Protection systems detect abnormal conditions and isolate them. The system depends on this happening correctly. When it doesn't, the system depends on the rest of the framework to limit the damage. PRC-004 misoperation analysis is one of the most-cited categories in NERC enforcement, and the misoperations themselves are reproducible patterns — settings drift, coordination gaps, missed maintenance. Protection misoperations don't always cause outages. But they always cause questions. Questions in a NERC investigation eventually become findings. Protection isn't an attribute. It's a discipline. Programs that treat it as installed-and-forgotten produce escalating findings. A misoperation traceable to settings drift is traceable to a process gap. The standards expect the process to catch the drift. A protection scheme that operated correctly during the contingency wasn't lucky. It was engineered, set, tested, and maintained for that exact moment. Misoperation rates correlate with program maturity. Mature programs have fewer. Less mature programs have more. The pattern is reproducible. Industry-wide misoperation trends drive standards revisions. Reading the trends tells you what's coming. From the Field Practitioner perspectives that frame the chapter ahead. Protection systems detect abnormal conditions and isolate them. The system depends on this happening correctly.
Contents
- Foreword
- The Role of Protection Systems in Bulk Electric System Reliability conditions, potential sources of human error, and inadequate operating procedures and control
- Protection System Misoperations as a Reliability Concept
- Misoperation Identification, Classification, and Reporting Frameworks
- Reliability Risk Implications of Protection System Misoperations
- Oversight, Analysis, and Industry Learning from Misoperations
- Boundaries Between Protection Engineering, Operations, and Reliability Oversight
- Evolving System Conditions and Emerging Misoperation Risk
- Systemic Risk, Pattern Recognition, and Reliability Context
- Reliability Objectives, Expectations, and Performance Perspective
- Misoperations in the Context of Reliability Events and Disturbances
- Reliability Oversight Without Prescription
- Synthesis and Reliability Perspective on Protection System Misoperations
- Glossary
- Glossary of Terms.
- About the Author
- About Energy Compliance, Inc.
Read offline
The complete reference is on this page. The PDF is for circulation inside your organization.
Download the PDFForeword
Foreword
This professional reference is one of a series Energy Compliance, Inc. publishes for registered entities and the people who run their compliance programs.
I’ve spent more than thirty years on every side of the bulk electric system. I’ve operated control centers as a Reliability Coordinator, Transmission Operator, and Power System Operator. I’ve audited grid facilities and signed off on findings as a senior compliance auditor. I’ve worked enforcement matters from inside the regulator’s process. For the last several years I’ve advised registered entities directly through the firm I founded.
The entities that do reliability well share a common habit. They take the standards seriously without confusing them with reliability itself. They know that a NERC Reliability Standard is a floor, not a ceiling. They know that compliance is something an auditor evaluates, but reliability is something a system either delivers or doesn’t. They prepare for audits by building programs that survive real questions, not binders that look thick.
That’s the perspective these references try to share. Each one focuses on a single topic. A standard family, an operational function, a regulatory framework, or an emerging industry challenge. Each one walks through how the topic actually works.
These references are written for the compliance manager who wants to understand the system, not just memorize requirements. For the legal counsel who has to brief a board honestly. For the senior operator who’s been told that compliance and reliability are the same thing and suspects they aren’t. And for the new compliance hire who got handed a binder and told good luck.
These references aren’t marketing material disguised as content. They’re the result of three decades of doing this work and watching it succeed and fail. I’ve written them in the same voice I use in a control room or in front of a Regional Entity audit team. Direct, evidence-grounded, honest about what the standards do and do not require.
Energy Compliance exists because most of the consulting offered to registered entities today is structured for billable hours rather than for outcomes. Every engagement is led by one senior practitioner. We don’t bring five people to a meeting that needs one. We automate the work that should be automated. We apply senior judgment to the work that requires it. If that approach matches what you’re looking for in a compliance partner, the back of this reference has our contact information.
If not, the reference still belongs to you. Take what’s useful. Apply it well. And remember the only test that ultimately matters: when the system needs to perform, does it?
Rob Smith, Founder, Energy Compliance, Inc.
EC-WP-306 System Protection and Misoperations
Chapter 1
The Role of Protection Systems in Bulk Electric System Reliability conditions, potential sources of human error, and inadequate operating procedures and control
measures that are also known to impact the likelihood of a misoperation occurring.
This E-Book focuses on NERC’s definition of protection system misoperations, how such events are categorized and reported, and the reasons behind the importance of consistent identification and analysis of misoperations to reliability oversight. It links the performance of protection systems to critical reliability functions including fault isolation, system stability, and proper coordination among separated systems, grids and utilities. It also highlights the importance of data gathering, analysis and knowledge sharing across the industry to enable a comprehensive risk-informed view of protection system performance.
It bridges gaps between protection engineering, operations and compliance assurance activities. It clarifies what the reliability framework is intended to measure and monitor, and what is therefore not in scope. Maintaining this clear understanding of what falls within versus outside the reliability framework for protection provides a context by which reliability organizations view protection systems without suggesting specific designs, configurations or operating practices.
This course is appropriate for a variety of roles within power systems operations, including management, compliance, planning, operations, and engineering. Roles that could benefit from an understanding of protection systems and misoperations from a reliability governance viewpoint are often tasked with conversing about the topic on an operational level. There may be a working understanding of the subject matter within the constraints of the power system operations and corporate reliability standards that have been put in place, but this knowledge may not be complemented with a clear appreciation of protection system behavior in relation to the reliability standards to which power systems operations are held accountable. This course serves to provide management, compliance, planning, operations and engineering personnel with a common ground for communication regarding protection system performance, within the constraints of current reliability regulations, and provides no guidance on compliance or the act of implementing requirements.
Protection systems are a basic tool for providing reliability services in the Bulk Electric System (BES). Their main purpose is to detect abnormal conditions of various nature and to perform in an automated manner the actions necessary to deal with faults in the power system to secure the affected equipment, reduce possible damage and ensure the continued reliable operation of the interconnected power system. Local in nature,
with operating times in the range of milliseconds, the cumulative impact of protection operations affects significant aspects of BES reliability at a system wide level including across multiple sub-stations, geographic areas and utilities.
When considering protection system reliability, the complexity and beauty of the design is not of primary importance. What is important is that the protection system can perform its reliability function for a large number of possible system configurations. In other words, the reliability function is the selective fault isolation (SFI) concept. Once a fault occurs in the system, the protection system is expected to
isolate the faulty component or section and retain as much of the rest of the system as possible. Effective protection system operation is vital to maintaining stability and to minimizing the effects of disturbances so that they do not develop into a reliability problem.
Protection systems are different from other reliability controls in that they operate without regard to operator actions or inputs from other control systems. Their performance is determined by their design, configuration, maintenance and testing, and their action occurs automatically and without real-time operator intervention. This can be both the greatest advantage and the greatest danger of protection systems. When they function properly they can provide the most rapid response to a disturbance. However, when they malfunction, they can cause harm to the power system in two opposing ways: - An instant that their operation is needed, the most critical components of the system are immediately removed from service, and the fault that they were intended to remove may not be cleared. - Seconds later, the resulting power system instability can cause additional components to be removed from service in cascade, greatly increasing the extent of the initial disturbance.
Reliability Standard D3_BES, Part D, Sections 1–3 Protection System Performance in the BES – Final Version 1 introduces a new framework for assessing and improving the reliability of protection systems that operate within the complex environment of the interconnected Bulk Electric System (BES). Today, protection systems operate within a coordinated environment. Assets of one registered entity may be electrically connected to facilities of another registered entity, and actions taken by protection systems at one location can rapidly affect large portions of the BES across organizational and jurisdictional boundaries. This reliability dependency is not local; it affects other systems, transmission interconnections, and regional reliability.
Although obvious, the reliability framework must consider that one impact of one component can affect the operation of other components; therefore, protection system performance is a question of collective risk rather than isolation to individual components
of the electric system. Current NERC reliability standards and associated documents with respect to protection systems do not prescribe the detailed design of protection systems, but rather define the expected performance, methods of monitoring protection system operation, and required analysis of protection system events. To facilitate uniformity, consistency and transparency to facilitate high quality determination of trends and potential reliability issues, standards define the expected performance, methods of monitoring and the associated actions for protection system events.
Definition of Terms and Concepts pertaining to Protection Systems: The terms protection intent and protection outcome pertain to a protection system’s expected states or modes of operation/confinement during a system event, and the resulting states or modes of operation/confinement that actually occurred. Reliability oversight is more focused on the protection outcome when the outcome is different from the intended protection state or mode of operation/confinement in a way that impacts Reliability.
This outcome-based focus to reliability oversight ensures that the approach to risk management for reliability is technology neutral.
Protection systems interact with other reliability functions such as system operation, system planning and asset management. The assumptions built into the protection schemes are based on the planning models and estimated system configurations. The reality of system operation may differ from the assumptions made in protection schemes design (due to topology changes, abnormal operating conditions etc.). In addition to this, the changes in generation capacities, load patterns and system configuration over time can lead to changes in fault characteristics and protection relay operation in a power system. Therefore, understanding protection system performance under varying operating conditions is essential.
From a reliability perspective, one of the oversights with protection systems is that they are one of the layers in the defense-in-depth strategy. In practice, they are not intended to be able to prevent any disturbances whatsoever, nor compensate for any shortcomings in the system. What is expected is that protection operations take place in a stable and predictable manner at all times. If this is not the case, the risks associated with any faults or malfunctions are by no means limited to the individual fault itself.
This chapter clarified the important role of protection systems as it related to the reliability of the Bulk Electric System (BES). Protection systems are treated as a reliability ‐ critical function because of their local action, far ‐ reaching consequences and their outcomes are among those most examined when determining the reliability of the BES. Misoperations are defined and discussed in considerable detail in order to establish a
clear understanding of what constitutes a misoperation of a protection system and consequently provides the backdrop against which misoperations can be identified as potential indicators of reliability risk.
End-of-Chapter Summary
Protection systems are considered a reliability control in the Bulk Electric System because they provide reliable automatic, high-speed fault detection and isolation functions to provide stability and support to disturbance management. Even though they operate locally with no operator intervention, the performance of protection systems can have far-reaching wide area reliability implications due to their operation on a interconnected system with system wide dependencies and common considerations among the registered Entities.
In a reliability view, the performance of protection systems is judged based on the outcome of the events to which they are applied, and not on the design features of the equipment. The difference between protection intent and real protection achieved is what turns a misoperation into a source of reliability
risk. The fact that protection equipments operate in isolation and immediately upon detection of abnormal conditions, adds to the potential for incorrect operation or failure to operate to escalate quickly a local disturbance into a significant power system event.
Reliability oversight treats protection system performance as a matter of collective risk concern focusing on reliability, consistency, coordination and result-based analysis throughout the interconnected system. The chapter lays the groundwork for treating misoperations as reliability indicators and sets the stage for discussing in greater detail the definitions, categorizations and analyses of misoperations within the context of the NERC reliability definitions.
Chapter 2
Protection System Misoperations as a Reliability Concept
Protection system misoperations are a serious reliability concern. Misoperations occur when protection system operations are not what is required or expected. In the context of the Bulk Electric System (BES) reliability, misoperations are not viewed as simple matter of an individual protection relay operating in an other than normal fashion. Rather, a misoperation is viewed as an event of sufficient consequence to impact power system stability, relay coordination, or the ability to confine disturbances within the system. Understanding misoperations as a reliability concept requires an understanding of what constitutes a misoperation, why they are important, and how FERC and regional reliability organizations view misoperations from an oversight perspective. A protection system misoperation as defined within the NERC reliability framework is an event in which a protection system operates improperly or does not operate when expected. Outcomes rather than design intent are considered, to ensure that the reliability framework does not make design choices related to protection technologies or methods. Misoperations could be classified into several types, including such things as unintended trips, failure to trip for fault conditions, incorrect identification of components to be tripped, and delayed operation with resulting loss of coordination. While understanding the technical cause of a misoperation may be important for design correction, the real concern is the system impact of the event. Misoperations could be classified as major because the system reacted in a manner which was different from that intended. In certain instances the system topology could be changed by the misoperation in such a way that important components of the system are removed from the system. Other misoperations may involve leaving faulted elements energized for some period of time longer than desired. Reliability impact of misoperations depends on timing and system conditions. A protection system takes action within milliseconds before any operator can even realize that a disturbance is occurring. The effects of a misoperation are immediate and irreversible. This is quite different from other types of reliability events. The impact on the system may
occur within milliseconds but the underlying condition may take seconds or even minutes to develop and for the effects to be reversed by an operator taking appropriate action. Misoperations are critical to understanding cascading because they can create the key cascading conditions. An unjustified or improperly coordinated protection response can, for example, over-load resources that are still operational, cause power to move in unintended directions or cause reductions in system reserves.
Similarly, a failure to operate when it should could allow a disturbance on the power system to continue and for abnormal operating conditions to develop such as damage to equipment, unstable transients, or further protection operations at remote points on the system. From the oversight perspective a misoperation is not determined based solely on whether an disturbance occurred. The protection system response is also checked for consistency with the reliability criteria expected for the particular system condition. Therefore, a misoperation can be only determined if there is lack of consistency between the system response to relatively small disturbances and the expected system behaviour for a specific system condition; even if no significant effect is otherwise observed. The fact that the consequence of the incident was minimal, does not preclude the oversight to take the incident into account, should the consequence in a different scenario be more serious. This proactive attitude is inherent to risk-based reliability oversight. Note: The NERC reliability standard also emphasizes the importance of the consistent high accuracy of the identification and classification of misoperations for grid reliability analysis purposes. Using standardized identification and description of misoperations, and standardized analysis constructs, allows for comparison and aggregation of misoperations occurrences across operations teams, control centers, and geographically, over time. Analysis of misoperations occurring under these circumstances contributes to reliability analysis and provides more meaningful information regarding systems reliability, rather than being considered purely a technological incident. Reliability analysis of protection system misoperations also needs to consider the classification of a misoperation as a fault or an error, which is not always clear-cut. The discussion of misoperations is not intended to imply that a misoperation is necessarily an evidence of neglect or omission on the part of any person. Rather, misoperations are viewed as events for which causes can be identified in relation to protection system design, system operating characteristics, system configuration and operational procedures. This type of objectivity in treatment and documentation of misoperations is also desirable for improving objectivity in the reliability analysis. Misoperations fall into this category because they occur in the
transition zone between the design team’s assumptions about protective system operation and the actual behavior of the power system. Misoperations result from many things including changes to system configuration, additions or changes in generation sources, changes in fault characteristics, etc. and can be the result of a change in operating procedures. The boundary between design assumptions and reality in the Bulk Electric System (BES) is becoming more real by the day and considering misoperations a reliability issue not just a pure protection issue is becoming more and more appropriate. The material in this Chapter establishes misoperations as a key reliability concept from the standpoint of outcome, system impact, and risk posture. From this perspective, including misoperations as a reliability concept provides a consistent basis for assessing the operation of protection systems and for determining where potential sources of risk exist in a system, without entering into specific design or operational details.
End-of-Chapter Summary
Procedural faults such as protection system misoperations, are considered as risk indicators for reliability purposes, due to their nature of being an event consequence, which is not necessarily a pure technological fault. Misoperations mean that the protection system has behaved in an undesired manner that could lead to instability, loss of synchronization or failure to damp out disturbances. Reliability-wise, misoperations are classified into three main categories in relation to their impact on the power system as well as their influence on potential cascading effects. The first category is related to the immediacy in time of occurrence of a fault. The second one concerns the extent of the system impact following the event. The third one refers to the potential of a misoperation to lead to cascading effects.
In chapter 3 we apply the NERC definitions of misoperations to high voltage transmission network reliability risk analysis and observe that their basis for using standard definitions, for protection misoperation identification and for data analysis facilitates using misoperations as an adjunct tool in reliability risk analysis. The purpose of this chapter is to establish why misoperations are of primary concern in protection monitoring and to highlight their key role linking the behavior of protection at the substation level with reliability at the network level.
Chapter 3
Misoperation Identification, Classification, and Reporting Frameworks
Classification and identification of protection system misoperations is a key factor in the treatment of misoperations as a reliability concern as opposed to mere random events. Misoperations will be evaluated using the established definitions and data elements (i.e., categories) for reliability analysis purposes, as outlined in the Reliability Volume BES_R1, and used in the reliability reporting structures as described in the Reliability Volume for the Bulk Electric System reliability activities conducted by registered entities and regions. This segment starts with the determination that the reaction of a protection system does not match the expected behavior for the specific state of the power system. Again, the key factor is not the intention, but the factually recorded behavior of the protection system. The evaluation does not deal with the design quality of the protection relays, but rather with whether their action or inaction matches the reliability function defined for this specific system component and its specific operating condition. Within the NERC reliability framework, misoperations are organized into several categories in order to facilitate identification, analysis, and uniform reporting. These categories identify two primary risk elements related to misoperations: the failure to operate (FTO) and the unintended operation (UG). An FTO occurs when a protective relay does not operate when it is supposed to. Such occurrences can result in faults remaining on-line and with potential to cause further harm to other system components should exposure to potential faults continue. An UG occurs when a relay operates when it is not supposed to operate. The action of such an unwanted operation can result in unnecessary removal of system components and can result in an unintended change to the system configuration. Faults that can be classified by determining whether the fault resulted in a protection system component failing, a logic/ communication failure, or an interaction between systems resulting in an unexpected outcome. Although the individual root causes may be quite different, classification into one of these fault types will ensure that faults resulting in the same set of symptoms are classified consistently and thus can be appropriately compared and
analyzed to identify common themes that may reflect conditions arising in other comparable systems. The purpose of reporting misoperations to the RRT is: To provide management within an entity with information necessary to understand the performance of its protection system and to understand the extent of problems and their solutions. To provide NERC and Regional Entities with enough information to do trend analysis and identify problems that occur frequently, and to determine if new problems
require action. The process of developing procedures to obtain and analyze this information must provide enough detail to be useful, but not so much that the resulting data is hard to use for comparative purposes across the entire power system. Reliability framework emphasizes the importance of timely and accurate misoperation reporting. Because the information reported on misoperations is relevant to a short period of time in the power system, timely and accurate information is crucial. Accurate information on misoperations supports accurate analysis and enables reliable aggregation. Blame or corrective actions are not intended. The purpose of the reporting framework is to assist in reliability oversight with insights derived from understanding violations and unusual operations. In the framework, misoperations are consistently defined and recorded thereby providing a uniform method of monitoring and comparing protection system performance across utilities and regions. This uniformity is particularly important in today’s large inter-connected transmission networks where the impact of a single event can cascade far beyond the point of origin. Misoperation data contributes to reliability efforts on a systems-wide basis. Trends and patterns in the data may lead to updates of guidance documents, the issuance of technical reports, or discussion in the reliability community to enhance the effectiveness and efficiency of protection system operations, again, without requiring specific actions to be taken to correct misoperations. This framework differentiates between reliability oversight and protection engineering. Oversight focuses on what occurred and its significance to the overall power system, not on the design or settings of protection systems. Differentiating between these two areas ensures the technology neutrality of the reliability framework, while still providing means to address risks associated with protection system performance. This chapter examined how misoperations are identified, classified and recorded within the NERC reliability framework. The framework utilizes standardized definitions and outcome-based criteria for assessing power system protection activities to facilitate uniform analysis and riskinformed reliability monitoring.
End-of-Chapter Summary
Identify, classify and report protection system misoperations is a prerequisite to treat protection system misoperations as a reliability issue rather than simply as separate events. Defining key terms and categorizing misoperation outcomes facilitates comparison and analysis among companies and locations.
The RSP Reporting Framework bases the reliability assessment on the achievement of key performance indicators, namely: measurable outcomes, timeliness and accuracy. Such an approach is adequate to support risk-informed reliability surveillance with the necessary integration and consistency, while strictly separating reliability surveillance activities from protection system design and engineering activities. This chapter demonstrated how structured misoperation data can be used to allow for industry-wide knowledge sharing and to gain insights on reliability risk associated with power systems.
Chapter 4
Reliability Risk Implications of Protection System Misoperations
Protection system misoperations can have significant reliability implications far beyond the instant of the event. When evaluating misoperations within the context of Bulk Electric System (BES) reliability, consideration is given not only to the immediate impact of the misoperation, but also to the potential risk to system stability, improper coordination, and disturbance suppression, all of which can surface under different or more stressful system conditions. One of the major reliability risks associated with misoperations is the potential for unintended change to the system topology. An incorrect protection operation can be designed to remove lines, transformers, generators, or other equipment from service when no such action is required. When such unnecessary removals of transmission lines, transformers, generators, etc. occur, they can lead to unforeseen changes in power flow, increased loading on other components of the system, and reduced margin for further contingencies. A misoperation that does not lead to instability in the short term, may yet make the system more susceptible to a subsequent event. Non-reset failures are a new reliability risk Different to other risks, a non-reset failure to operate is a situation where the protection does not operate appropriately during a fault and consequently the fault clears more slowly than is considered in planning and operational models. Long fault clearance times can expose the system to increased risk of further faults due to potential overheating, unstable voltages, etc. Non-reset failures to operate can also trigger further protection actions on other parts of the system and potentially result in a cascade of failures. Misoperations add an element of uncertainty to the reliability analysis of power systems. Protection system reliability is predicated on the idea of reliable, rapid response to abnormal system conditions. Unexpected or erratic operation of protective relays erodes the assumptions used in system analysis and relaying studies. The uncertainty of protective relay behavior not only affects real time operating and control, but also the results of planning studies, operating procedures, operating guides and the analysis of system performance following disturbances. The impact of a misoperation can be a function of the state of the grid at the time of the event. A misoperation that in one circumstance may have minimal immediate impact on the grid, in another circumstance with more stressed conditions (such as high load, low margin, etc.), could have a much more dramatic effect. Reliability analysis considers the impact of a misoperation given full recognition of the circumstances of the event. Reliability issues that cause misoperations can lead to changes in the situational awareness of the operators that are interacting with the power system. The situational awareness is the understanding that an operator has about a situation and it is built upon the expected behaviors of all of the
components in the system. For the operators, it is expected that they will understand the reason for an alarm, a change in the system state or the sequence of events that are happening. This understanding is often impacted by unexpected protection actions especially during disturbances where the events are happening in real time and the operators must be able to react quickly in order to have an impact on the system behavior. Therefore, the erosion of the situational awareness contributes to another source of risk in addition to the physical effects of the misoperation. Because of the interconnected nature of the BES, the risk implications of misoperations are magnified. Operation of protection relays at one point on the BES can cause disturbances in adjacent systems that may cross multiple boundaries, including those of geographic territories and/or utilities. A misoperation at one location can be propagated through the system, potentially challenging relays at other points and increasing the likelihood of secondary misoperations or mutual interactions. Therefore, there is a strong need to consider misoperations in the context of a holistic BES reliability assessment. Reliability oversight does not assume that every potential misoperation will have adverse consequences. Misoperations are viewed as an indicator of potential risk exposure. Recurring misoperations can be an indicator of potential system vulnerabilities, and may be an early warning sign that the system could experience a more severe event in a different circumstance. This probabilistic view is consistent with risk-based oversight that focuses on mitigating risk exposure to those conditions that could potentially lead to rare high-consequence events. This chapter analyzed how Relay Misoperations translate into Reliability Risk consequences to power system topology, stability, predictability and situational awareness. Understanding the risk consequences of Relay Misoperations is important in order to utilize Relay Misoperation data in a meaningful way and to understand why Relay Misoperations are a focal point of the Reliability Monica, even though their direct consequences are generally minimal.
End-of-Chapter Summary
Protection system misoperations cause reliability problems by changing the configuration of the system, by extending the time that a fault exists, and by not following the expected behavior of the system. Misoperations, as well as non-operating correctly, can also increase the vulnerability of the system under stressed conditions due to reduction of margins and increased degree of uncertainty.
Reliability oversight views misoperations in their operational and system circumstances and focuses on the consequences that result from the misoperation of power apparatus, which may not always be immediately apparent. This chapter sets out the reasons why misoperations are viewed as risk indicators and their wide-reaching effects on reliability.
Chapter 5
Oversight, Analysis, and Industry Learning from Misoperations
Reliability oversight of protection system misoperations will be accomplished by analyzing large amounts of data, performing detailed technical analysis, and learning from incidents to gain system wide insight into risk. Overseeing the reliability of the Bulk Electric System (BES) through protection system misoperations does not require prescriptive protection system designs or operational procedures. Rather, it is more about being able to view resulting system performance and patterns in that performance that may indicate new or systemic reliability issues. We utilize misoperation data for our oversight activities in order to gain insight as to how our protection systems operate over a wide range of system states and configurations. A single misoperation may appear relatively unimportant. However, when viewed in a mass, (as patterns) the misoperations frequently tie back to assumptions inherent in the protection schemes, as well as system changes which have taken place since protection schemes were implemented, or to interactions between different systems facilities, which when considered in totality give great insight into the overall risk to the reliability of the system, rather than trying to ascertain the relative merits of individual events. BFDs based on misoperation analysis focus on the frequency, incidence, and circumstances of misoperations, as well as other relevant factors, and seldom cover the technical reasons of the occurrences. Oversight identifies circumstances that should trigger further investigation, including trends in specific types of misoperation, or repeated misoperations at the same facilities, or across entities and/or areas. Insights from this analysis allow utilities to understand the extent and nature of reliability risk problems even when significant power disruptions have not occurred. Industry learning is a significant outcome of the oversight activity. Misoperation analysis findings may be incorporated into technical reports, lessons learned reports or industry discussions to alert industry to reliability problems that have been observed. Informatory in nature, these documents do not impose any requirement on industry members. Rather they provide tools to raise industry awareness of observed trends and contextual information. The reliability framework provides a means of facilitating industry-wide voluntary improvement and risk reduction. Misoperation oversight and the need for consistent interpretation and reporting The TCR addresses several issues discussed during the reliability oversight roundtable, including the relationship between misoperation oversight and the need for consistent interpretation and reporting of misoperations. The panelists agreed that misoperation oversight is enhanced by having consistent understanding of what constitutes a misoperation and how misoperations are reported. The lack of uniformity in describing or
classifying misoperations can distort the data and obscure meaningful trends. Therefore, reliability oversight places a premium on clarity, consistency and transparency in reporting. Consistent reporting enhances the utility of and credibility of comparative analyses. There are multiple oversight scenarios where misoperation data may be used; however, the reliability of that data is probably its most value to learning and risk identification activities. Handling misoperations as learning opportunities versus violations will impact how operators will report misoperations. Operators will likely choose not to report as violations events if they perceive penalties for small errors. The Bulk Electric System is undergoing a tremendous amount of change. As these changes occur, monitoring and learning about the system becomes more critical. With the variety of changes occurring including: changes in the generation resource mix, the increased use of power electronics, system restructuring, and operating practices, it is important to understand how these interactions affect and stress the protection systems that enable reliable power delivery. Misoperation analysis serves as a useful tool to begin to observe and understand these interactions and to provide an early indication of potential reliability issues that may arise in the future. This chapter discussed how oversight organizations analyze misoperation data and learned lessons for the industry. The Reliability Framework, by focusing on aggregated outcomes, contextual analysis and common understanding of misoperations uses near misses and misoperations as a mean to manage risk at the system level, without entering into protection engineering details and without prejudging operational choices.
End-of-Chapter Summary
Reliability oversight of Protection System Misoperations (PSMs) activity involves the use of aggregated data and analyses to identify trends or issues that are not self-evident in the individual events. The emphasis is on consistency, transparency and judgements relative to the context, in order to assist in developing a risk informed perspective of performance issues.
Industry learning derived from misoperation analysis promotes awareness of reliability issues on a common basis to all parties in transmission and generation operations, while clarifying the interfaces between functions and limiting the scope of each function. The chapter demonstrates the role of misoperations in being a catalyst for system-wide learning and risk reduction activities within the reliability framework.
Chapter 6
Boundaries Between Protection Engineering, Operations, and Reliability Oversight
Protection system misoperations can be viewed as occurring at the interfaces between several functional areas that are critical to the operation of an electric power system, including protection engineering, real-time operations, maintenance and reliability monitoring. Identifying and clearly defining these interfaces is important for appropriate identification of misoperations and for ensuring that the reliability framework tracks anomalies appropriately. If these interfaces are not clearly defined, then technical decisions may be confused with reliability criteria which can lead to a number of undesirable practices in protection engineering, as well as to an inappropriate use of reliability monitoring. Protection engineering is concerned with design, application and performance of protection systems. It includes the aspects of protection philosophy, protection relays’ settings and coordination assumptions. This is a highly technical aspect with a large degree of discretion and hence a lot dependent on the physical properties of the assets and network configuration. Under reliability framework, the engineering part of protection systems remains the exclusive prerogative of asset owners and utility engineers and is not dealt within reliability regulations. This includes all real-time activities that ensure the system is operating in a stable state under normal and abnormal conditions. Protection system operations are viewed as an automatic barrier to prevent severe accidents by providing a rapid response that does not involve the time and resources of the operator. In most cases, the operator has no influence over the activities of the protection systems during an event. Misoperations can cause significant difficulties to the operator by inducing adverse changes to the state of the system. These changes are difficult to understand and must be controlled by the operator in a short time frame and under conditions of high uncertainty. Reliability oversight is neither design nor operations. Rather, it is about understanding how protection systems behave from a system reliability perspective and whether the resulting behavior is reliable or not. It is not about whether the protection
scheme was properly designed, or whether a different design or set of design choices would have prevented a misoperation. Rather, it is about the impact of what actually occurred to the Bulk Electric System reliability. The integrity of reliability roles requires that they be kept separate. Reaction to misoperations usually begins with a search for technical cause and blame. While technology is essential
to all aspects of engineering and asset management, reliability assurance is not a technical exercise but rather a holistic function monitoring patterns, trends and risk. Retrospective evaluation should not prejudice legitimate efforts to assess the impact of a misoperation. It’s important to remember that the reliability framework is there to support these boundaries. The focus is on assessing system outcomes and setting technology neutral reliability criteria. The standard and guidance documents focus on what needs to be seen, recorded or analyzed rather than how the protection systems are designed or operated. The reliability framework is intended to address the reliability risk associated with protection system performance while still allowing for a wide range of system configurations and technologies. Ideally, you would like to have clear boundaries between activities so that communication between departments or individuals is effective. By describing misoperations using a reliability vocabulary, one can clearly distinguish between efforts to design improvements and discussions about their impact on overall system risk. This prevents misunderstanding and ensures that regulatory reviews or audits are viewed as additive to, rather than a constraint on, engineering and operations activities. The Bulk Electric System is evolving, and the boundaries of the System must be protected and preserved. New technologies, changing fault characteristics and operational practices can all challenge conventional understanding incorporated into design and control algorithms. Reliability oversight enables observation of resulting performance effects without mandating any specific actions and provides a flexible tool to monitor and exercise judgment regarding evolving risk conditions. This chapter clarifies the Scope of Protection Engineering, Operations and Reliability Services with respect to misoperations within a reliability framework. Such delineation of Scope provides an objective basis for analysis, and enables a framework for learning and balance of protection system reliability risk.
End-of-Chapter Summary
Protection system misoperations occur at the boundary of engineering, operations and reliability. To analyze this objective accurately, clear boundaries are required. In power systems, the boundary for protection engineering is defined by technical questions related to design of protection relays, for operations – by the operational tasks related to activation of protective functions, and for reliability – by analyzing the system wide risk related to potential consequences of misoperation of protective relays.
Reliability framework after the reform maintains an outcome-based, technology-neutral perspective, and therefore does not prescribe technical measures or processes. It was shown in this chapter that clear boundaries provide a basis for learning, clear interpretation and thus balanced protection system reliability risk management.
Chapter 7
Evolving System Conditions and Emerging Misoperation Risk
Reliability Risk of Protection System Misoperations is a Dynamic Challenge The reliability risk of protection system misoperations is a dynamic challenge that continues to exist in the Bulk Electric System (BES). Advances in technology and changes in the BES result in new operating conditions which can potentially impact the assumptions made in protection philosophies and could lead to unforeseen protection system behavior resulting in misoperations. Reliability oversight of the BES requires a comprehensive understanding of the impact of evolving system conditions on the risk of protection system misoperations to maintain situational awareness. The change in generation resources connected to the BES is one of the main factors influencing the power system. The changes in generation resources mix, operating conditions, fault characteristics etc., lead to a change in system behavior during fault conditions. The protection systems were specified and coordinated based on the previous system characteristics. When these changes in system characteristics materialize in a disturbing event, they end up occurring in a different material than what the original design or coordination specified. Protection design and engineering of protection systems deal with the change of generation mix and resources at the asset level, whereas reliability oversight will also monitor how the changes impact the misoperations observed. Each year we examine the Misoperation Risk due to changes in system topology. These changes can be due to a transmission project, the replacement of an old power line or transformer, or a change in system configuration (temporary configuration for maintenance, etc.). It is important to recognize that changes in system topology can affect system faults, impedances and loads which are all variables taken into account in protection system design. Temporary operating configurations may also introduce increased stresses on design assumptions, which could indicate that protection system performance is becoming more volatile and that reliability issues could start to arise at more than the facility level. In this instance increased system complexity has lead to an emerging misoperation risk. Modern protection systems now have more communication
interfaces, sophisticated algorithms and elements which are interdependent. Even though reliability analysis has indicated that the added sophistication is reliable, the unforeseen consequences of such complexity and the resulting potential for interactions have led to unexpected misoperations which have had a detrimental effect. Misoperations can highlight unrecognised interactions that had not been uncovered during design audits. Operational practices impact misoperation risk as well. Changes in
dispatch schedules, power flow direction, or contingency handling may affect system operating conditions. Although operators do not directly cause protection to act, their operational decisions affect the protection environment in which systems operate. Reliability oversight therefore takes into account the operational conditions impacting trends in misoperations that result from combined technical and operational system conditions. Like vulnerabilities and significant technical errors, emerging risks are often identified through analysis of individual events, but their underlying reasons may relate more to a change in the misoperation characteristics. For example, an increase in the number of occurrences for a specific type of misoperation, a change in the circumstances under which such errors are recorded or similar misoperations being observed in other entities may indicate a change in the assumptions underlying the proper functioning of electricity systems. Reliability oversight is about using these “flags” to alert and raise awareness about potential emerging risks and for further investigation, rather than for immediate determination of root cause or liability. The changing nature of the Bulk Electric System makes a risk-based approach to misoperations even more important. Rather than treating misoperations as static compliance requirements, TPL talked about how the reliability framework views misoperations as a dynamic “proxy” for the way protective systems will behave on the BES given its constantly changing nature. It makes a lot of sense as it promotes flexibility and the fact that regulations have to adapt to changing technologies and operating practices. This chapter examined the effects of changing generation and transmission resources, system configuration, and operation on misoperation risk. It explored the connection between misoperations and the evolving character of the grid reliability system, using the reliability framework to detect potential reliability issues arising from these changes and provide a qualitative warning of the potential for future reliability problems, without necessarily indicating that corrective actions are required or that technological or operational countermeasures are necessary.
End-of-Chapter Summary
Misoperation risk for protection systems is a factor that is being changed by the evolving conditions of the Bulk Electric System (BES) due to potentially invalidating a number of assumptions regarding BES generation and configuration including increased system complexity. Misoperations potentially occurring on the BES are an indication that the established protection system expectations for the System are being stretched.
Reliability oversight monitors the Grid Performance and uses trends and patterns from misoperation data to monitor and assess potential new risks related to system development. Misoperations as Dynamic Reliability Indicators for the Grid Misoperations are more than just simple technical faults. This chapter has explored how they may serve as dynamic reliability indicators and therefore reveal the evolving nature of the power system.
Chapter 8
Systemic Risk, Pattern Recognition, and Reliability Context
Protection system misoperations are a key element in considering systemic risk. While an individual misoperation to either a piece of equipment or a segment of the grid may appear to be relatively minor in individual consequence, when viewed as a series of events over time it can potentially reveal systemic vulnerabilities in the BES. This aspect of reliability monitoring is heavily dependent upon detecting and understanding patterns and context in order to ensure that any individual misoperation is recognized for its impact upon the larger system reliability. The occurrence of systemic risk suggests that similar misoperations occur in multiple places and times (e.g., across different locations, systems, financial institutions, or geographic regions) or occur under similar systemic conditions where other similar failures occur in clusters. This indicates that the underlying causes are more likely to be associated with broad-sweeping assumptions, characteristics of the system, or general operating practices rather than with individual system components or specific design features. While the occurrence of a single failure is relatively uninformative from a reliability perspective, the identification of such patterns is potentially very valuable. Pattern recognition requires consistent classification and reporting of misoperations. Without uniform definitions and outcome-based categories, it is difficult to determine whether a particular incident is an anomaly or if there are trends. For reliability oversight, this type of data is used to determine if there is a trend of certain types of misoperations, if they occur under certain system conditions, or if they are related to changes in system design or operations, and to determine if they are indicators of reliability stress on the power system. Context is key to understanding misoperation patterns. A number of misoperations occurring during atypical system conditions, heavy load, or other unusual events may simply be an indication of a system being sensitive to one or more unusual events, rather than any performance problem. On the other hand, events that occur during a variety of normal system conditions may point to a different type of reliability problem. The context of the frequent misoperations should be considered
during an oversight analysis of the reliability of the system and its components. The analysis of systemic risks may also involve mutual impacts between protection functions and other reliability functions. Misoperations may occur during difficult operating conditions such as decreased situational awareness, and decreased system margins, thereby having a more significant impact on power system reliability. Misoperations may act as triggers for larger disturbances or even contribute to their occurrence
(although the affected power system element(s) do not suffer any significant amounts of load loss as a result of the misoperation). These interactions between protection functions and other reliability functions require to be understood in order to evaluate the effects of any protection functions misoperation on the system reliability. Reliability oversight does not imply that patterns in data confirm conclusions about cause and effect. Patterns may represent potential warning signs that may require further investigation, discussion or awareness within the industry. Handling patterns in reliability data in a more cautionary manner can act as an educational tool to raise risk awareness without immediately prejudging technological or procedural failures. The increased interest in the topic of systemic risk underscores the need for a holistic view of protection system operation. Having visibility across the industry provides a common dataset and means of evaluating findings. This shared knowledge can be used to confirm or dispute observations made by any individual component within the system, and it can be used to develop a more complete understanding of trends that may be difficult to spot by looking only at individual pieces. The interconnected nature of modern systems further highlights the importance of viewing protection system operation on a system-wide basis in order to preserve overall reliability. This chapter has examined how pattern recognition and contextual analysis can be used to determine instances of systemic reliability risk associated with protection system misoperations. Reliability analysis based on aggregated effects and system wide context can be used to gain insight into potential problems or vulnerabilities that are not always present in individual system components.
End-of-Chapter Summary
Systemic reliability risk associated with protection system misoperations is generally a matter of patterns and relationships that may not be apparent during the review of individual events. Through analysis of aggregated misoperation data, reliability managers can uncover patterns and clusters of misoperations, as well as relationships between misoperations and various system parameters that may be indicative of more systemic risks.
Through the analysis of misoperation patterns in the context of their operations and systems, reliability concerns that may develop over time are identified and addressed in a manner that clearly differentiates them from prescriptive controls. The Chapter discussed the nature of misoperations as an indicator of a broad risk to the BES.
Chapter 9
Reliability Objectives, Expectations, and Performance Perspective
Protection system misoperations are analyzed within a reliability context relative to defined reliability criteria (objectives) rather than an absolute criterion of right or wrong. Since the BES does not require that protection systems perform perfectly in all probabilistic circumstances, reliability analysis reviews whether the protection system performance supports BES reliability objectives. A main reliability objective of protection functions is the rapid separation of faults (selective and quick disconnection of a fault). This means that protection is required to be able to remove or switch off faulted components quickly enough so that the entire system remains stable after a fault occurs and minimum component sections are switched off. Misoperations of protection (i.e. inappropriately triggering a disconnect command or keeping a faulted component connected for too long) greatly impede these basic performance criteria in reality. Therefore, the protection system performance is evaluated as to what extent its operational behavior at real-time fault conditions on the power system meets these performance criteria. There are several objectives related to reliability that must be considered when designing and operating systems that include protection equipment. In addition to a high level of reliability, another important objective is predictability. Reliable system operation is obtained when the dynamic behavior of the system is sufficiently stable, i.e. with sufficient predictability to correspond to the basic reliability assumptions. In particular, protection functions should act in a manner that is in line with the assumption used for design, planning and operational studies. Misoperations represent a factor of unpredictability that can generate added complexity for operational management during disturbances and for the post-event analysis. In reliability terms, unpredictability itself represents a risk, even if the consequences of misoperations are limited in time. Coordination is also a factor that affects reliability. Protection operations are designed in a coordinated system environment where numerous protection devices and schemes function together to achieve selective switching and isolation of faulted sections. Misoperations that occur may be the symptom of a failure
in one or more of the assumptions made on the coordinated operation of the system under different operating conditions, configuration changes, or complexities introduced by multiple relaying functions and protective schemes. Reliability analysis of misoperations deals with the impact on the coordinated function of the system, rather than with the coordination criteria or methods used. The Performance perspective from a reliability perspective is outcome-oriented and situation-dependent. The
performance of protection systems is not related to a benchmark of perfect performance. Instead, performance is assessed relative to specific reliability goals and circumstances that can occur while the power system is in various operating conditions. A misoperation that occurs in an abnormal situation is not necessarily viewed in the same light as a misoperation that occurs in a normal operating mode. Assessing performance in a situational context provides a more balanced perspective that avoids drawing overly broad conclusions based on limited or unusual events. In the reliability world there are many other systems and structures that must be accounted for, other than the protection systems that we regulate, and misoperations alone do not mean that a site’s overall reliability posture has failed. What’s important to consider is when there are a series of events at important locations and/or similar events at different times that might indicate a weakening of a layer of the defense-in-depth (DID) posture and the need for further examination and understanding of potential effects to system reliability. Oversight is all about identifying anomalies or potential indicators of future issues and analyzing their impacts to reliability and safety. Reliability Framework (RF): The Performance Expectations Evolve with the System The RF recognizes that the performance expectations may change over time and as the system evolves. As operating, technological and system conditions change, the protection system performance in the actual operating conditions must be validated by current operating experience to ensure the protection system continues to meet the current reliability requirements. Misoperations provide valuable direct operating experience information on system performance and serve to validate or otherwise the current expectations, without implying any requirements for modification. This chapter focuses on protection system misoperations from the viewpoint of reliability goals, expectations, and performance perspective. By placing misoperations in this perspective, the reliability framework retains focus on the systemic effects and performance of the power system, while at the same time addressing in a balanced and dynamic fashion the reliability-related technical issues involved in protection operations.
End-of-Chapter Summary
Reliability Rules for Evaluation of Power System Protection Misoperations (PSM) The subject of power system protection misoperations (PSM) reliability evaluation is discussed within the framework of reliability rules relevant to selective fault elimination, fault occurrence predictability and fault coordination reliability criteria. Reliability monitoring is generally based on an outcome oriented and context dependent performance assessment standard, implying that no particular level of performance has to be met at all times.
By seeing the mistake from the performance perspective to the dynamic state of the power system at the time of the occurrence, it was observed through reliability framework that the effect of the
protection system action as a reliability defense layer was checked and it was verified how the reliability targets of the system influenced the importance of the misoperations to the power system reliability.
Chapter 10
Misoperations in the Context of Reliability Events and Disturbances
Protection system misoperations are often scrutinized in the greatest detail when they occur during reliability events or system disturbances. Misoperations occurring during these events and disturbances can affect the progression, impact, and recovery of the event. The reliability effort views misoperations occurring in the BES as part of the sequence of events, rather than as an isolated occurrence. Protection system performance during disturbances is generally presumed to be consistent with the assumptions embedded in contingency analysis, operating conditions, and emergency response plans. In the event of a misoperation, these assumptions may be proven false and the resulting system behavior is uncertain. From the reliability perspective, this is a material deviation because it is occurring during the most stressing aspects of system operations. Misoperations can occur at several levels during a disturbance. They can either lead to increased exposure and therefore contribute to the initiation of an event by unnecessarily removing resources and not properly isolating the fault; or they can occur as secondary misoperations after the initial event, when the power system is already in a vulnerable state. Reliability oversight looks at these misoperations in the context of the sequence of events and therefore considers the impact of timing and system conditions on the magnitude of the consequences and the level of risk. Misoperations in a power system refer to actions or decisions taken by operations personnel or automated control systems that, based on the subsequent development of events, are not appropriate for the initial circumstances. These actions are deemed to be incorrect, at least in retrospect. Misoperations in a power system can affect the probability that a cascading condition occurs and can affect the extent to which such a condition develops. Cascading conditions occur as a sequence of failures of power system components following an initial event (disturbance). Some of these failures occur intentionally, in the form of preplanned system activation or other control actions aimed at preventing subsequent power line faults. However, other power system component failures may not occur in an intended or controlled fashion and so can be termed as occurring under cascading conditions rather than by design. Such cascading conditions occur after an initial event when the resulting power system states following each successive failure do not return to stable conditions such that all important power system components remain operative. In such scenarios, cascading conditions may be hastened, or the consequences thereof increased, because misoperations can: Increase current flows on the power lines to which switching instructions are directed and thus contribute to possible line failures. Reduce possible alternatives to select, as more options for transferring power may become unavailable as
component failures continue. Cause protection systems to order removal of additional power lines from service as a preventative measure in an already unstable power system. Increase the likelihood that cascading conditions will occur, since each event provides additional uncertainties and instabilities that contribute to possible failures of other power system components. Reliability event analysis also explores the impact of misoperations on system recovery after an event. Unexpected protection actions can cause additional outages that hinder restoration by obscuring the location of the initial fault, or by causing changes in system configuration that require further corrective actions. From a reliability oversight perspective, these challenges to restoration are seen as a continued manifestation of misoperation risk extending beyond the period of the initial disturbance. We must differentiate between those misoperations that are a direct result of a disturbance and those that occur incidentally. Not all misoperations have a material impact on the outcome of the event and the causality is not based solely on the timing of the misoperation. In order to determine whether a misoperation had a material impact, we need to determine whether the misoperation had any effect on the plant response, margin or operator action during the event. Reliability models may use event analysis in order to relate misoperations to the reliability model through contextualizing the event and in order to better assess the protection system behavior during stressed conditions. Findings may be discussed in relation to the overall system robustness, defense-in-depth and interactions between protection systems and other reliability control measures. These discussions are still at a non-prescriptive level. This chapter examined protection system misoperations relative to reliability events and disturbances. With the misoperations looked at in the context of the event sequences, the chapter brought the discussion full circle relative to the focus of the chapter on establishing an integrated perspective for evaluating the performance and risk of electric power transmission and distribution systems.
End-of-Chapter Summary
Protection system misoperations may affect the initiation, development and restoration of reliability events by altering the system behavior during disturbances. The relative importance of these effects depends on the timing, the system operating conditions and the mutual interaction with other protection and control actions.
Reliability oversight monitors non-normal operating events within the framework of sequences of events to determine the impact of specific events on risk and to quantify the impact of each single event on reliability, without necessarily concluding that the event was the cause of the problem. This chapter discussed the need for contextual event analysis to ascertain the reliability consequences of misoperations.
Chapter 11
Reliability Oversight Without Prescription
A central tenet of the new BES reliability standard is the focus on risk monitoring with only very general direction regarding technology and operational design. Protection system misoperations provide an example of hundreds of very technical engineering judgment decisions being made at a level that does not interfere with determination of system performance in relation to the RTO/ISO defined reliability standards and metrics, while at the same time having to preserve sufficient local operational flexibility and innovation. Reliability oversight focuses on the outcomes that are visible to management and their consequences on system reliability. Rather than scrutinize the technical design and configuration of protection systems, management can focus on the fact that there are a number of acceptable technical ways to design and configure protection to achieve reliable performance given the specific circumstances of a piece of equipment or system, including its design, condition, operating history, etc. Therefore, reliability oversight is primarily concerned with whether the performance of protection systems is appropriate for reliability objectives. The omission of any prescription is deliberate and necessary. Including design prescriptions in documents for systems and connections would be relatively easily rendered obsolete because of technological advances and changes in system conditions. any attempted prescription of protection measures could be felt to be inflexible for entities, which might choose to develop, in relation to particular circumstances, innovative or more efficient means of mitigation or protection that would not be described in the documentation. The outcome-oriented, technology-neutral approach to reliability ensured that system design diversity could be taken into account without prescribing specific countermeasures to mitigate risks of misoperation. This interpretation of non-prescriptive oversight in the context of misoperations implies that the non prescriptive oversight policy relates to reliability analysis only after the fact of the discovery of the sequence of misoperations, in order to identify patterns and trends that may be related to high risk and possibly require remedies. The fact that potential emerging risks are identified in misoperation data does not necessarily mean that the reliability organization would require protective action such as design modifications, procedural
changes, or technical specifications in the form of relays or redundancy prior to learning from other entities’ experiences. Instead they may respond to such disclosures by increased scrutiny and studies, information exchange among reliability organizations, and discussion among members of forums and
regulatory commissions, giving ample opportunity for learning and education to occur before a mandate to take technical or operational corrective measures is imposed by anyone responsible for protection engineering and operations. Reliability oversight without prescriptive features can also serve an objectivity function. By refraining from assessing the merits of particular accident prevention designs, the reliability function will avoid the hindsight bias and outcome-based nature of conventional risk reduction judgments. Objectivity of the reliability oversight function is important to maintain public and industry confidence in the factfinding and reporting of misoperations. The separation between observation and instruction is highlighted in the Technical Reports, Lessons Learned and Information Products. These products describe the observed performance outcomes, the context under which these were observed and any reliability implications, but do not offer any guidance on how to carry out maintenance instructions. These products are for educational and analytical purposes only, and serve to demonstrate the purpose of a reliability centered maintenance framework. As systems grow in complexity, non-prescriptive elements of oversight become increasingly important. The issues associated with new technology, changing system dynamics and operational models cannot always be fully understood and covered by specification in advance. Through outcome-based approaches, reliability frameworks can become more dynamic and adaptive, learning from real system performance in real time, in place of being overly restrictive and attempting to account for every eventuality through prescriptive detailing. In Chapter 2, Reliability Oversight addresses the occurrence of protection system misoperations without mandating particular technical or operational measures to prevent such occurrences. Instead, the reliability framework addresses the outcomes, trends and implications in the BES resulting from such occurrences, providing a risk-based and objective approach that is dynamic and adaptive to changing conditions.
End-of-Chapter Summary
The reliability element for protection system misoperations will be performance based as not being prescriptive in nature. While protecting specific design choices or operating practices may be valid, it is less important than ensuring performance does not result in positive reliability risk to the overall power system. This approach ensures that innovation and future developments in this area are not unnecessarily constrained by last event hindsight.
Based on the principle of observation, analysis and information exchange, a misoperation in this context can be used to improve understanding of system operation and performance of protection operations, without prescriptive direction for any corrective measures to be taken. As demonstrated in this chapter, non-prescriptive monitoring is designed to foster an objective, adaptive and reliable approach to governance of grid reliability.
Chapter 12
Synthesis and Reliability Perspective on Protection System Misoperations
Provisions for Protection System Misoperations will address a critical element of Bulk Electric System reliability. Misoperations of protection systems will not be viewed solely as an engineering issue, nor as an inevitable occurrence. Rather, reliability analyses in the BES will treat misoperations of protection systems as a set of observable consequences resulting from the functioning of protection systems in a complex, dynamic and risk-prone environment. This document integrates some of the main concepts derived in this report into a reliability framework. Misoperations matter at their core because protection systems are engaged to perform automatic, high-consequence actions to protect the system for a wide range of abnormal conditions. These fast, automated actions are necessary to maintain reliability, but when a misoperation occurs, the consequences can be both rapid and profound. Reliability monitoring views misoperations as a rich source of information about the performance and reliability of protection systems. Reliability Metrics Current practices in the reliability metrics are mostly technology neutral and measure misoperations through the outcome-based methodology. What, when, and where a misoperation occurred are described, along with a description of its impact, or potential impact, to the power system reliability. A technology neutral approach allows for variation in system technologies and designs without any implication on its validity. The method of describing misoperations does not imply any judgments or interference with regard to specific designs or operating practices, which are the sole prerogatives of experts in the field. Technology neutrality provides uniform basis for combination and comparison of the reliability data across different regions, utilities and times. Context is becoming a common criterion for evaluating the importance of misoperations. Several parameters such as system conditions, configuration, operating mode, and sequence of disturbances have been cited to set the context of misoperations. RSO does not necessarily assign the same importance to various events and accordingly evaluates the impact of each in the context in which it occurred. A contextual evaluation appears to yield more reasonable consequences by achieving a balance between not overstating an isolated incident and at the same time noting potential trends in the grid that could indicate some developing vulnerability. Because of the interconnections in the Bulk Electric System, the understanding of this risk is heightened. A misoperation at one facility can impact reliability at facilities owned by many
other companies. Therefore, misoperations represent a risk to the entire industry, and require industrywide awareness, uniform incident reporting, and a vehicle for industry learning. Reliability oversight is the key to helping utilities achieve this shared understanding of the risks of misoperation. In the reliability framework there is a conscious separation of learning from prescription. Misoperations are used for understanding within the framework rather than for prescribing action. This allows for the flexibility and openness that promotes transparency and effective adaptive governance in a dynamic system. As technologies, resources and operating practices change over time, a more learning-oriented approach enables the framework to remain applicable and focused on the intended objective without needing to include overly specific or static operational requirements. When analyzed together, protection system misoperations highlight the relationships between design assumptions, operating practices, and system developments and, therefore, provide insight into system performance as observed by reliability organizations. They demonstrate system response to disturbances and are an indicator of developing conditions that can impact reliability. Misoperations should not be seen as means of determining fault, but rather as a learning tool for understanding risk. This chapter summarises the role of protection system misoperations in the reliability context, highlighting the role of misoperations as reliability indicators, that capture dynamic system performances and reliability impacts. Misoperations, therefore, remain a critical reliability monitoring tool that enhances proactive risk assessment and dynamic operational awareness of protection system reliability.
End-of-Chapter Summary
Protection system misoperations are classed as outcome-based metrics to reflect their role as an indicator of system reliability, robustness and future risk. Misoperations offer valuable insight into how protection systems behave under the increasingly dynamic operating environment associated with grid modernization, including the challenges associated with increased interconnection.
Through examination of context, aggregation and adaptive learning without prescription, reliability oversight demonstrates how misoperations can be used as a tool to support an objective and adaptive governance framework for the Bulk Electric System (BES). This final chapter ties together all of the ideas presented in the report to provide a reliability perspective on protection system misoperations.
Glossary
Glossary
The terms listed below are taken directly from the NERC Glossary of Terms and are specific to this publication.
Bulk Electric System (BES) - Except where modified by the listings in the tables above, all Transmission Elements that were operated at voltages of 100 kV or above and all Real Power and Reactive Power resources that were connected at voltages of 100 kV or above. Excludes facilities that are used for the local distribution of electric energy.
- Substation electrical, including protective relays, protective relay communications, voltage and
current transformers, batteries and dc control circuitry.
Misoperation Relates to a failure of an element of a Protection System not to perform its specified function (e.g. failure to trip, slow trip, or premature trip).
Reliability Coordinator (RC) – The entity with the overall responsibility for the reliability of the Bulk Electric System. The entity with a wide-area view of the Bulk Electric System. The entity that has the operational tools, processes and procedures necessary to prevent or mitigate potential emergency operating conditions that are identified through next-day analysis and real-time operations.
Operator TOP – Transmission Operator The entity responsible for the reliability of its “local” transmission system, and that operates or directs the operations of the transmission facilities.
This glossary contains selected terms and definitions from the NERC Glossary of Terms. It is provided for informational purposes only and should not be considered to supersede or replace the official NERC
Glossary of Terms.
Glossary of Terms.
About the Author
About the Author
Rob Smith is a senior electric industry professional with over thirty years of experience across every major function of the North American Bulk Electric System. His work spans reliability coordination, transmission operations, regulatory compliance, and cybersecurity reliability.
Rob has worked directly in real-time grid operations as a Reliability Coordinator, Transmission Operator, and Power System Operator within RTO/ISO and utility control center environments. He has also held senior regulatory and oversight roles, including senior compliance auditor and subject matter expert for NERC Reliability Standards. In those roles he audited grid facilities for compliance with applicable standards, evaluated the adequacy of mitigation actions, supported the development of violation notifications and settlements as part of FERC-directed enforcement actions, and participated in risk based oversight of utility mitigation activities.
Rob founded Energy Compliance, Inc. to bring senior, regulator-side compliance authority to registered entities directly, without the layered staffing, billable-hour overhead, and generalist advice typical of larger consulting firms. Every Energy Compliance engagement is led by Rob personally.
About Energy Compliance, Inc.
About Energy Compliance, Inc.
Energy Compliance, Inc. is an independent consulting and advisory firm focused exclusively on electric reliability, cybersecurity reliability, and regulatory compliance for organizations connected to the North American Bulk Electric System.
Our work supports registered entities, including Generator Owners and Operators, Transmission Owners and Operators, Reliability Coordinators, Balancing Authorities, and Distribution Providers. We work across NERC Reliability Standards, FERC orders, RTO/ISO market participation rules, Regional Entity oversight, and state regulatory frameworks.
We do this work differently than larger consulting firms. Engagements are led by a single senior practitioner with regulator-side experience. We don’t staff for billable hours. We staff for outcomes. Our deliverables are written to be operationally executable and audit-defensible, not to manufacture activity. Where automation can replace manual work, we build the automation. Where senior judgment is required, the senior is in the room.
Energy Compliance is not affiliated with, sponsored by, or endorsed by the North American Electric Reliability Corporation, the Federal Energy Regulatory Commission, or any Regional Entity.
Services Provided
Our services are written to be clearly defensible. Operationally executable in real time. Audit-defensible at compliance review. Every deliverable is structured for the auditor’s question, not the consultant’s binder.
Energy Compliance services include, but are not limited to:
- NERC reliability and compliance advisory support
- Reliability governance and program assessments
- Registration and applicability analysis
- Operational and engineering reliability alignment
- Compliance program design and improvement
- Audit and enforcement support (non-advocacy)
- Mitigation planning and Self-Report development
- Training and executive briefings on reliability frameworks
- Regulator-perspective program reviews
Each engagement is scoped to the entity’s role, function, and bulk system impact.
ENERGY COMPLIANCE PROFESSIONAL REFERENCE
Rigorous Compliance. Defensible Programs. Energy Compliance, Inc. partners with registered entities on the institutional and technical questions that define strong reliability and cybersecurity programs, from classification through audit through enforcement response.
N ERC CO MP LIANC E S ENIO R ADV ISO RY Program support, interpretation, and audit Direct engagement on complex reliability preparation. questions.
I ND USTRY ENGAGEMENT AUD IT D EFENSE Standards development and working-group Notice of Penalty response and settlement participation. posture.
CONNECT WITH US Scan to visit
E N E RGY COMPL IAN CE , IN C. · EC-WP-306 · © 2026 · AL L RIGHTS RES E RV E D