IBR Protection Event Evidence Checklist: What Engineers Need Before Reviewing a Trip
A practical checklist for reviewing inverter-based resource trips: preserve the original records, validate time and channels, separate protection from control response, and document evidence gaps before drawing a conclusion.

On this page
An inverter-based resource (IBR) trip is a system event, not a single relay screenshot. The protection engineer may need to explain what the relay saw, what the inverter controls did, whether the breaker opened as intended, and whether the event exposes a model or settings problem. The first engineering decision is therefore not “what tripped?” but “do we have enough trustworthy evidence to ask that question?”
Start with an evidence-preservation hold
Create a case ID, preserve the original files read-only, and record who collected them, from which system, at what time, and with what export settings. Do not rename a COMTRADE file in a way that loses the source identity. Keep the associated configuration, data, header, and information files—or the single-file format where used—together. IEC 60255-24 defines COMTRADE as an exchange format for transient waveform and event data; it does not make a poorly mapped channel or an incorrect time base trustworthy.
The NERC PRC-028-1 purpose is to make adequate IBR data available for evaluating ride-through performance during system disturbances and for model validation. Treat that as an evidence contract, not as permission to infer a cause from a single record. If the facility is within a different regulatory scope, the same preservation discipline remains useful, but the applicable obligation must be confirmed by the responsible compliance and engineering teams.
The minimum packet
Before interpretation, collect the following:
- Waveforms and event files: relay and disturbance-recorder COMTRADE records, channel configuration, sample rate, filtering, trigger and pre-fault window, sequence-of-events record, and any recorder quality flags.
- Time and identity: time source, UTC offset or local-time code, clock-health alarms, GPS/PTP/NTP status where relevant, device names, firmware, serials, and the mapping from channel name to physical quantity.
- Protection context: as-found settings, active setting group, approved as-specified settings, logic equations, CT/VT ratios, protection mode, communications-assisted signals, breaker status, trip/close outputs, and reclose state.
- IBR and plant context: inverter unit or collector-feeder identity, plant-controller mode, voltage and frequency ride-through state, momentary cessation or blocking state, fault codes, alarms, control references and feedback signals, and the point-of-interconnection measurements.
- System context: topology, switching state, pre-event loading, system voltage and frequency, fault location or credible contingency, weather or lightning information where relevant, and the study or model version used for comparison.
The checklist should show “not available” separately from “not applicable.” That distinction is important: a missing inverter fault code is an evidence gap; an element that genuinely does not exist is a scope decision.
Validate before correlating
Align records to a common time basis before comparing them. Check sample counts, channel scaling, polarity, phase rotation, nominal frequency, CT and VT ratios, saturation, clipping, missing samples, and the timestamp of the first valid sample. A waveform can look plausible while being shifted by a cycle or mapped to the wrong phase. For synchrophasor channels, CIGRE TB 843 emphasizes the lifecycle implications of time synchronization, multi-vendor interoperability, commissioning, periodic testing, and troubleshooting.
Next, reconstruct the sequence without a causal label: disturbance begins; protection element asserts; communications signal changes; inverter mode changes; trip output operates; breaker changes state; current collapses or persists; reclose or lockout follows; plant response recovers or remains blocked. Mark each statement as observed, calculated, expected, or inferred. Never let an AI-generated narrative blur those categories.
Separate protection response from control response
An IBR can reduce current, change its control mode, ride through, block, or cease energization without the same mechanism that opened a breaker. The review should therefore compare the relay target and trip logic with inverter alarms, ride-through states, plant-controller references, and breaker evidence. The correct question is not “did the inverter trip?” but “which device or control function changed state, when, under which setting or mode, and was that response expected?”
The NERC PRC-004-6 misoperation process and PRC-027-1 coordination context make the disposition consequential. Record the observed behaviour, the intended behaviour, the evidence supporting the comparison, and the corrective-action owner. If evidence is insufficient, the disposition can be “undetermined—additional record or test required.” That is a valid engineering result.
Where bounded AI helps
ProtectionAI can organize the relay and protection portion of this packet: retrieve the relevant settings version, read event evidence, build a test or reproduction plan, compare measured values with deterministic expectations, and draft a report for review. AI can also extract device names, find missing metadata, group similar events, and propose questions. The COMTRADE event-analysis workflow shows the useful middle ground.
The guardrails are firm. AI must not edit the original record, decide that a trip was correct, write settings, authorize a retest, issue a control command, or hide uncertainty. The engineer checks the raw files, the calculations, the study case, and the physical system. The IEEE PSRC AI/ML report and NIST AI RMF both support treating validation, transparency, and deployment acceptance as explicit work rather than as a side effect of model accuracy.
If the event also raises a transformer condition question, an engineer can pass an approved event reference or export into a separate AgenticGrid Pro assessment. That product handles transformer diagnostic evidence and maintenance work packages; it does not turn the IBR event into a protection command or bypass the protection review.
A review-ready disposition
Close the case with five statements: what happened; what the protection scheme was expected to do; which records prove or contradict that expectation; what remains unknown; and what the engineer approved next. Preserve the settings and firmware versions, the reviewer identity, comments, test evidence, and any corrective-action or model-validation reference. The result should be reproducible by another engineer months later, even if the AI assistant is no longer available.
References
- North American Electric Reliability Corporation. (2024). PRC-028-1: Disturbance monitoring and reporting requirements for inverter-based resources. https://www.nerc.com/standards/reliability-standards/prc/prc-028-1
- North American Electric Reliability Corporation. (2020). PRC-004-6: Protection system misoperation identification and correction. https://www.nerc.com/standards/reliability-standards/prc/prc-004-6
- North American Electric Reliability Corporation. (n.d.). PRC-027-1: Coordination of protection systems for performance during faults. https://www.nerc.com/standards/reliability-standards/prc/prc-027-1
- International Electrotechnical Commission. (2013). IEC 60255-24: Measuring relays and protection equipment—Part 24: Common format for transient data exchange (COMTRADE) for power systems. https://webstore.iec.ch/en/publication/1170
- CIGRE. (2021). Life cycle testing of synchrophasor based systems used for protection, monitoring and control (Technical Brochure 843). https://www.e-cigre.org/publications/detail/843-life-cycle-testing-of-synchrophasor-based-systems-used-for-protection-monitoring-and-control.html
- IEEE Power & Energy Society, Power System Relaying and Control Committee. (2023). Practical applications of artificial intelligence / machine learning in power system protection and control (PSRC Working Group C43 report). https://www.pes-psrc.org/kb/report/117.pdf
- Tabassi, E. (2023). Artificial intelligence risk management framework (AI RMF 1.0) (NIST AI 100-1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.100-1
- North American Electric Reliability Corporation. (2025). 2025 State of Reliability: Technical Assessment. https://www.nerc.com/globalassets/programs/rapa/pa/nerc_sor_2025_technical_assessment.pdf
References
- NERC PRC-028 NERC PRC-028-1 — Disturbance Monitoring and Reporting Requirements for Inverter-Based Resources
- NERC PRC-004 NERC PRC-004-6 — Protection System Misoperation Identification and Correction
- NERC PRC-027 NERC PRC-027-1 — Coordination of Protection Systems for Performance During Faults
- IEC 60255-24 IEC 60255-24:2013 — Common Format for Transient Data Exchange (COMTRADE)
- IEEE PES PSRC C43 — Practical Applications of Artificial Intelligence / Machine Learning in Power System Protection and Control
- CIGRE Technical Brochure 843 — Life Cycle Testing of Synchrophasor Based Systems
- NERC — 2025 State of Reliability Technical Assessment
- NIST AI RMF NIST AI Risk Management Framework 1.0
Questions engineers ask
What is the minimum evidence needed before reviewing an IBR trip?
Preserve the original disturbance records and metadata, sequence-of-events data, breaker states, relay settings and active group, inverter alarms and ride-through states, plant-controller context, time synchronization information, and the communications or telemetry evidence needed to align the sequence.
Can a relay target prove that an IBR protection scheme misoperated?
No. A target is one observation. The review must compare the target with waveforms, settings, timing, breaker response, inverter controls, network conditions, and the intended protection sequence, while recording any missing or unreliable evidence.
Can AI determine whether an IBR trip was caused by protection or controls?
AI can classify, correlate, and draft hypotheses, but it cannot resolve an ambiguous event without adequate evidence. A qualified engineer must test the hypotheses against the records, models, settings, and applicable procedures.


