Automatic Transfer, Load Shedding and Restoration Logic in MV Switchgear

A coordinated MV automation guide for transfer philosophy, staged load shedding/restoration, breaker feedback, protection and degraded modes.

Automatic transfer, load shedding and restoration must be engineered as one coordinated state machine. Transfer preserves supply, shedding preserves source stability/capacity, and restoration returns load without retriggering the disturbance. Unsafe schemes arise when each function has separate timers, stale topology, competing command authority or no defined abort/recovery state.

This guide designs MV bus/incomer/coupler automation with protection independence, source-quality validation, synchrocheck, priority, communications failure behavior and end-to-end testing.

1. Define objectives and prohibited outcomes

  • Maintain critical loads after loss of one source where capacity/topology permit.
  • Prevent paralleling sources not rated/authorized for parallel operation.
  • Prevent closing onto a faulted bus/feeder or active lockout.
  • Keep source/transformer/generator loading within emergency/continuous limits.
  • Shed low-priority load before frequency/voltage collapse or source overload.
  • Restore gradually only after stable conditions and adequate reserve.
  • Never block protection trips or breaker-failure action.

2. Inputs and their quality

Input groupRequired information
SourceVoltage/frequency/live-dead, phase sequence, transformer/generator availability and capacity
TopologyIncomer/coupler/feeder double-point position, truck/disconnector/earthing state
ProtectionTrip cause, lockout, bus/arc/transformer fault, breaker failure and reclose state
EquipmentBreaker mechanism/DC readiness, trip/close circuit, maintenance/local mode
LoadingSource/bus/feeder P, I, demand, reserve and priority
SystemAuto enable, authority, time/communication quality and sequence state

Every required input needs a freshness/quality rule. “Last good voltage” after VT/IED link loss must not authorize transfer.

3. Transfer philosophies

ModeSequenceMain constraint
Open transitionOpen failed source, verify open/dead as required, close alternateSupply interruption and residual bus voltage
Fast transferRapid source change within phase/frequency criteriaMotor residual voltage, timing and source relationship
In-phase transferPredict/close within acceptable phase windowAccurate voltage/frequency/phase measurement
Closed transitionBriefly parallel then open original sourceParalleling rating, protection and utility authorization
Manual supervisedOperator sequence with automatic checksHuman timing/authority and clear feedback

4. Cause qualification

  • Distinguish source undervoltage from VT fuse/MCB failure, dead-bus measurement loss and downstream fault depression.
  • Use appropriate voltage threshold, delay and phase criteria to ride through acceptable disturbances without delaying real loss.
  • Block transfer for busbar/arc/transformer fault, breaker failure or lockout that makes alternate energization unsafe.
  • Coordinate with upstream reclosing and generator/transformer protection.
  • Record the initiating cause and conditions that qualified it.
  • Do not initiate from a single unvalidated SCADA analog.

5. State-machine design

  1. IDLE/armed with all prerequisites supervised.
  2. DETECT/QUALIFY source loss or overload.
  3. BLOCK CHECK for protection, maintenance, topology and authority.
  4. OPEN/SHED required breakers with bounded confirmation timeout.
  5. VERIFY open/dead/synchronism and alternate source capacity.
  6. CLOSE alternate/coupler with one authorized attempt.
  7. CONFIRM final topology, voltage and load.
  8. RESTORE staged loads under stability/reserve checks.
  9. COMPLETE with latched event record or ABORT/LOCKOUT with operator action.

Every state needs entry, action, exit, timeout, restart and manual-takeover behavior. A controller reboot must not resume from an ambiguous output state.

6. Load-shedding design

  • Create consequence-based priority groups: essential, process critical, restart-sensitive and interruptible.
  • Initiate from frequency/ROCOF, voltage, source overload, transformer limit or transfer-state logic as justified.
  • Calculate required MW/Mvar/current relief including motor behavior and contingency margin.
  • Use stages and minimum separation to observe response; avoid simultaneous unnecessary over-shedding.
  • Verify breaker availability/current state before counting expected relief.
  • Alarm a failed shed command and escalate/issue the next action by defined logic.
  • Maintain fairness/rotation only if it cannot compromise priority.

7. Restoration logic

  • Require stable voltage/frequency/source reserve for a defined dwell time.
  • Restore highest-priority load first, subject to inrush/motor-start and transformer limits.
  • Use one stage at a time and verify measured response before continuing.
  • Abort/pause on instability, overload, bad measurement or failed breaker feedback.
  • Limit automatic retries and prevent oscillation between shed/restore.
  • Consider process restart sequence and cold-load pickup, not only steady-state kW.
  • Provide operator approval where consequences/uncertainty justify it.

8. Protection and control coordination

  • Protection trips take priority over automation close requests.
  • Coordinate transfer dead time with motor protection, undervoltage release and process ride-through.
  • Review short-circuit level and protection settings for alternate/coupled topology.
  • Breaker failure and bus/arc protection must lock out unsafe transfer paths.
  • Synchrocheck/dead-bus logic remains at the final close gate.
  • Local/maintenance authority and earthing/truck interlocks block automatic closing.
  • Reclose and transfer logic must not issue conflicting commands.

9. Centralized versus distributed implementation

  • Bay IEDs provide local final interlock/output and fast protection-independent state.
  • Station controller may own multi-bay sequence/topology/load calculation.
  • GOOSE can transfer fast supervised peer signals; define timeout/fail-safe behavior.
  • SCADA provides enable, initiation/abort, monitoring and audit, not the only final close interlock.
  • Central logic needs redundant power/compute/network or a safe manual degraded mode.
  • One approved state-machine owner prevents duplicate station/SCADA automation.

10. Failure and cyber behavior

  • On lost/stale required input, block new automatic close and hold/abort safely.
  • On output uncertainty, reconcile breaker position before retry.
  • Prevent split-brain redundant controllers and duplicate commands.
  • Role-protect auto enable, thresholds, priorities, bypass and manual force.
  • Audit every mode/setting change, cause, state transition and command result.
  • Segment/allowlist automation flows and protect SCL/logic/settings.
  • Restore from a signed/tested release; never use unverified standby configuration.

11. Study inputs before implementation

  • Load-flow for normal, contingency, transfer and restoration stages.
  • Short-circuit/protection study for alternate topology.
  • Motor residual-voltage/inrush and transformer cold-load pickup where relevant.
  • Source/utility paralleling and synchronism constraints.
  • Breaker operating/clearing times and mechanism/control voltage limits.
  • Communications/timing and common-mode failure analysis.
  • Operating philosophy and manual fallback switching procedure.

12. FAT/SAT dynamic tests

  1. Freeze state diagrams, settings, SCD/logic, load priorities and test model.
  2. Simulate each valid initiation and every block cause.
  3. Vary voltage/frequency/load around thresholds/delays/hysteresis.
  4. Fail breaker to open/close, use intermediate/invalid feedback and late operation.
  5. Lose VT/IED/GOOSE/controller/LAN/time and restart/fail over the controller in every state.
  6. Test competing manual/remote/reclose/protection commands.
  7. Apply load model to prove shedding magnitude and staged restoration stability.
  8. Verify no duplicate close, unsafe parallel or automatic retry after ambiguity.
  9. At SAT, use staged secondary injection and approved breaker operations.
  10. Archive SOE, waveform/network evidence, timings and as-built logic/settings.

13. Commissioning and operational governance

  • Commission first in monitor/advisory mode and compare proposed actions with operator decisions.
  • Enable closed-loop stages only after topology, measurement and remote-control quality is demonstrated.
  • Train operators on every armed, blocked, running, abort and manual-recovery state.
  • Review every automatic operation or near-miss against the study/model and SOE.
  • Revalidate after source, transformer, feeder, protection setting, load priority, breaker-time or firmware/network change.
  • Periodically test failover, block inputs and a representative end-to-end sequence without creating unacceptable system risk.

References and further reading

Engineering note: Never count a load as shed or a source as transferred until independent breaker feedback and stable electrical measurements confirm the physical result.

LearnSwitchgear

Search the engineering library