A practical readiness guide for resilience, sustainability, maintenance evidence and responsible facility automation.

Professional Singapore data-centre operations infographic showing electrical systems, cooling, fire safety, water monitoring, maintenance records and responsible AI automation connected to a readiness checklist.

Singapore’s proposed Digital Infrastructure Act is a timely reason for data-centre operators, building owners and facility teams to review how they manage resilience, continuity, sustainability and operational evidence.

The Bill was introduced for First Reading on 8 September 2026. It is proposed legislation, not a fully operative requirement. The Bill states that commencement would take place by a later notification in the Gazette, while detailed thresholds, transition arrangements, regulations and Codes of Practice are still subject to development and consultation.

This means preparation should focus on sound operational control rather than trying to predict every future rule. The objective is to know which systems are critical, how they perform, who is responsible, what happens during disruption and whether the organisation can produce reliable evidence.

What the proposed framework may mean for facility operations

The proposed framework includes licensing regimes for major data-centre and cloud services, as well as data-centre operators with critical IT load of at least 3 MW. The research context also identifies a proposed sustainability-focused data-centre licence for facilities at or above 3 MW and a major foundational digital infrastructure licence for qualifying data-centre facility services at or above 10 MW. These thresholds and their application should be verified against the final legislation and supporting instruments.

Potential expectations include physical and cyber security, business continuity, disaster recovery, service-disruption notification and facility-level sustainability. The proposed framework may address risks arising from technical failures, power, cooling and fire-related incidents. It may also introduce PUE requirements and possible future requirements concerning IT equipment and water efficiency.

Do not treat these proposed obligations as a replacement for current statutory duties, fire-safety requirements, workplace responsibilities, electrical controls, building requirements or project-specific competent-person duties. Instead, use them as a planning signal to strengthen your management system.

Step 1: Confirm your facility and service profile

Start with a short applicability and exposure assessment. Record:

  • Critical IT load and how it is calculated.
  • Whether the site provides co-location, cloud, managed services or other digital infrastructure services.
  • Which systems are operated by the data-centre owner, tenant, cloud provider, landlord or specialist contractor.
  • Power, cooling, fire protection, water and security dependencies.
  • Customer commitments for availability, maintenance windows and incident communication.

Do not assume that a building’s total electrical capacity is the same as critical IT load. Ask a suitably qualified engineering professional to confirm the basis, boundaries and calculation method used for your site.

Step 2: Build a critical-asset and dependency register

Create one controlled register covering the systems that support safe and continuous operation. At minimum, include:

  • Incoming supply, transformers, switchboards, UPS systems, batteries, generators, fuel systems and automatic transfer equipment.
  • Cooling towers, chillers, pumps, CRAH or CRAC units, controls, valves, heat rejection and ACMV systems.
  • Fire detection, alarm, suppression, smoke control, emergency power and fire command interfaces.
  • Water storage, treatment, leak detection, drainage and cooling-water systems where relevant.
  • Building management systems, energy meters, environmental sensors, network links and security systems.

For each asset, capture location, duty and standby arrangement, capacity, operating limits, maintenance owner, contractor, failure effect, bypass or isolation method and last test date. Link every critical asset to the loads or services it supports.

Step 3: Define operating envelopes and alarm priorities

Resilience depends on detecting deterioration before it becomes an outage. Establish approved operating ranges for temperature, humidity, differential pressure, chilled-water conditions, electrical loading, battery condition, fuel status, generator readiness, water levels, leakage and energy performance.

Separate alarms into at least three levels: immediate safety or service threat, urgent investigation and routine condition change. Every alarm should have an owner, response time, escalation path and closure requirement. Avoid creating a large volume of alarms that operators cannot review.

Sensor readings are only useful when sensors are correctly located, calibrated and connected to a time-synchronised system. Document sensor limitations, communication failures, missing data and manual verification procedures.

Step 4: Strengthen maintenance and test evidence

Review preventive and condition-based maintenance for electrical, ACMV, fire, water, controls and security systems. Your evidence pack should make it possible to demonstrate:

  • What was maintained, inspected or tested.
  • When the work occurred and under which approved procedure.
  • Who performed and verified the work.
  • What defects were found and how they were closed.
  • Whether temporary impairments, bypasses or degraded redundancy remain open.

Keep certificates, test results, calibration records, method statements, risk assessments, permits, photographs, trend data and contractor reports in a controlled repository. Records should be searchable by asset and date, protected from unauthorised alteration and retained according to applicable contractual, statutory and governance requirements.

Maintenance evidence does not replace inspection, approval or certification duties assigned to competent persons, licensed professionals, fire-safety personnel or other authorities.

Step 5: Map continuity, shutdown and recovery scenarios

Write practical playbooks for the scenarios most relevant to the facility. Consider utility failure, generator failure, UPS or battery fault, cooling loss, water leak, fire-system impairment, smoke event, control-system failure, cyber-related loss of visibility and restricted site access.

Each playbook should identify decision-makers, safe operating limits, customer communication, isolation points, manual fallback actions, contractor contacts, recovery priorities and evidence to capture. Define when an incident becomes a reportable or customer-notifiable disruption, but do not assume final notification timelines until the applicable law, licence condition or Code of Practice is confirmed.

Exercise the playbooks using tabletop reviews and controlled technical tests. Shutdown and recovery activities must be planned by appropriately qualified personnel and coordinated with tenants, equipment vendors and relevant safety roles. Never use an AI recommendation as authority to open, close, energise, isolate or bypass equipment.

Step 6: Establish energy and water data controls

Begin measuring the data needed to understand facility performance. Define the boundaries, meters, calculation method, sampling interval, data owner and review frequency for PUE and related energy indicators. Where water is material to the cooling strategy, document water sources, consumption points, treatment systems, reuse arrangements, leakage events and data gaps.

Green Mark for Data Centres 2024, the Green DC Roadmap and the Tropical Data Centre Standard can provide useful technical references and benchmarking direction. Present them accurately as guidance or reference material unless a future instrument, licence condition or contract makes a particular requirement mandatory.

Investigate unusual changes rather than chasing a single number. A rising PUE may reflect weather, maintenance, partial loading, meter faults or a change in IT demand. Record the explanation and corrective action.

Step 7: Use automation with human accountability

AI and automation can help facility teams review alarms, detect abnormal trends, summarise work orders, identify overdue maintenance and assemble audit evidence. A practical starting point is a controlled workflow that combines BMS, DCIM, CMMS and energy data without changing equipment commands automatically.

Apply safeguards:

  • Keep a human reviewer for safety-critical, service-affecting or irreversible decisions.
  • Show the source data, timestamp, confidence limitations and reason for each recommendation.
  • Log user actions, overrides, model changes and data corrections.
  • Restrict access according to role and separate monitoring from control authority.
  • Test for stale data, sensor drift, missing tags and false alarms.

Automation should reduce administrative delay and improve visibility, not hide uncertainty or transfer engineering responsibility to software.

Step 8: Assign responsibilities and close the gaps

Create a responsibility matrix covering the owner, operator, tenant, cloud or co-location customer, landlord, M&E contractor, fire-safety specialists, security provider and automation vendor. Mark each control as owned, shared, customer-controlled or outside your direct control.

Then produce a gap register with priority, risk, interim control, budget need, responsible person and target review date. Prioritise life safety, single points of failure, unreliable alarms, missing maintenance evidence, unclear shutdown authority, untested recovery procedures and uncontrolled data access.

Important limitations

This guide is an operational readiness framework, not legal advice, a licensing determination or a substitute for engineering design. The Digital Infrastructure Act remains proposed in the supplied research context, and final requirements may change. Confirm applicability with the relevant Singapore authorities and obtain project-specific advice from competent and appropriately qualified professionals.

Prepare before the details are final

Organising asset data, operating procedures, incident workflows, energy records and responsibility boundaries is useful whether or not every proposed provision takes its final form. A disciplined evidence system also improves maintenance planning, tenant communication and day-to-day facility decisions.

ISS can help organisations review engineering information, facility-management workflows and AI automation opportunities for practical, responsible implementation. Contact ISS to discuss your engineering, facility management or AI automation requirements.

Reference points