Protection · ROCOF / Loss of Mains

ROCOF & Loss-of-Mains Protection in a Low-Inertia Grid: The Nuisance-Trip vs Missed-Islanding Trade-off

As grids lose inertia, frequency protection is squeezed between two failure modes: nuisance-trip your generation, or miss a genuine island. How the elements work, why GB moved to 1.0 Hz/s, and where the line sits.

Frequency protection used to have plenty of margin. On a low-inertia grid, it doesn't. As synchronous generation is displaced by inverter-based wind, solar and storage, the system's inertia falls — and frequency moves faster after any disturbance. That squeezes ROCOF and loss-of-mains protection between two failure modes, and understanding the squeeze is now core protection work.

Inertia sets the nadir

After a sudden generation loss, the frequency falls at a rate set, to first order, by the power imbalance and the system inertia:

RoCoF ≈ ΔP · f₀ / (2H)
      

Less inertia → a steeper initial rate of change of frequency → a deeper, faster nadir → less time for governors, fast-frequency response or under-frequency load shedding to arrest it. Everything downstream — your settings, your shedding scheme, your margin — is governed by that curve.

The scale of the effect is easy to see in a live model. In the Frequency Protection Suite's default islanding study (a mixed synchronous-and-inverter grid, 32% severity), dropping the inertia class from low to very low deepens the nadir from 48.83 Hz to 48.24 Hz and steepens the measured peak df/dt from 0.88 to 1.32 Hz/s — enough to carry the frequency into the load-shedding region. Raising it to high, the same event barely dents the trace: 49.47 Hz at 0.40 Hz/s. Same disturbance; the only change is stored rotating energy.

The protection elements

A frequency-protection scheme typically combines:

The measurement chain matters as much as the pickups: df/dt measured over too short an averaging window is noise; over too long, the element is slow. Typical practice uses a window of a few hundred milliseconds with smoothing on top.

Failure mode 1 — too sensitive (nuisance tripping)

Set ROCOF too sensitively and a normal grid disturbance looks like a fault. On a low-inertia system the real df/dt during ordinary events is higher than it used to be, so an old-style sensitive setting picks up — and multiplied across thousands of distributed generators, a small grid event becomes a large, self-reinforcing loss of generation. This is exactly why Great Britain raised the RoCoF setting from 0.125 Hz/s to 1.0 Hz/s (with a time delay), through the Accelerated Loss of Mains Change Programme: the sensitive setting had become a system risk.

Worked live: set the pickup to 0.18 Hz/s and apply a benign weak-grid event — the kind that should ride through — and the element trips in 1.425 s, flagged by the model as a possible nuisance trip.

Failure mode 2 — too insensitive (missed islanding)

Push the settings the other way and you create the opposite problem. Loss-of-mains protection exists to detect islanding — a safety and power-quality requirement. A very insensitive ROCOF and low underfrequency stages can leave a genuine island with a small power imbalance undetected.

Worked live: at a pickup of 8 Hz/s with the underfrequency stage dragged down to 45 Hz, a genuine islanding event sails through 7.12 Hz/s below pickup — neither element asserts, and the model flags a possible failure to detect islanding. That's the security-versus-dependability tension: every loss-of-mains setting is a deliberate position between these two failures.

The source mix matters too

"Low inertia" isn't a single derating factor — the type of source changes the shape of the response:

Reasoning about a real scheme means modelling these separately, not lumping them into one number.

See the trade-off

The Frequency Protection Suite simulates generation-loss, islanding and weak-grid events across inertia classes and source models, then evaluates the ROCOF, UF, OF, UFLS and loss-of-mains elements — flagging both the nuisance-trip and the missed-islanding cases on the same model, with the frequency trace, the df/dt slope and each element's decision. It also reads the same scenario across four relay vocabularies — ABB Relion, MiCOM, Siemens 81R and SEL 81D — in each manual's own terms.

The dynamics are an illustrative scenario model (showing how the frequency response moves with inertia and source mix), paired with rigorous protection-element logic. It is not a calibrated EMT/RMS dynamic simulation and not a grid-code compliance verdict; the engineering judgement remains the engineer's. RoCoF and loss-of-mains practice follows the applicable grid code (e.g. UK G99).

Frequently asked questions

What is ROCOF protection?

ROCOF (rate of change of frequency, df/dt) protection trips when frequency moves faster than a set rate for longer than a set delay. It is the classic loss-of-mains element for embedded generation: a genuine island usually has a power imbalance, so its frequency runs away faster than the interconnected grid's ever would.

Why did Great Britain change the RoCoF setting from 0.125 to 1.0 Hz/s?

On a lower-inertia system, ordinary grid disturbances produce a higher df/dt than they used to, and the legacy 0.125 Hz/s setting was tripping distributed generation during normal events — turning small disturbances into large generation losses. The Accelerated Loss of Mains Change Programme moved the setting to 1.0 Hz/s with a time delay to make the element secure while keeping islanding detection.

What is under-frequency load shedding (UFLS)?

Staged, automatic disconnection of load blocks as frequency falls (a common reference around 48.8 Hz on a 50 Hz system), designed to arrest a decline before it reaches the underfrequency trip stages and cascades. Lower inertia gives UFLS less time to act, which is why the inertia debate and the load-shedding debate are the same conversation.

Why does low inertia make frequency protection harder?

Because RoCoF ≈ ΔP·f₀/(2H): halve the inertia and the same power imbalance moves the frequency twice as fast, deepening the nadir and shrinking every response window. The gap between a setting that nuisance-trips and one that misses an island narrows with it.

What is the difference between grid-following and grid-forming inverters here?

Grid-following inverters synchronise to the grid's waveform and largely ride a frequency excursion — and under a voltage fault they hit their current limit and saturate. Grid-forming inverters (and battery fast-frequency response) actively construct the waveform and arrest the fall, lifting the frequency nadir. The same event can trip on one source mix and stay restrained on the other.

Related on EI Portal