Autonomous Control System Audit Obligations

Autonomous Control System Audit Obligations

1. Introduction

Autonomous Control System Audit Obligations refer to the legal duties to regularly examine, test and document automated systems that control energy infrastructure. These systems may include AI-based grid controllers, automated substations, smart-grid systems, automatic fault-control systems, energy-management software and autonomous trading platforms.

As electricity systems become more automated, an important legal question arises: Who checks whether an autonomous system is operating lawfully and safely?

An audit provides an answer. It examines whether the automated system follows legislation, licence conditions, grid codes, technical standards, cybersecurity requirements and safety obligations. In South Africa, this is particularly important because NERSA monitors compliance with electricity licence conditions and undertakes compliance audits.

2. Meaning of Autonomous Control System Audits

An autonomous control system audit is a structured examination of a system that makes or implements decisions automatically.

An audit may examine:

whether the system operates within its legal authority;

whether software follows approved operating rules;

whether safety limits are correctly programmed;

whether decisions are properly recorded;

whether cybersecurity protections are effective;

whether human intervention remains possible;

whether system failures are detected and corrected;

whether the operator complies with licence conditions; and

whether consumers and other affected parties are protected.

For example, an autonomous electricity-grid controller may automatically disconnect a damaged transmission line. An audit should establish whether the system used correct information, applied the approved grid rules and maintained a proper record of the decision.

3. Legal Basis in South African Energy Law

The Electricity Regulation Act 4 of 2006 (ERA) provides the central regulatory framework. NERSA licenses electricity-generation, transmission and distribution activities and monitors compliance with licence conditions. NERSA's compliance programme includes audits of distribution licensees and generation facilities.

Licence conditions can require information, documentation and compliance with operational requirements. In Eskom Holdings SOC Ltd v Silicon Smelters (Pty) Ltd (2023), the court considered section 14 of the ERA, which permits NERSA to impose licence conditions concerning matters including information and documents required by the regulator.

Therefore, audit obligations may arise directly from legislation, NERSA rules, licence conditions, grid codes, environmental authorisations or other applicable regulatory requirements.

4. Relevant Case Laws

Eskom Holdings v Vaal River Development Association (2022)

In this Constitutional Court case, the court explained the broad regulatory framework established by the ERA. NERSA can impose licence conditions, regulate electricity activities and adjudicate contraventions of licences. Its decisions are subject to statutory appeal and review mechanisms.

The case is important for autonomous control systems because an operator cannot argue that its automated technology is outside regulatory supervision. If the system performs functions covered by a licence, its operation must remain consistent with the applicable regulatory framework.

Eskom Holdings v Lekwa Ratepayers Association (2022)

The Supreme Court of Appeal recognised NERSA as the regulatory authority responsible for the electricity regulatory framework and confirmed its powers concerning electricity licences.

For autonomous systems, this supports the principle that technical automation does not remove regulatory oversight. Operators remain responsible for compliance even when control functions are performed automatically.

Eskom Holdings v Sonae Arauco (2024)

This case concerned the operation of electricity systems under NERSA's regulatory framework. The court noted that NERSA's codes, including the South African Grid Code, form part of licence conditions. The Grid Code requires the system operator to take prompt remedial action where abnormal conditions threaten reliable operation.

This is directly relevant to autonomous control systems. If an automated controller performs remedial action, its programming should reflect applicable grid-code requirements, and audits should test whether it actually does so.

Eskom Holdings v Emfuleni Local Municipality (2023)

The court discussed NERSA's powers to enforce licence conditions and noted that certain electricity distribution licence conditions require audited financial statements, maintenance planning, compliance management and safety-related measures.

This demonstrates that auditing is not merely a technical exercise. It can be part of a licensee's continuing regulatory obligations.

5. Main Audit Obligations

Technical Audit

The system should be tested to determine whether it performs according to approved technical standards and grid requirements.

Legal Compliance Audit

Auditors should determine whether automated decisions remain within the powers granted by legislation, licences and regulatory codes.

Cybersecurity Audit

Because autonomous control systems can be remotely affected, audits should examine authentication, access controls, software integrity and incident response.

Data Audit

The accuracy and reliability of sensor and meter data should be examined because incorrect data can lead to incorrect automated decisions.

Decision-Logging Audit

Important automated actions should create reliable records showing what happened, when it happened and which rule or system instruction was applied.

Human-Oversight Audit

Audits should determine whether responsible personnel can intervene when an autonomous system malfunctions or produces an unsafe result.

6. Legal Importance

The main purpose of auditing is accountability. Without regular audits, an operator may not know whether an autonomous system has gradually developed errors, cybersecurity weaknesses or unlawful operating practices.

Auditing also supports transparency. If an automated decision causes a power interruption, market loss or safety incident, audit records can help determine responsibility.

The recent Topigs Norsvin v Eskom Holdings (2026) decision also illustrates the importance of clearly identifying which regulator has a particular statutory duty. The Supreme Court of Appeal emphasised that regulatory bodies operate within the powers and duties created by their enabling legislation.

7. Conclusion

Autonomous Control System Audit Obligations are essential for modern electricity governance. Automation can improve reliability and speed, but it also creates new risks involving software errors, cybersecurity, data quality and unclear responsibility.

South African law supports a model in which autonomous technology remains subject to statutory authority, licence conditions, technical codes, compliance monitoring and audit requirements. The cases involving Eskom, NERSA and electricity regulation show that technological systems cannot operate outside the legal framework.

The best regulatory approach is therefore continuous technical auditing combined with legal compliance review and human accountability. Autonomous control may perform the operational task, but the responsible licensee and regulator must remain capable of explaining, reviewing and correcting the system's actions.

LEAVE A COMMENT