Skip to the main column
Genset Digest Diesel power & process air

Genset Digest / Maintenance & Operation Guides / What starts when the mains drop

September 12, 2026 Maintenance & Operation Guides Controls

What starts when the mains drop: the set's own boot sequence

Between the mains failing and the load being fed there is a timed sequence, not an event: the failure is confirmed, the engine cranks, voltage is built, the transfer switch moves and the set is allowed to settle. Each stage exists to prevent a worse failure than the outage itself.

Anyone who has watched a computer boot knows the shape of what a standby set does on a mains failure: a fixed order of stages, each one gated by the last, with deliberate waits where haste would do damage. The computing side of that order is mapped in Windows startup locations, a technical guide to where programs register to start, what triggers them and how a slow or broken boot is diagnosed by stage. The genset's version is mechanical, electrical and timed to the second.

Automatic transfer switch cabinet open on a wall showing contactors and control wiring
The transfer switch: the one component that is never allowed to be in two states at once.

Stage by stage, what actually happens

The sequence runs in a fixed order. Sensing first: the controller watches the mains and must see it gone, not merely flicker, so a short delay rides out brief dips. Then the start command: the battery and the starter motor crank the engine, within a defined cranking limit and rest cycle. Then run-up: oil pressure proven, speed stabilised, voltage and frequency built at the alternator. Only then the transfer: the switch moves the load from the dead supply to the live set. And finally settling: the set runs on to a stable temperature, taking the real load it was sized for in the sizing calculation.

Why are the delays designed in?

Because a premature step is worse than a slow one. Transfer before voltage is stable dumps an unready machine onto a waiting load; sensing without a delay makes the whole system chase every grid flicker; cranking without a limit runs the battery into the ground on a set that will never start. Each wait in the sequence is a learned protection, and the standard that frames emergency and standby systems, NFPA 110, writes expectations about start time and reliability into the design rather than leaving them to hope.

The clock that matters

Critical installations define a maximum time from mains failure to restored supply, often in the tens of seconds. Every stage in the sequence spends a share of that clock, and the specification is where the shares are agreed.

Hour meter on a newly installed generator set showing its first recorded hours
The hour meter: every exercise and every real start accumulates here, and the log says which.

What goes wrong, stage by stage

Each stage has its signature failure. Sensing faults are phantom starts and missed transfers. Cranking faults are batteries, chargers and starters, the commonest cause of a no-start and the reason the battery system is treated as life-safety equipment. Run-up faults are oil pressure, governor and AVR. Transfer faults are the switch itself, worn contacts and failed operators. The monthly exercise exists to rehearse the whole chain, and the annual load test to prove it under real work, as set out in the load bank guide.

The return sequence is half the job

When the mains comes back, the set does not simply stop. A retransfer delay confirms the restored supply is stable before the load moves back, the engine runs on unloaded to cool the turbocharger and the windings, and only then does it shut down and reset to standby. Skipping the cool-down shortens the machine's life; skipping the stability wait can drop the load a second time. The whole sequence, start and return, is what the exercise routine in the maintenance schedule is rehearsing.

Testing the sequence without the outage

The sequence can be rehearsed in pieces, and each piece tells its own story. A simulated mains fail at the switch tests sensing, cranking and transfer without waiting for weather; the exercise timer tests the controller's automatic version of the same thing. What neither proves is the set under real load for real hours, which is why the sequence test and the load test are different appointments with different purposes.

Recording the rehearsal is what makes it a test. The log entry for a simulated transfer should read like the test sheet it is: when the fail was simulated, how long the set took to accept the load, what the readings showed, what was found wanting. A sequence rehearsed but unrecorded is a story; recorded, it is evidence, and the difference is the entire argument of this magazine's approach to the machine's file.

Manual start is the contingency the sequence still needs. Automatic systems fail at their sensors, their batteries and their switches, and a site that cannot start its set by hand is a site whose backup depends on the backup working. The manual procedure, written, posted and rehearsed, is the fallback that makes the automatic chain a convenience rather than a single point of failure.

Diagnosing a failed sequence follows the same staged logic as a slow boot: work out which stage failed and stop there. A set that never tried to start is a sensing or battery question; one that cranked and died is fuel, air or protection; one that ran but never took the load is voltage build or the switch. The sequence that was understood stage by stage is the sequence that gets fixed quickly, which is the entire point of knowing what starts when the mains drop.

Read that way, the start sequence stops being a black box and becomes a designed argument: confirm, crank, prove, transfer, settle. Every stage is there because some failure once taught the industry to put it there, which is exactly how standards and procedures everywhere are written.

The exercise interval is where the sequence is kept honest. A monthly run under the building's parasitic load proves the chain works; an annual load test proves it works under real demand. Skipping either is how a site discovers, in the outage, that the sequence it depended on was last proven two years ago.

Sources

NFPA 110, Standard for Emergency and Standby Power Systems

Read next

Where such a set is sited changes what the sequence must protect: siting a set on an industrial estate looks at land, power and clearances.

For the test that proves the whole sequence under load, see the load bank guide, and for the controls' record the digital file guide.