration. This will be particularly relevant in ring bus and breaker-and-a-half configurations where the loss of one breaker will affect the level of redundancy in the configuration and therefore the system’s sensitivity to subsequent faults. Improved understanding of configuration impact will improve contingency awareness in the process of outage coordination. It is important to note the auxiliary systems related to breakers. Loss of control power, malfunction of SF6 pressure alarms, warning lights for hydraulic system etc may indicate a decrease in the reliability of switching off. It is also advised to monitor health indicators of the breakers so as to know the risk of failure. Though there is no maintenance done by the operations team, degraded condition of the breakers is considered while carrying out the operational risk assessment. Switching operations are based on breaker switching sequence and breaker status confirmation. Switching procedure is not discussed in this document. However, the importance of breaker status accuracy for SCADA systems has to be acknowledged. Inaccurate breaker status could mislead operations personnel about the actual status of the system which may lead to erroneous switching decisions. This has been observed in several events where the incorrect breaker status provided to operations personnel by the SCADA system was identified as a contributing factor to the abnormal system response. Reliability-wise, the breakers are the execution points for the protection decision made. Breaker performance
has a direct impact on whether the fault remains localized or not. Breaker availability has a direct relation to the grid operational reliability. Breaker failure modes have a direct relation to the outage extent and to the complexity of the fault restoration. For operators the functional understanding of the breaker behavior is important for fault diagnosis of simultaneous element loss of control, protection relays operation and abnormal switch operation. The circuit breaker represents the mechanical boundary between normal system continuity and the fault isolated by protection relays. The performance of the circuit breaker under fault conditions is a critical aspect for reliability.
End-of-Chapter Summary
Circuit breakers are used for fault isolation, switching operation and setting limits in substations. Breaker failures, misoperations or degraded states can affect extent and behavior of outages. Understanding
breaker operations and protection interactions enhances operator situational awareness in fault situations as well as during switch changes.
FROM THE FIELD
Circuit breakers are how the system isolates faults. A breaker that doesn't operate correctly during a fault is the difference between a contained event and a propagating one.
Breaker maintenance and testing aren't routine; they're reliability work. The standards expect both, on cadence.
Most breaker findings come from missed maintenance intervals or untested operations. The pattern is reproducible, and the audits know it.
Chapter 4
Bus Configurations and Operational Flexibility
The design of substation buswork and associated switches influences the configurations of power flow, the method of fault isolation, and the resulting impact of maintenance outages on power system reliability. Bus design is a significant operational factor not necessarily a drafting design choice. The design of buswork and switches greatly affects the exposure to contingency and the degree of flexibility available with respect to power system switching operations. The most common transmission-level bus configurations are: Single bus Main and transfer bus Ring bus Breaker and a half Bus configuration is a reflection of cost vs redundancy vs operation flexibility factors, none of which are decided by the operator. A single bus layout has a high concentration of risk. All components are interconnected through a common electrical node. A bus fault or breaker failure can potentially lead to an entire station being de-energized. Maintenance on one breaker may require the removal of all associated lines and/or transformers. Operation in a single bus layout can result in low flexibility and therefore high contingency sensitivity. Main-and-transfer arrangements can provide a little more flexibility with a transfer bus and switching capability. The breaker in the maintenance station could be removed and still provide continuous service. However, configuration errors, or unintended transfers can reduce redundancy until they are corrected or the transfer is reversed. When considering contingency exposure, it is important to consider the current state of the buses. Ring bus topology has added redundancy in the system. Each element is connected between two breakers to form a closed loop. There is not a single point failure, in the event of a breaker or line failure, the element to the other side of the failure is not lost. There are several things to keep in mind when working with a ring bus topology. When multiple breakers need to be opened in a small area of the system they can inadvertently create radial exposure to areas they may not be prepared to supply or conversely limit current below safe levels in a single path. Breaker-and-a half arrangements provide a high degree of operational flexibility. Each phase in a circuit breaker-and-a half arrangement is protected by two breakers, with each breaker being shared between two phases. This arrangement permits any single phase to be taken off line for maintenance or repairs
without interrupting the other phases. Breaker status and protection coordination must be understood to accurately interpret the impact of faults on the system and the isolation boundaries that apply. An operational awareness of the current configuration and its impact on the overall system reliability is important. During maintenance outages, the effective bus arrangement in the system will likely be
different from its normal configuration. A breaker-and-a-half station with one breaker taken out of service can act as less redundant than normal. This results in a potential reduction in system reliability to double contingency events. Because of the high degree of connectivity, bus faults are high impact events. Clearing the bus faults with a reliable protection scheme, which trips all breakers in a zone, results in a number of breakers tripping in synchronism. Public documents have bus differential misoperations leading to unwanted tripping of a number of transmission lines. In such scenarios, the impact of multiple transmission lines tripping is often due to a bus protection operation. It becomes very important for the operators to exercise some discretion, before jumping to conclusions, upon experiencing multiple outages in a short span of time. These switchings change the bus alignment or the way buses are defined, thereby affecting power flow in unexpected ways. A line transfer can change impedance paths and increase loading on other system facilities. The Contingency analysis tools reflect these topological changes, but provide more effective information with an understanding of Bus topology. Voltage stability is also affected by bus configuration. Placement of too many shunt reactor or capacitor banks on a particular bus section, in conjunction with a bus configuration switch, can have an adverse effect on local voltage support. Voltage increases following a switch can give a guide to possible adverse bus configuration effects on reactive flow. Best practices in the industry are to always be aware of reduced contingency conditions during planned outages. Outage coordination formal processes handle approval, but it is very beneficial to be aware of when a bus is temporarily constrained and therefore not in a full contingency condition so that the operator can adjust their level of monitoring and readiness to respond to possible additional contingency events. Bus configuration is a structural reliability feature that plays an important role in how faults are isolated and how maintenance and substations reliability is restored after a contingency. It is therefore very important for control room operators to understand bus configurations to better able to understand the symptoms of alarms, the contingency analysis results, and the single line animation following any T/L operations.
End-of-Chapter Summary
The configuration of the substation bus affects power delivery system voltage and current stability, fault isolation, and contingency capacity. Information on bus alignment, on-going maintenance, protection operation, etc. is essential for improving operational knowledge relative to the bus topology for the effective control of reliability.
FROM THE FIELD
Bus configuration determines how flexible the substation is. Single-bus configurations are simple and brittle. Multi-bus configurations are resilient and complex.
The configuration that worked in 1985 may not match today's loading and contingency profile. Configuration reviews are part of operating discipline.
Chapter 5
Instrument Transformers: Measurement Integrity and Protection Dependence
Instrument transformers (Current Transformers (CTs), Potential Transformers (PTs)) are often thought of as the measurement point between the high voltage apparatus on one side and the protection, metering and control systems on the other. From an operational point of view they often work in the background, as their primary function is often taken for granted, and consequently their reliability to provide the measurement required is often not realised. However accurate measurement is fundamental to reliable system control. The primary function of current transformers (CTs) and potential transformers (PTs) is to reduce the magnitude of the primary current and voltage to a secondary value that is proportionally representative of the primary quantity, and that is suitable for relay and metering applications. The reduced value is often used to determine if faults have occurred, to measure various quantities of impedance, and to determine if other trip conditions have been met. Inaccurate or suspect instrument transformer performance or application may impact the reliability of protection. CT saturation under high fault current occurs occasionally and can affect many measurement circuits. Under these conditions, the measured signals can be heavily distorted, and in some extreme cases the relay may not receive the correct current values and may mis-time or lose selectivity. Studies confirm several occurrences where relay mis-operation was caused by problems with CT performance under severe fault conditions. Relays can mis-operate occasionally under severe fault conditions due to device performance under normal design parameters. These incidents can rarely be expected to occur, but understanding device performance limits helps to better understand relay behaviour. Incorrect Polarity and CT/VT Wiring will lead to incorrect differential current calculation which is not reliable and can cause many errors. This has been observed in many public misoperation reports, the most common are CT wiring issues for transformer and bus protection. Differential protection cannot operate reliably if operator has to consider whether the cause of protection alarm is
due to measured value anomaly or else an equipment failure which should be resolved by a measured response. Loss of PT signals can affect both protection and situational awareness. The operation of voltage-dependent relays, synchronizing checks and automatic control schemes all depend on the integrity of the voltage input. The SCADA telemetry system also uses the PT signals to display the voltage
at a particular location. If a PT fails or its fuse operates, the operator may notice that the voltage does not appear on the display panel, or that they receive unusual alarm messages. It is important to the overall system management to be able to determine whether a voltage collapse has occurred, or if the measurements are not being received. The accuracy of metering information can have an impact on operational awareness. Real time load flow, interface monitoring and contingency analysis require accurate input. Erroneous measurement can obscure developing overloads, or exaggerate apparent system stress. It is important to validate the quality of telemetry and to quickly clear errors to maintain an accurate operational picture. These types of faults can be classified into three major categories: tripping out (due to protection); unusual alarms; and unusual display readings. CT faults can cause incorrect tripping out of healthy sections of the line; PT faults can interfere with voltage regulation schemes. Unusual relay settings or display readings on the telemeter may indicate an instrument fault that the operator must be aware of. Protection Relays dependency on instrument transformers is a very common phenomenon. This dependency implies multiple layer of reliability in a system. Although primary relays are operating correctly, faulty input from instrument transformers may cause unwanted circuit separation. On the other hand, correct input from instrument transformers can lead to instant discrimination and selective tripping of circuit breakers which helps in maintaining stability of the system. Restore operations to be performed after a fault occurs in an instrument transformer element must take into account the possibility of coordination with protection personnel to check the signal integrity before bringing back to service the affected element. Even though the operator does not perform any testing, it is important to have knowledge of the measurement chain in order to guide the actions during the restoration process. Instrument transformers are some of the most mundane yet critical components of any substation. They take the large voltages and currents of the high voltage system and change them to voltages and currents that can be used by relays and monitoring devices. Proper operation of instrument transformers results in proper protection and situational awareness. Abuse of instrument transformers results in improper protection and improper situational awareness. It is important for control room personnel to recognize how measurements are utilised in protection and telemetry systems in order to enhance their ability to understand alarm groups during transient conditions and data inconsistencies during abnormal operating modes of relays.
End-of-Chapter Summary
Instrument transformers provide the primary measurement sources for protection, control and monitoring functions in the Substation. The accuracy and reliability of Current Transformers (CTs) and Potential Transformers (PTs) directly affects relay operation and telemetry accuracy. Knowledge of the measurement source integrity and failure modes helps in discrimination between normal and abnormal system operation and ensures adherence to operations procedures in the face of unexpected events.
Chapter 6
Protective Relays: Fault Detection, Selectivity, and Misoperation Risk
The Protective Relays are the brains of the protection system. They receive input signals from instrument transformers, apply rules and logic to the signals and send trip signals to the circuit breakers to neutralize the fault current. From the control room perspective, the point at which the relays operate is the dividing line between keeping the disturbance contained and allowing the power failure to spread. Everything about transmission protection revolves around three main factors namely speed, selectivity and coordination. Speed helps in quick discrimination of faults and prevents damage to large number of costly circuit components and enhances the stability of the system, selectivity ensures that only the faulty section of the line is switched off, and coordination is provided between the protection relays in case the primary protection does not operate. The mentioned factors provide the basic building blocks for any relay system. Common transmission protection functions are: Distance protection: Measures the impedance to determine the location of faults on a transmission line. Differential protection: Compares currents entering and leaving a protected zone such as a transformer or a bus. Overcurrent relays: Responds to the magnitude of current above predetermined levels. All protection functions have specific operating characteristics and defined scope or zone of protection and control. Relay operation is usually the first indication of a fault at the control room. The understanding of breaker trip indications along with relay target information and SCADA alarms provides a means of identifying which relay operated and thus helps the operator to deduce if the fault is internally in the affected piece of apparatus, externally but still within the protection zone or even the consequence of some misoperation. Misoperations are a considerable source of reliability problems. Numerous misoperations have been recorded in NERC documents that were made public due to relay premature operation or failure to operate when expected because of incorrect relay wiring, settings, communications between protection systems, or unexpected system conditions. The cause being Relay misoperations are not the fault of operators since they do not have anything to
do with the settings and understanding that Relays are not infallible is important for measured event assessment. Zone protection overlap and backup schemes can increase the impact of an outage during complex faults. An example of this is when a failure to clear a fault is detected in the primary line
protection relays and the backup protection then subsequently removes power from a larger area of the system. Loss of multiple facilities should raise suspicion that the additional circuit may have been tripped by backup protection relays. Coordination of this type is normal in protected transmission systems and the high voltage impact on the power system is a normal consequence of the design rather than a fault in itself. Communication assisted protection schemes add an extra layer of complexity to conventional protection relays. Operation of these relays can be controlled by permissive or blocking signals exchanged between line terminals. Loss of communication can also change the sensitivity of the protection relays or can cause a switch over to backup relays. Importance of monitoring communication channels has been emphasized in many literature by promoting protection awareness. The relay settings are derived from studies such as coordination studies based on the impedance, fault levels and contingency conditions of the system. Unless changes in the system configuration, changes in generation pattern or capacity augmentation is considered in the protection settings; adverse effects have been observed due to outdated protection setting while the system was experiencing dynamic changes. Protection systems are designed to be reliable rather than to provide a continuous source of power. The fast clearing of a fault can prevent cascading effects by removing more than just the faulted element. The effect of this design philosophy is that unexpected trips may occur in the control room. Knowing the design philosophy can aid in understanding the reasons for a large system trip. For the operator relay operation is a signal which has to be treated in a specific way. All relevant information for a rough assessment of the origin of the fault can be derived from the relationship between the relays involved, the state of the circuit breakers, the faulty circuits indication and system response features. To make a correct assessment of the situation, knowledge of protection zone characteristics and coordination principles is needed. Protective relays are not abstract electronic devices. They are the tangible gatekeepers of protection and thereby serve to preserve the integrity of the protected equipment and to secure stability of the power system. They have a direct impact on the extent of the area affected by faults and on the sequence of switching actions.
End-of-Chapter Summary
The protective relays sense the abnormal conditions of the circuit and operate the breakers to isolate the faults. The concepts of speed, selectivity and coordination are associated with the disturbance containment limits. Understanding the protection logic and misoperation potential helps in better understanding of fault occurrence and leads to a more disciplined approach towards reliability responses.
FROM THE FIELD
Switching is one of the most common operations in a substation. It's also one of the most consequential. A switching error can de-energize loads, ground equipment, or initiate cascading events.
Chapter 7
Capacitor Banks, Reactors, and Voltage Control Dynamics
Substation Reactive Power Equipment The purpose of reactive power devices in a substation is for voltage control and stability purposes. Shunt capacitor banks, shunt reactors and series compensation equipment affect the voltage, reactive current, and in some cases real power. The substation control room operators operate these devices as voltage control & stability aids, but often as a reactive tool. The shunt capacitor banks provide reactive power by injecting vars. By injecting vars, the voltage is increased at the point of injection and reduced on the transmission lines between sources. This results in improved voltage profiles during high load conditions and increased transmission capacity. However, the effect is highly location dependent. Although energating a capacitor bank in one substation increases the voltage in that substation, it can reduce the voltage in other substations and cause a ripple effect on reactive power flows in unpredictable ways. Shunt reactors are used to absorb reactive power. These are used under light load conditions to prevent over voltage. Excessive reactive power is generated by long transmission lines during low load conditions due to line charging. This charging reactive power is absorbed by shunt reactors so that the voltage is maintained. The cause of high voltage during light load or post contingency conditions is sometimes misunderstood by the operators. The switching of reactive devices can cause fluctuations in voltage. The switching of capacitors can cause abrupt increases or decreases in voltage with a small number of oscillations. In some instances, back-to-back capacitor switching has caused stress to relay contacts and tripped protection when inadequate coordination was provided. Misoperations have been noted in the industry in relation to reactive switching under certain system conditions. The relationship between controlling the voltage, transformer tap change and generator reactive capability are closely interwoven. With the involvement of shunt capacitor banks and reactors, the effects of AVR and load tap changer may yield dynamic performances, so when voltages shift the effects of various regulating devices and systems should not be regarded in isolation. Reactive power deficit is associated
with the risk of voltage instability. In stressed conditions, the removal of a major capacitor bank or generator reactive source can be detrimental due to reduced voltage margin. High reactive injection under light loads can also cause overvoltages and exacerbate insulation stresses. An understanding of when reactive resources are limited is important for situational awareness. Capacitor/reactive compensation protection issues The operation of protection relays connected with reactive
compensation equipment represents one of the newly introduced operational issues. Capacitor banks are protected by unbalance relays, over current relays and over voltage relays. Similarly reactor protection also detects unusual current conditions. In addition unexpected tripping off the reactive compensation circuits can lead to changes in voltage magnitudes and load flow patterns. Series compensation is less frequently used but again alters effective line impedance and can increase transfer capacity. Again, power flow changes and stability margin can also be altered. Protection is fast to prevent damage to the equipment. Series compensation effects on line dynamic response to changes during faults are important for operational understanding. Most industry guidance relates to coordinated voltage control within an interconnection. However, the RTO/ISOs have made it clear that voltage control does not occur within the confines of a single substation. Actions at one point in the grid can cause voltage changes elsewhere in the system. Thus, Reliability Coordinator and Transmission Operators spend a considerable amount of time looking at voltage conditions throughout the entire grid in order to ensure grid stability. Reactive devices are often switched to improve system operation at the time of switching. Again, the switching action is not discussed in this book. However, a little thought shows that decision to switch reactive devices can affect the contingency analysis. Say for example, capacitors are switched on or off. This may cause a change in load flow situation which in turn can affect the stability margins in the event of certain contingencies. In our opinion, capacitor banks and reactors are much more than auxiliary equipment. They are the real actors in voltage regulation and system stability. Their operation and protection mechanisms, as well as their influence on other voltage control devices define the electrical state of the grid. Control room personnel who have an understanding of the operation of reactive devices will be better able to analyze and respond to potential issues such as excessive voltage alarm conditions, post-contingency voltage instability alarms and stability warning messages. Voltage behavior is one of the key parameters to determine the status of a power system and reactive devices are the main resource to manage and regulate voltage behavior.
End-of-Chapter Summary
Treats the impact of capacitor banks, reactors and other reactive devices on voltage control and stability. It focuses on the impact of these devices on reactive power flow, voltage levels and contingency analysis sensitivity. It emphasizes the need for an understanding of how these devices operate in order to effectively monitor the system voltage conditions and to exercise reliability oriented situational judgment.
FROM THE FIELD
Protection at the substation level implements the system-level protection scheme. The two have to align, and the alignment is the design responsibility.
Substation-level protection settings are reviewed against system-level requirements. The review is auditable. Programs that don't have current review records fail audit.
Chapter 8
Station DC Systems and Control Power Integrity
Station operation encompasses not only high voltage apparatus but also low voltage control power for protection, breaker operation and display functions in the substation. These are generally provided by the station batteries and associated DC distribution. Degradation of DC system can impact operation functions such as fault isolation, breaker operation and display functions. Power provided by a station DC system is required for trip and close circuit breaking, protection relay excitation, communication, and control. It is common for many substation DC systems to be isolated from the primary AC sources to provide continuing supplies in the event of any AC fault. Thus loss of DC power can have an immediate and adverse impact on reliability. This guideline discusses procedures and criteria to determine the suitability of the battery banks installed on ships to supply adequate voltage and capacity for defined periods in the event of an AC power loss. Battery testing and maintenance criteria can vary between shipyards and authorities but generally concentrate on the capacity of the batteries and the condition of the cells. Since operator testing of the batteries has not been implemented, awareness of the DC system alarms including low voltage, charger fault and ground faults may alert personnel to potential conditions in the DC system which require extra vigilance. - A DC ground is a special operating condition. When a ground fault occurs on a DC system, it provides additional current paths and can interfere with the trip function of a breaker. Numerous industry documents and fault reports show instances where a DC ground that is not cleared can prevent a trippable fault from being successfully tripped or can cause improper breaker operation. If DC grounds are displayed by alarms, it is an operational condition where protection reliability may be compromised. If battery charger failure is not critical to current operating conditions (i.e., batteries are fully charged), it will not be considered an immediate problem. However, the loss of a battery charger for an extended period of time will eventually drain the battery reserves and could leave a system more vulnerable to subsequent events. The ability to use alarm information from the battery charger to influence operational risk assessments during extreme weather or high contingency conditions is also lost. DC sources are required for many functions in protection and control panels. Transient voltage changes and stable DC level changes in batteries can impact relay operation, alarm functionality and communication interfaces. In some cases the breaker will not trip when the DC source voltage levels are below design values and the backup protection must be activated, thereby potentially increasing the scope of the resulting power outage. A great number of restoration problems that arise after a disturbance are associated with availability of control power. Without DC in a
substation it is frequently impossible to carry out switchings and re-energizations required during restoration until normal control power can be brought in. Such problems are verified by review of the industry’s disturbance reports. Many station DC systems include monitoring and SCADA interfaces. Loss of DC power can affect Telemetry, Station status indication and remote control capability. It is important to note that an operator must be able to determine whether loss of communication is due to a control power problem or that the associated device has actually lost main power. It is considered good practice in the industry to design, operate and maintain DC supplies so that there is adequate redundancy and also some means of monitoring the integrity of the system to enhance reliability. Battery banks may be duplicated, multiple chargers used and ground fault protection included in the detection systems. Understanding the operation of the DC supply can also assist in assessing system performance when it is subject to abnormally charged or unusual conditions. It is common that not a great deal of information is displayed on the DC circuits in the control room other than alarm indicators. However, these circuits provide control signals to breakers, relays and communication apparatuses. And are essential to achieving fault isolation and subsequent restoration. For control room operators, knowledge of the role and consequences of DC system degradation will enhance their situational awareness during alarm conditions and aid in the assessment of protection reliability during stressed system conditions.
End-of-Chapter Summary
Station DC supplies protection relay control, breaker control, alarm panels and other monitoring functions. Any decay of battery banks, chargers or DC system integrity can hinder the correct operation of fault clearance and prevent an accurate assessment of the condition of the system. An awareness of station DC system condition enables a value judgment of risk to be made and reinforces the reliability of all systems in faulted states.
FROM THE FIELD
SCADA integration is what makes the substation visible to the control center. Without it, the substation is operating blind to the larger system.
Automation handles routine operations. The standards expect manual override capability, tested, and documented.
Cybersecurity overlays substation automation. The OT/IT convergence is real, and CIP applies wherever the convergence creates BES-relevant cyber exposure.
Chapter 9
SCADA, RTUs, and Telemetry Integrity
SCADA systems, as well as RTUs, IEDs and communication links, Energy Management Systems, are all systems that are used in the control room to interface with substation equipment, and convert physical status of substation equipment into data that can be viewed. From an operational perspective the reliability of telemetry is inextricably linked to the reliability of situational awareness. Operators do not see the substation. They see its image, formed by status points, analog values, alarms, and event indications. Breaker positions, line loads, transformer temperatures, voltage levels, and reactive powers are all elements that are measured and transmitted via various communication and measurement systems. Wrong or missing telemetered values can cause incorrect or even unreliable decision-making. RTUs and IEDs are used to collect signal from instrument transformers, protection relays and control circuits. This information is then sent to the control centre via communication channels. Delays in receiving real time information, communication breakdown, settings errors can mislead the operator about the real time state of the system. Analysis of industry wide power system disturbances has identified several instances where incorrect transmission of real time information has resulted in prolonged time to discover the cause of overloads and incorrect breaker status. A communication loss to a substation does not necessarily indicate a fault on the station equipment. It can be due to communication channel out, an RTU fault, a control circuit power loss or a combination of the above. It is very important to understand the difference between a telemetry loss and a de-energization. To confirm the substation de-energization, it is recommended to cross check different data points such as analog signal losses, breaker positions and alarms. Analog telemetry (e.g. line loading or transformer temperature) may require scaling and/ or calibration. Incorrect scaling factors may produce incorrect readings. There have been instances where an incorrect calibration of telemetry has masked an increasing overload condition. Understanding that data integrity is heavily dependent upon correct configuration should prompt extreme caution when dealing with out of expected values. Control capability through the use of SCADA brings a different perspective to the issue of substation automation. Operation of breakers and
reactive devices from a remote location requires reliable communication, and command verification to ensure that the desired changes are made to the circuit. Substation switching procedures are not discussed in this book, but it is important to note that reliable status indication after a remote control
command is required to prevent errors due to incorrect circuit configuration. If issues arise with input data used for Contingency analysis, the reliability of the resulting contingency information will be compromised because this analysis is based on real-time or near realtime SCADA telemetry. Operator awareness is recommended if large amounts of stale input data are encountered, if there are problems with the estimator (used to interpolate values between reported measurements) converging or if there are repeated communication errors with certain substations. Authentication, network segregation and monitoring are types of SCADA cybersecurity controls implemented to prevent unauthorized access. These controls can present operational challenges, and it is important to understand how they impact operations and the reasoning behind the messages they generate to be able to treat alarm messages appropriately. One of the design principles of today’s SCADA systems is redundancy. Systems are designed to allow continued situational awareness during any failures of individual components. This includes multiple communication paths, redundant master control centers and servers. However, redundant components can still cause failures which can impact the reliability of the overall system. Industry wide experiences have shown that simultaneous failures of primary and redundant paths can occur. Problemtelemetries are related to operational integrity of real time telemetries and post event analysis telemetries. Sequence of the events and the status in the disturbance logs can be used to gain insight into the nature of disturbances in the power system. Unreliable or bad quality data could impede the process of investigation to understand the cause of the fault and to prepare recommendations for preventive maintenance. For control room operators, SCADA and telemetry systems are their window to the substation, providing a real-time view of what is happening. Having a basic understanding of how the systems collect, transmit and display information can be invaluable to the operator, aiding in the management of alarms, recognition of trends and unusual conditions and generally aiding in the maintenance of a focused state of awareness, especially during fault or abnormal conditions.
End-of-Chapter Summary
SCADA systems, RTUs, and telemetry networks provide control room operational visibility of substation equipment. Maintaining data integrity, reliable communications, and accurate configuration settings is critical to ensuring quality operational awareness. Understanding the limitations and failure modes of telemetry helps operational personnel better analyze alarm messages and make more reliable reliability centered decisions.
FROM THE FIELD
Maintenance is reliability work. Programs that defer maintenance to control budget produce findings and accelerate equipment failure.
Asset management spans the equipment lifecycle. Programs that focus on individual asset failures miss the lifecycle pattern.
Chapter 10
Switching Exposure and Configuration Risk
Switching changes the electrical configuration of the system. The act itself actually takes place in the field, or in the substation, under local control, but the command originates in the control center. Every switch has the potential to change interconnections, change power flow paths, change protection protection relays settings and thereby present a high exposure event from a reliability standpoint. Substation configuration controls the way faults are isolated and the manner in which contingencies propagate. When breakers or disconnectors change state the effective bus configuration may momentarily revert to a less redundant condition; e.g., a breaker-and-a-half station under maintenance can function for a short time with a reduced fault tolerance, and a ring bus broken open at two or more points can revert to a radial configuration. The operator must recognize the impact that configuration changes may have on the contingency RVT. Industry disturbance investigations have found that configuration errors or other issues with SCADA/switchgear alignment have contributed to extended outages. In some instances, relay operations functioned as intended; however, the resulting system conditions exacerbated the effect of the switch operation. The impact of the switch operation was not the sole reliability consequence – it was the system conditions into which the switch operated. Verify breaker status. There are several factors that affect configuration awareness. Some include discrepancies in the Telemetry, outdated data, or incorrect equipment position identification. If configuration does not match assumed state contingency sensitivity may be greater but this may not be indicated. Vigilance in operations involves cross correlating the data from all the sources to ensure the integrity of the system topology. Protection zones are also affected by switching. A protection zone boundary can change when an associated bus tie or sectionalizing breaker is opened. A transfer bus may also be energized which brings a new set of protection interactions. A few publicly available misoperation analysis reports indicate that in a number of instances, differential protection has not operated as expected during abnormal switching states following topology changes caused by such switchings. Switching during stressed system conditions adds more complexity. High load, voltage instability and low reactive power margin
can make topology switching more impactful. Normal maintenance activities such as switching configuration can also result in measurable impact to power flow transfer. Understanding system conditions that affect the risk of switching configuration changes. After a disturbance, restoration
generally involves a series of offon toggles to regain power delivery and normal grid configuration. It is a practice in power systems that the restoration should be done in a planned manner to avoid overloading and voltages deviation. The details of the restoration procedures are not discussed in this book. The switching actions that form the recovery path of the power system are of great importance. Switching exposure and human performance This section contains excerpts from public event reports (PERs) where human performance was reportedly a factor due in part to Switching Exposure. The first excerpt lists some of the factors reportedly identified as contributing to error in several publicly available PERs for analyses of major public events involving aviation, as provided by the investigation authority. Formal procedures are one of the industry’s preventive measures following such findings. From reliability standpoint, switching is not an innocuous operation. It changes the configuration of the components of the power system upon which all contingency analyses are based. Contingency analysis tools model the system according to its actual configuration at the time of the analysis, and the accuracy of the analysis is dependent on a timely and accurate representation of the system topology. It is useful to know how different configurations will affect high availability. Knowing which alignment is less redundant and causes higher concentration of switched currents may also be an occasion to increase the monitoring density prior to and during switchings. Switching exposure does not necessarily imply avoidance of configuration changes. Switching activities, such as maintenance, reliability improvement and restoration, are often carried out while a system is in the switched exposure condition. Understanding the risk envelope of the system’s different configuration states is key to defining an effective operational objective. The configuration awareness that a control room operator has for their assets is the bridge between their knowledge of the equipment and their ability to make correct reliability judgments at the system level. A control room operator has this knowledge based on the components that make up the substation and how switching arrangements determine which configuration of components is in service.
End-of-Chapter Summary
Switching activities can impact the topology, protection relay boundaries and contingency restore points of the power system. Configuration changes may increase or decrease the exposure of reliability to potential fault states of the system depending on current system conditions and levels of redundancy. A high level of awareness of system topology, accuracy of measurements, and current system loading is essential to manage the risk associated with switching activities.
FROM THE FIELD
"It's just equipment" — equipment that determines operating envelope, fault clearing, and system flexibility.
"Maintenance can be deferred" — sometimes. Often, the deferral compounds into failure.
"The protection scheme is the engineer's problem" — the scheme is enforced. Misoperations have audit consequences. Engineering and compliance can't be separate.
Chapter 11
Misoperations, Cascading Pathways, and Situational Awareness
The failure of substation equipment is not necessarily catastrophic. Protection, breaker schemes and redundancy are built in to allow faulty equipment to be isolated and the rest of the system to continue to operate. Cascading occurs because of the relationship between the behavior of the failed equipment, the configuration of the system at the time of the failure, the loading on the system and the performance of the protection. Understand how cascade blackouts begin Researchers using the NERC VEAT and CEAT disturbance reports have consistently identified that Public Disturbance reports related to cascading blackout events typically begin at the point where a small disturbance (such as a line fault, breaker failure, transformer trip-out or a false protection relay operation) occurs. The magnitude of the final blackout is heavily dependent on the ensuing response of the power system over seconds and minutes. Misoperations are a common thread running through many of these scenarios. A relay incorrectly tripping, a breaker not successfully opening, or a protection zone being inappropriately set can cause more items to be removed from service. While such an event may not cause a problem in a lightly loaded system, the same misoperation in a highly stressed system can result in power flows moving outside of stable bounds. Situational awareness is the operator’s primary defense against escalation. Identifying patterns of abnormal events (for example, simultaneous loss of all circuits on a bus or a bus voltage decline following loss of reactive) is key to quickly understanding the extent of a disturbance. Understanding the design of the system and knowing protection boundaries helps the operator to quickly determine whether a disturbance is due to an individual piece of equipment failing, or to a system-wide distress condition. Cascading circuits often experience a series of overloads. Upon the failure of one heavily loaded line, the resulting strain on the parallel transmission paths can cause subsequent Line Failures. While a contingency analysis tool can provide guidance regarding the likelihood of such an event, practical knowledge of the individual components can significantly aid in the interpretation of the results. An understanding of the
specific impact of a transformer outage, (i.e. voltage compensation, etc.), as well as the possibility of a breaker failure scheme, expanding the scope of an initial line failure, will all aid in reaching a more accurate assessment of an unusual transmission line event. High Voltage Voltage instability following loss of reactive reserves or heavy power transfers has also been a problem. Several disturbances in the past, where the initial cause did not seem significant, have been found to be made worse by a secondary
voltage collapse. Operators should be aware of increasing voltage decline and consider the residual margins of other sources and their approaching stress limits. Protection coordination is a means of limiting faults to particular sections of the system. The backup protection is also biased in a conservative direction. In the event of failure of the primary protection or in the event of sluggish fault clearance by the primary protection, the backup protection may have to take in larger sections of the system. This phenomenon can be observed on line by noting that subsequent power shut downs may be caused more due to coordination than due to independent faults. If some changes in operation are not recorded in real time via telemetry systems, events that were precipitated by the problem being measured may not be recorded, thereby masking cascading effects and obscuring cause and effect links between the incident and other events. For brief periods following the onset of a problem while system messages are being reestablished, operators may not have full information and have to proceed with other known information pending resumption of system messages. Lessons have been learned in respect to particular communication practices such as continuity of formal communication with field personnel and adjacent stations to prevent breakdowns in emergency response planning at times when field instrumentation is without power and no data are being transmitted. System queries and plant interactions are typically part of an NDE. Lessons learned from the Station Blackout and turbine generator relay relay malfunctions, and SEP transformer burnouts at Davis Besse consistently point out the need to identify visible signs of degradation. Sometimes even an operational parameter is a sign that the plant is no longer in normal conditions, and the results of insufficient repairs, high power margins and reduced reactor or turb generator reactive backup capability can all contribute to the potential for cascade trips. Knowing system interactions helps the operations personnel to more readily recognize when the power system is approaching instability. Cascading is rarely almost instantaneous over the transmission interconnection. Identifying the individual steps or events that occur can be important in making operational choices to mitigate the effects of the initial event and can also
be important in coordinating with the Reliability Coordinator. Understanding the characteristics of individual substation components (e.g., breaker failure logic, bus protection actions, and transformer overload effects) is one way to enhance this ability. Substation components are the physical platform for the cascading effects. Their performance under various fault and stress conditions greatly impacts the disturbances. Operating personnel with knowledge of substation component interactions, along with their system configuration, contribute to a stronger reliability position for their control area.
End-of-Chapter Summary
The cascading conditions are often a result of combination of failure of certain pieces of equipment, activation of certain protections, loading conditions and current state of the configuration of the substation. Situational awareness based on understanding of substation component behaviour enables
better identification of potential cascade development in the early stages of the disturbances and facilitates more structured and reliability centred approach to managing substation abnormal states.
Glossary
Glossary
This section lists terms found in the NERC Glossary of Terms, which were adopted verbatim for use in this volume. Terms included are those specifically referenced in this volume.
Balancing Authority (BA) - The entity that provides scheduling services for generating resources ahead of time and is responsible for maintaining equilibrium of load, interchange and generation within a Balancing Authority Area, and for providing frequency support to the Interconnection in real time.
Bulk Electric System (BES) - As defined by the NERC Reliability Standards.
Cascading - The uncontrolled successive loss of system elements caused by an initial event at some location in the grid. Cascading leads to extended power outages over large areas that cannot be prevented from propagating from one area to another as described by conventional grid reliability studies that define high voltage transmission system areas that can sustain power outages of a specified magnitude for specified times without loss of power to customers in other areas.
Interconnection - A geographic area in which the operations of the individual parts of the Bulk Electric System are synchronized so that the loss of one or more such parts may impact the ability of other system operations personnel to provide reliable service to the systems and equipment under their control.
Interconnection Reliability Operating Limit (IROL) - A System Operating Limit that, if violated, could lead to instability, uncontrolled separation, or Cascading within an Interconnection.
Protection System - Relays, protection communication, voltage & current transformers, batteries and DC circuits.
Reliability Coordinator (RC) - The Entity that is the highest level of authority for reliability of the BES and has a Wide Area view of the BES. The RC has access to Operating Tools and processes and procedures that enable the RC to prevent and mitigate emergency operating conditions on a real-time and next-day basis.
System Operating Limit (SOL) The value (such as MW, MVar, Amperes, Frequency, or Volts) that satisfies the most limiting of the prescribed operating criteria for a specified system configuration to ensure operation within acceptable reliability criteria.
Transmission Operator (TOP) - The entity responsible for the reliability of its local transmission system and that operates or directs the operation of the transmission facilities.
The definitions in this section are reproduced directly from the NERC Glossary of Terms as made public. It is the reader’s responsibility to refer to the current official version of the NERC Glossary for the most current language and definitions.
About the Author
About the Author
Rob Smith is a senior electric industry professional with over thirty years of experience across every major function of the North American Bulk Electric System. His work spans reliability coordination, transmission operations, regulatory compliance, and cybersecurity reliability.
Rob has worked directly in real-time grid operations as a Reliability Coordinator, Transmission Operator, and Power System Operator within RTO/ISO and utility control center environments. He has also held senior regulatory and oversight roles, including senior compliance auditor and subject matter expert for NERC Reliability Standards. In those roles he audited grid facilities for compliance with applicable standards, evaluated the adequacy of mitigation actions, supported the development of violation notifications and settlements as part of FERC-directed enforcement actions, and participated in risk based oversight of utility mitigation activities.
Rob founded Energy Compliance, Inc. to bring senior, regulator-side compliance authority to registered entities directly, without the layered staffing, billable-hour overhead, and generalist advice typical of larger consulting firms. Every Energy Compliance engagement is led by Rob personally.
About Energy Compliance, Inc.
About Energy Compliance, Inc.
Energy Compliance, Inc. is an independent consulting and advisory firm focused exclusively on electric reliability, cybersecurity reliability, and regulatory compliance for organizations connected to the North American Bulk Electric System.
Our work supports registered entities, including Generator Owners and Operators, Transmission Owners and Operators, Reliability Coordinators, Balancing Authorities, and Distribution Providers. We work across NERC Reliability Standards, FERC orders, RTO/ISO market participation rules, Regional Entity oversight, and state regulatory frameworks.
We do this work differently than larger consulting firms. Engagements are led by a single senior practitioner with regulator-side experience. We don’t staff for billable hours. We staff for outcomes. Our deliverables are written to be operationally executable and audit-defensible, not to manufacture activity. Where automation can replace manual work, we build the automation. Where senior judgment is required, the senior is in the room.
Energy Compliance is not affiliated with, sponsored by, or endorsed by the North American Electric Reliability Corporation, the Federal Energy Regulatory Commission, or any Regional Entity.
Services Provided
Our services are written to be clearly defensible. Operationally executable in real time. Audit-defensible at compliance review. Every deliverable is structured for the auditor’s question, not the consultant’s binder.
Energy Compliance services include, but are not limited to:
- NERC reliability and compliance advisory support
- Reliability governance and program assessments
- Registration and applicability analysis
- Operational and engineering reliability alignment
- Compliance program design and improvement
- Audit and enforcement support (non-advocacy)
- Mitigation planning and Self-Report development
- Training and executive briefings on reliability frameworks
- Regulator-perspective program reviews
Each engagement is scoped to the entity’s role, function, and bulk system impact.
ENERGY COMPLIANCE PROFESSIONAL REFERENCE
Rigorous Compliance. Defensible Programs. Energy Compliance, Inc. partners with registered entities on the institutional and technical questions that define strong reliability and cybersecurity programs, from classification through audit through enforcement response.
N ERC CO MP LIANC E S ENIO R ADV ISO RY Program support, interpretation, and audit Direct engagement on complex reliability preparation. questions.
I ND USTRY ENGAGEMENT AUD IT D EFENSE Standards development and working-group Notice of Penalty response and settlement participation. posture.
CONNECT WITH US Scan to visit
E N E RGY COMPL IAN CE , IN C. · EC-WP-305 · © 2026 · AL L RIGHTS RES E RV E D