Wide-Area EMT Studies · Acceptance & Validation

Acceptance Testing and Validation of EMT Models

The wide-area EMT mini-series opened by asking whether a model is adequate. This guide — the second of three — asks the next question: has the model been accepted and validated strongly enough to trust? A model earns trust; it is not granted it. It covers the single-plant SMIB acceptance tests, the weak-grid checks, and the wide-area validation against coherency and long-run checks, staged field tests, real disturbances, playback validation and hardware in the loop — with real system-operator examples. It follows CIGRE Technical Brochure 881, with APS engineering interpretation, for EMTP® and other EMT tools.

Reading time ≈ 26 min · Acceptance, SMIB, weak-grid, field validation & hardware-in-the-loop

A model earns trust; it is not granted it. The previous guide explained model adequacy — whether an EMT model carries the right vendor-specific, site-specific, network, protection, aggregation and distributed-energy-resource (DER) detail for the study. This page moves from adequacy to trust. Even an adequate-looking model still has to be accepted and validated before it is used for connection studies, compliance decisions, incident investigations or wide-area operating studies. Trust is built in layers: documentation, initialisation, flat-run stability, disturbance response, weak-grid behaviour, comparison with measurements, and long-term software usability.

Where this sits — the wide-area EMT mini-series

This is the second of three guides that follow the nine-part IBG modelling series. The first asked whether a model is adequate. This guide asks whether it has been accepted and validated strongly enough to trust: SMIB tests, weak-grid checks, coherency and long-run checks, field validation, disturbance playback and hardware-in-the-loop. The third asks how the large-scale case is built and run: load-flow initialisation, boundary selection, network equivalencing, hybrid PDT–EMT, co-simulation and real-time simulation.

By the end of this page, the reader should understand
  • the difference between model acceptance and model validation, and why a model that runs is not necessarily trustworthy;
  • what SMIB testing is, why it is used before commissioning, and which fault, voltage, frequency and reference-step tests to apply;
  • why extremely weak networks require special acceptance logic;
  • why wide-area EMT models need coherency and long-run stability checks;
  • how staged field tests and real disturbance records validate EMT models, and what playback validation means;
  • what hardware- and software-in-the-loop add, and why control replicas are the highest-fidelity validation.
Acceptance and validation are not the same thing

Acceptance testing checks whether the submitted model is robust, documented, correctly parameterised, numerically stable and suitable for use — before it is relied on. It answers: “is the model suitable to use?” Validation checks whether the model reproduces real measured behaviour from the plant or network. It answers: “does the model reproduce the real plant or system?” Acceptance can happen before the plant is commissioned; validation normally needs measured data from factory tests, field tests, staged tests or real disturbances.

Both are required. A model can pass acceptance tests but still fail validation if its response does not match the real plant; a model can match one disturbance but still be unacceptable if it is unstable, poorly documented, impossible to initialise, or outside its valid operating range. Acceptance without validation gives a neat but unproven model; validation without acceptance gives a model that matches one event but is unreliable outside it.

A trust ladder
  • Lowest confidence — the model runs without errors.
  • Better — it passes flat-run and SMIB tests.
  • Better — it matches the expected vendor / grid-code response.
  • Better — it matches staged field tests.
  • Better — it matches real disturbance records.
  • Highest — hardware-in-the-loop or a control replica confirms the actual control behaviour.
A note on IBG and IBR

The APS series uses IBG (inverter-based generation). CIGRE’s brochures use IBR (inverter-based resource). On this page, IBR appears where the source material uses it; it is closely aligned with IBG, but slightly broader, because it also includes storage and other converter-interfaced resources. Read the two as the same idea for the purposes of acceptance and validation.

Abbreviations used on this page
EMTElectromagnetic transient (time-domain) simulation
PDTPhasor-domain transient (the RMS / phasor method)
RMSRoot-mean-square (phasor) simulation
EMTP®Electromagnetic Transients Program (an EMT tool)
SMIBSingle machine – infinite bus (test environment)
IBG / IBRInverter-based generation / resource
OEMOriginal equipment manufacturer (the vendor)
SCRShort-circuit ratio (system strength)
X/RReactance-to-resistance ratio of the source
PoC / PCCPoint of connection / common coupling
LVRT / HVRTLow- / high-voltage ride-through
FRTFault ride-through
TOVTemporary over-voltage
PLLPhase-locked loop
ROCOFRate of change of frequency
SSOSub-synchronous oscillation
SSCISub-synchronous control interaction
DFIGDoubly-fed induction generator (Type-3 wind)
WPPWind power plant (park)
HVDCHigh-voltage direct current
HIL / SILHardware- / software-in-the-loop
RTS / DRTS(Digital) real-time simulator
SCADASupervisory control and data acquisition
Key idea
  1. Acceptance proves the model is usable — robust, initialising, documented, numerically stable across output and system-strength levels — and it is done per plant in a controlled single-machine (SMIB) environment before the model enters a wide-area case.
  2. At an extremely weak grid, a “good” result can be a bad sign: a model that stays perfectly stable where the real plant sits near its stability boundary has probably omitted the interaction, PLL limit, protection mode or site tuning that would appear in reality.
  3. Validation compares the model to measured reality — coherency and long-run checks on the wide-area case, staged field tests, and overlays against real disturbances inside a defined accuracy band. A poor match almost always means data, settings, initialisation, control-mode or measurement problems, not a limit of EMT.
  4. Playback and hardware-in-the-loop / control replicas are the strongest evidence: replay recorded voltages and confirm the recorded currents, or run the actual control in real time — reserved for the critical converter, HVDC and weak-grid studies that most need it.
Test the same three headings the series used

Acceptance and validation should check the same categories the IBG modelling series read every plant through:

  • Control — PLL, current control, plant controller, active / reactive-power control, frequency response, damping functions.
  • Protection — LVRT / HVRT, frequency protection, ROCOF, vector jump, momentary cessation, blocking, tripping and reconnection.
  • Capability — current limit, reactive range, overload capability, active-power headroom, dc-link behaviour, ride-through limits.
Key terms used on this page
01Model acceptance
Checking a submitted model is robust, documented, correctly parameterised, numerically stable and suitable for use.
02Validation
Checking a model reproduces real measured behaviour from the plant or the network.
03SMIB
Single machine – infinite bus: one plant model connected to a simplified grid equivalent for controlled testing.
04Flat run
A no-disturbance run at the intended operating point; the model should stay quiet, with no drift or artificial oscillation.
05System strength (SCR)
Short-circuit power at the connection point divided by plant rating; low SCR means injected current strongly moves local voltage and angle.
06Coherency check
Comparing the wide-area EMT case with a trusted RMS / PDT reference for the same condition, to confirm broad agreement before EMT-specific study.
07Long-run stability check
An extended, low-disturbance run to expose numerical drift, hidden oscillation, control wind-up or slow protection artefacts.
08Staged field test
A deliberate, safe disturbance applied to the real plant or network under known conditions, with high-quality measurements.
09Real-disturbance validation
Comparing model output against an actual system event (fault, trip, switching, oscillation) using measured records.
10Accuracy band
A tolerance for judging an overlay (e.g. ±10% of the maximum deviation) — a guideline, not a universal law.
11Playback validation
Feeding recorded terminal voltages into the model and confirming it reproduces the recorded current and power.
12Sub-synchronous oscillation
A growing oscillation below system frequency, often from converter-control interaction (SSCI) — invisible to a PDT model.
13HIL / SIL
Hardware- / software-in-the-loop: running the real controller hardware, or its actual code, against a real-time simulated grid.
14Control replica
A high-fidelity copy of the real control and protection system, run in the loop — the strongest, but costliest, validation.

Section 1

Two kinds of confidence

Confidence in an EMT model is built at two levels, and the tests differ. Acceptance asks whether a single supplied plant model is usable and trustworthy on its own: robust, quick to initialise, faithful to the installed plant across the operating conditions it will meet — it answers “is the model suitable to use?” Validation asks whether the model — alone or inside a wide-area case — reproduces what really happens: the coherency of a newly built network, its behaviour over long runs, and its overlay against staged tests, real disturbances and hardware in the loop — it answers “does the model reproduce the real plant or system?”

The two feed each other, and both are needed. A plant model that passes acceptance can still be wrong in the field; a wide-area case that matches one disturbance can still hide an error elsewhere. The programmes below — drawn from real system-operator experience — show why both are needed, and why the strongest evidence always comes from comparing the model to measured reality.

Section 2

Pre-commissioning model acceptance

Acceptance testing runs before commissioning, on each plant model individually, in a single-machine–infinite-bus (SMIB) environment. The tests exist to answer a short list of questions:

  • Is the model robust across the defined test conditions, bounded by the upper and lower limits of system strength it must operate within?
  • Is its performance consistent and accurate against the manufacturer’s own validation, and representative of the equivalent system-strength conditions at the point of connection (PoC)?
  • Is the model information fit for purpose — good enough to progress the connection studies and to serve operational, planning and assessment needs, meeting the relevant modelling requirements?
  • Is it properly documented — data, source information, settings and control diagrams provided to the required standard?

Read through the series’ three headings, acceptance is confirming that the Control, Protection and Capability functions the study will exercise are present and behave sensibly — before the model is placed in a network large enough to hide its faults.

Section 3

SMIB: the controlled test bench

SMIB means single machine–infinite bus: a controlled test environment where one plant or converter model is connected to a simplified grid equivalent. The infinite bus represents a strong reference system with fixed voltage and frequency, unless deliberately disturbed. SMIB tests are not meant to reproduce the whole grid; they check whether the plant model responds correctly to standardised disturbances before it is placed in a wide-area EMT case. Testing a model first in SMIB avoids hiding its problems inside a large network: if the model cannot initialise, ride through, trip, recover or follow references correctly in a controlled test system, it should not be trusted inside a wide-area case. Table 1 lists the core tests; the groups below explain what each is really doing, and almost every test is swept across the expected SCR and X/R and at several operating points.

Table 1 — Core pre-commissioning SMIB acceptance tests for an IBG model (after CIGRE TB 881, Section 5.1).
TestWhat it verifiesKey conditions
Flat run (prerequisite)No memory leak; fast, clean initialisation; repeat runs identicalLong, undisturbed; several output and SCR levels
Balanced faultReasonable large-disturbance response; grid-code active / reactive current; SCR withstand limitVarious durations, SCR and X/R
Unbalanced faultResponse to single-line-to-ground, phase-to-phase and phase-to-phase-to-ground faultsVarious durations, SCR and X/R
Sequential faultReasonable ride-through of multiple faults in sequence (where the code requires it)Per grid-code sequence
Temporary over-voltageReasonable response — especially reactive absorption — to a switching over-voltageFull output; max Q inject / absorb; various SCR, X/R
Voltage-reference stepThe voltage (or power-factor) controller works and moves reactive power correctlyStep up and down; full and low P; various SCR, X/R
Active-power referenceActive power follows the setpoint at a reasonable ramp (key if a runback scheme exists)Allow time for ramping
Grid-frequency controllerActive power responds to a realistic rate of change of frequency to oppose itRise (init at full P); fall (init at min P)
Inertia / frequency controlInertia-controller behaviour (stored energy, deadband, droop, recovery)Case-by-case
Grid-voltage changeVoltage controller holds active power in-range; FRT if the change triggers itStep and ramp; full and min P; no tap changer
Oscillatory rejectionStable operation and consistent current-reference response to modulated voltageVoltage modulated 1–10 Hz, 1 Hz per step
Phase-angle changeControl not lost through a phase jump (e.g. 30–40° within a cycle or two)Largest angle the equipment can sustain

The suite falls into four natural groups:

  • Steady-state — the flat run, the initialisation check and the operating-point check.
  • Voltage disturbance — balanced, unbalanced and sequential faults, temporary over-voltage, and voltage-reference and grid-voltage steps.
  • Power / frequency / control — active-power-reference steps, frequency steps or ramps, inertia / synthetic-inertia response, phase-angle jumps and oscillatory rejection.
  • Protection / recovery — LVRT / HVRT, current limiting, momentary cessation, trip and reconnection, and the active / reactive-power recovery ramp.

What each group is really checking:

  • Flat run. A no-disturbance simulation started at the intended operating point: it should remain stable, with no artificial oscillation, drift, unexplained controller movement or protection operation. It matters because if the model cannot stay quiet before the disturbance, any later fault response may be contaminated by an initialisation error.
  • Balanced and unbalanced faults. Balanced tests check the positive-sequence and severe voltage-dip behaviour; unbalanced tests check the negative-sequence response, the phase-specific voltage measurement, the PLL behaviour, the current limiting and the protection logic.
  • Sequential faults. These test memory and recovery — a model may ride through one event but fail when a second arrives before all controls, dc-link states, protection timers or recovery ramps have reset.
  • Temporary over-voltage (TOV). Checks whether the model correctly represents HVRT, reactive-current absorption, converter blocking, dc-link behaviour and over-voltage protection.
  • Reference steps. Voltage-reference and active-power-reference steps are not fault tests: they confirm the plant controller, local controller, ramp limits, dead-bands, filters and delays are represented correctly.
  • Frequency and inertia. Frequency tests check whether P(f), droop, dead-band, synthetic inertia, fast frequency response, headroom and recovery are implemented as expected — and reveal any unrealistic instantaneous active-power response.
  • Phase-angle jump. Stresses the PLL and synchronisation logic, because real faults, switching and islanding cause sudden voltage-angle movement.
  • Oscillatory rejection. Injects small oscillations into voltage, frequency or angle to see whether the model damps, ignores or amplifies them — a useful weak-grid and control-interaction screen.
SMIB acceptance checklist
  • model version and software version; compiler / library requirements; a valid time step;
  • the parameter set and site settings; the initialisation method; flat-run stability; a power-flow match;
  • the correct P / Q sign convention; the correct transformer ratios and base values;
  • the correct LVRT / HVRT thresholds; the correct current limit and P / Q priority; the correct protection flags;
  • the correct recovery ramp; the correct plant-controller mode; the output channels available; and the known limitations documented.

Section 4

Extremely weak networks: when “good” is bad

The most revealing acceptance tests happen at the edge, where the connection is extremely weak — short-circuit ratio near \(1.0\). SCR is the short-circuit power at the connection point divided by the plant rating; a low SCR means the converter current has a strong effect on the local voltage magnitude and angle. It is a warning indicator, not a universal pass / fail rule — but at the edge the usual logic inverts.

A stable model at SCR ≈ 1 may be a wrong model

In an extremely weak grid the real plant may be close to its stability boundary. If the model appears unrealistically smooth and stable, that may mean it has omitted the control interaction, PLL limitation, protection mode, current limiter or site-specific tuning that would appear in the real plant. So for a very weak network, acceptance is not simply proving the model stays stable — it is proving the model reproduces the correct stability margin and failure mechanism. Two checks are recommended: raise the active-power reference in gradual steps toward rated output (the plant may be unable to hold stability at 100%, and the ramp may need slowing for the slew-rate limit); and apply a fault-clearance strength change that leaves the post-fault SCR at \(1.0\). Where ride-through at SCR = 1 is genuinely possible, evidence beyond the model should back the claim.

The weak-grid acceptance rule

In weak-grid model acceptance, a model that is too stable can be as dangerous as a model that is too unstable. Repeat the checks across the expected SCR and X/R range and across operating points.

Section 5

Coherency and long-run checks

Once a wide-area EMT network is built, the first guard against gross construction errors is a coherency check: compare the EMT case with a trusted RMS / PDT reference for the same operating condition and disturbance. The purpose is not to make EMT and PDT identical — it is to confirm that the basic network, the power flow, the generator response and the broad dynamic behaviour are coherent before the EMT-specific effects are studied. The two tools will not return identical results (the IBG models are simplified, and the EMT waveforms carry higher-frequency content the phasor solution never shows), but they should agree in the overall shape of active power, reactive power and voltage.

Where EMT and PDT should legitimately differ

If the study involves fast converter control, unbalance, harmonics, switching, weak-grid interaction or protection logic, EMT and PDT may legitimately differ. The key skill is telling whether a difference is a real modelling improvement (EMT seeing a mechanism PDT removed) or a data / setup error. A difference is not automatically a fault, and identity is not automatically a success.

The second guard is a long-run stability check: run the EMT case for an extended period without a severe disturbance and watch for artificial behaviour — numerical drift, hidden oscillation, control wind-up, slow protection timers, transformer-saturation states or converter controls creating something that is not physically there. A steady synchronous-machine speed is a good indicator that the controls, the modelling options and the numerics are sound; and, tellingly, numerical noise on that speed can disappear once a physical detail such as the transformer magnetisation branch is included — representing real physics is a condition for a clean solution, not optional polish.

Section 6

Validation against staged field tests

A staged field test is a deliberately applied disturbance under controlled conditions — a voltage-reference step, a reactive-power step, an active-power step, a capacitor or reactor switching, a controller-mode change or another safe plant-level test. They are valuable because the disturbance is known, the plant configuration is known, and high-quality measurements can be collected. The method is to configure the model to match an achievable operational test; if the correlation is good, the specified — often more onerous, weak-grid or N−1−1 — conditions can then be simulated with confidence.

Their limitation is honest: staged tests rarely cover the most severe faults or the weakest grid conditions, because those are not safe to create deliberately. So they are strong validation evidence, but they do not prove the model for every possible condition. A trio of Australian solar cases from 2019–2020 shows the method finding, confirming and then fixing a real problem.

The Australian solar-farm oscillations, and the real lesson

EMT simulation flagged an \(\approx 8\) Hz sub-synchronous voltage oscillation (SSO) from newly connected solar farms in a very weak area, pushing the post-fault voltage past the flicker limit — and it could be triggered simply by switching off one particular transmission line, with no fault at all. A real-time line-switching test triggered it exactly as predicted, and feeding the exact condition into a playback-validated EMT case (with the farms’ actual field inverter settings) reproduced the oscillation in both magnitude and frequency (6–8 Hz). A second case traced an oscillation to an interaction between two static var compensators (SVCs) and a solar farm; a third proved a retuning fix over four days of recommissioning tests. The lesson is not that EMT is automatically superior. It is that when the phenomenon is created by inverter controls, weak-grid behaviour, sub-synchronous oscillation or control interaction (SSCI), a PDT / RMS model may remove the mechanism entirely — and EMT captures it only if the converter model contains the relevant control and protection behaviour.

Section 7

Validating against real disturbances

Beyond staged tests, a wide-area model is validated against the disturbances the system throws up on its own. Real-disturbance validation compares model output against an actual event — a fault, trip, switching event or oscillation — using the measured voltages, currents, active power, reactive power and frequency to check whether the simulation follows the real response. One robust technique feeds the measured three-phase voltages and frequency back into the model and compares its computed response with what the plant actually did.

A wide-area validation workflow
  • 1. Verify the load-flow match.
  • 2. Run a flat-run / no-disturbance case.
  • 3. Compare EMT and PDT for a simple disturbance.
  • 4. Check the steady-state voltages, angles, P / Q flows and frequency.
  • 5. Check the machine and converter outputs.
  • 6. Run a long-duration numerical-stability case.
  • 7. Apply a staged field test or a real-disturbance comparison.
  • 8. Adjust only justified parameters.
  • 9. Document the mismatches and the limitations.
Accuracy bands, and what to compare

An accuracy band defines an acceptable difference between measured and simulated response. A \(\pm 10\%\) band of the maximum deviation is one example from operator guidance — not a universal law; the acceptable band should depend on the variable, the study purpose, the measurement quality and the operator’s model-acceptance requirements. And validation should not stop at active and reactive power. Compare, where available: the terminal / PCC voltage; the active and reactive power; the active and reactive current (and the phase currents in EMT); the frequency and ROCOF; the dc-link voltage; the plant-controller references; the protection flags; the trip / block / momentary-cessation status; and the recovery ramp and settling time.

And when the overlay fails: if the simulated response is outside the band, do not immediately blame the EMT tool. First check the model parameters, the site settings, the measurements, the event timing, the initial conditions, the protection settings, the control modes, the transformer / cable data and the sign conventions — an unacceptable correlation almost always means insufficient or incorrect modelling, not a limitation of EMT.

Section 8

Playback validation: a Type-3 wind model

What playback validation is

Playback validation feeds recorded terminal-voltage waveforms into the model and checks whether it produces the recorded current and power response — the real grid disturbance is replayed to the model. It is powerful because it isolates the plant model from uncertainty in the wider network model: the input is exactly what the plant really saw, so any mismatch is the plant model’s.

A validation from the Gaspésie Peninsula illustrates it in full on a Type-3 (doubly-fed) wind generator. Type-3 wind normally means a doubly-fed induction generator (DFIG) with a partially rated converter connected to the rotor; its response depends on the machine dynamics, the converter control, the crowbar / protection, the dc-link behaviour and the fault-ride-through logic. Over 2007–2009, six recorded events were chosen to span the operating range — low power at sub-synchronous speed to full power at super-synchronous speed — and by fault severity and type (Table 2). The model was fed the recorded voltages and judged valid when it produced the same currents that were recorded; the whole wind-power-plant (WPP) model and its control were validated the same way at the point of interconnection.

Table 2 — The six recorded events used to validate the Type-3 wind-generator model (after CIGRE TB 881, Table 5-1). Sequence figures are the positive- and negative-sequence stator voltage as a percentage of the pre-fault positive-sequence voltage.
EventPre-fault operating conditionFault type (duration)Positive / negative sequence
1 (2007)Super-synchronous speedUnbalanced (0.05 s)−4% / +3%
2 (2007)Sub-synchronous, 360 kWUnbalanced (0.2 s)−4% / +5%
3 (2008)Super-synchronous, full powerUnbalanced (0.11 s)−28% / +21%
4 (2009)Sub-synchronous, 230 kWUnbalanced (0.15 s)−9% / +9%
5 (2009)Near-synchronous, 440 kWUnbalanced (0.2 s)−13% / +13%
6 (2009)Super-synchronous, 1.3 MWEvolving unbalanced (0.42 s, then 0.8 s)−17% / +14%, then −28% / +4%

For event 6 — the most severe and varied, an evolving unbalanced fault — the model matched the field measurement very closely, and good agreement across the other events raised confidence. The events were chosen deliberately to span operating points, power levels, speeds, fault types and severities, because one disturbance is not enough: a credible validation must cover a range, or the model may be tuned to one event and wrong elsewhere. Fine-tuning is straightforward for small disturbances but harder for large or unbalanced ones, where the machine’s nonlinearities bite. The honest caveats are worth keeping: the model was validated on only six events and a single generator, and it carried no protection systems, because no data was available to model them — which is exactly why the programme was extended with on-line monitoring at further plants. Validation is a direction of travel, not a finish line.

Section 9

Hardware- and software-in-the-loop

HIL means hardware-in-the-loop: a real controller, protection relay or control platform is connected to a real-time digital simulator (RTS / DRTS). The simulated network sends voltages and currents to the hardware, and the hardware sends control and protection actions back to the simulation. It is useful because it tests the actual controller hardware or firmware interface, not only a software representation. SIL — software-in-the-loop — runs the actual control code, or a compiled version of it, against the simulated system without the physical controller hardware.

Real time is the demanding part: a real-time simulator must finish each simulation time step within the same wall-clock time. If the time step is 50 microseconds, the simulator has less than 50 microseconds to solve the network and exchange its inputs and outputs — overrun the step and the result is inaccurate or diverges.

A real-time validation programme

A Tasmanian programme validated a real-time model of the whole power system, as dispatched (built from a SCADA snapshot), against a run of 2020 events — a line-commutated-converter (LCC) HVDC commutation failure (a generic PDT-plus-PLL model, because the proprietary offline EMT model could not be copied into the RTS, still matched the active- and reactive-power recovery closely); a line-to-line fault under high asynchronous penetration (the RTS reproduced the remote phase shifts, the HVDC and frequency recovery, and both a Type-3 and a Type-4 windfarm’s ride-through); and a legacy windfarm on a single-phase fault (a voltage-recovery mismatch, chased through a PDT repeat and fixed by tuning the reactive-power recovery). HVDC validation is especially important, because the converter controls, commutation behaviour, protection, filters and ac-system strength can strongly affect the surrounding network.

Section 10

Control replicas and the evidence hierarchy

A control replica is a high-fidelity copy of the real control and protection system used for testing. It is one of the strongest validation methods, because it brings the simulation close to the actual control implementation — but it is expensive, complex, and normally reserved for critical HVDC, flexible-AC-transmission-system (FACTS) or major grid-connection studies. The INELFE France–Spain interconnector illustrates it: a 2 GW modular-multilevel-converter HVDC link whose control replicas were run against an equivalent ac network on a real-time simulator. A 20% active-power step matched measurement and replica closely in frequency and amplitude; a block / deblock sequence matched in overall behaviour and peak values, the only notable differences coming from the field test having both HVDC links in service while only one was modelled — account for what is and is not represented, and the concordance is excellent.

The validation evidence hierarchy
  • documentation-only review;
  • SMIB acceptance tests;
  • comparison with vendor test cases;
  • staged field-test validation;
  • real-disturbance validation;
  • playback validation;
  • hardware- / software-in-the-loop;
  • control replica.

Higher evidence is not always required for every study — but critical weak-grid, compliance, incident or interaction studies need the stronger levels.

Section 11

Documenting the evidence

Acceptance and validation are only as useful as the record they leave. The report should let a later engineer know exactly what was proven, and under what conditions the model may — and may not — be used.

The acceptance / validation report should document…
  • the model name and version; the software / tool version; the study time step; the operating point;
  • the grid equivalent used for SMIB; the SCR / X/R tested; all the test cases; the pass / fail criteria;
  • the compared quantities; the measured-data source; the validation accuracy band;
  • the known mismatches; the limitations; the approved use cases; and the conditions where the model must not be used.
Do not tune blindly

Model tuning must be physically justified. Do not change hidden gains or parameters only to force a match, unless the change corresponds to a real plant setting, measured data or OEM confirmation. And remember the two neighbours of this page: acceptance and validation do not replace model adequacy — a generic or incomplete model can pass a narrow test but still be inadequate for the real study question; and after validation the model still has to be placed into a credible large-scale EMT case, where initialisation, boundary equivalents, network reduction and co-simulation can all change the result.

Common mistakes

Common mistakes

The traps that most often undermine acceptance and validation:

Twelve traps to avoid
  • Treating a successful simulation as validation, or confusing acceptance with validation.
  • Passing SMIB tests but skipping field validation.
  • Validating only one operating point.
  • Ignoring the weak-grid stability margin — or assuming a perfectly stable weak-grid response is always good.
  • Comparing EMT and PDT without understanding why they should differ.
  • Using poor-quality measurements without accounting for filtering and timing.
  • Tuning a model to one event and degrading others.
  • Validating P / Q only, ignoring current, voltage, PLL, dc-link and protection flags.
  • Ignoring software, compiler or time-step limitations.
  • Using HIL or control-replica results outside their tested range.
  • Blaming the EMT tool for a mismatch that is really data, settings or measurement.
  • Changing hidden parameters only to force a match, without physical justification.

Key points

Key points

Trust is tested, not assumed
  • Acceptance proves the model is usable, stable, documented and suitable for the intended tests; validation proves it can reproduce measured behaviour.
  • SMIB tests isolate the plant model before it enters a wide-area case.
  • Weak-grid tests must check realism, not just stability — a too-stable model can be as wrong as an unstable one.
  • Wide-area EMT cases need coherency checks and long-run numerical-stability checks.
  • Field tests and real disturbances provide stronger evidence than documentation alone; playback validation is powerful because measured voltage is replayed into the model.
  • HIL / SIL and control replicas give high-fidelity evidence for critical converter and HVDC studies.
  • A validation mismatch usually points to data, settings, initialisation, control-mode, protection or measurement issues — not the EMT method.
  • A model should only be used within the conditions for which it was accepted and validated.

The main takeaway: an EMT model is not trusted because it is detailed; it is trusted because it has been tested. Acceptance checks that the model is usable and robust; validation checks that it behaves like the real plant or system. For a wide-area EMT study the model must pass both — first in controlled SMIB conditions, then against credible wide-area evidence such as field tests, disturbance records, playback validation, HIL or control-replica tests.

Once the models are accepted and validated, the next challenge is building and running the large-scale EMT case itself. The next guide explains load-flow initialisation, boundary selection, network equivalencing, hybrid PDT–EMT simulation, co-simulation and real-time simulation. This page is based on CIGRE Technical Brochure 881, with APS engineering interpretation.

References

References

CIGRE Technical Brochure 881 is the primary reference for this page; the Australian Energy Market Operator’s model-acceptance-test and power-system-model guidelines inform the acceptance tests and the accuracy band; and the CIGRE/CIRED brochure on inverter-based generation gives the wider modelling context.

  1. CIGRE Working Group, Electromagnetic Transient Simulation Models for Large-Scale System Impact Studies in Power Systems Having a High Penetration of Inverter-Connected Generation. CIGRE Technical Brochure 881.
  2. Australian Energy Market Operator (AEMO), Model Acceptance Test Guideline and Power System Model Guidelines.
  3. CIGRE/CIRED Joint Working Group, Modelling of Inverter-Based Generation for Power System Dynamic Studies. CIGRE Technical Brochure.
  4. EMTP®, Electromagnetic Transients Program — Documentation, Model Validation and Real-Time / HIL Notes. Powersys / EMTP®.

Twelve-Part Technical Series

Modelling Inverter-Based Generation

A twelve-part guide to modelling inverter-based generation — from device characteristics and the RMS and EMT model families, through model adequacy, validation and large-scale wide-area EMT, to frequency, voltage and small-signal stability studies.

Part 6 Reading now

Acceptance Testing and Validation of EMT Models

How an EMT model earns trust: SMIB acceptance tests, weak-grid checks, staged field tests and playback validation against real disturbances.

Series progress 6 of 12