A practical, governance-first playbook for testing AI in Singapore facility and building operations.

Professional illustration of a Singapore commercial facility operations team reviewing an AI-assisted maintenance dashboard with human approval and cybersecurity safeguards.

Artificial intelligence can help facility-management teams reduce repetitive administrative work, organise operational information and identify issues for review. However, responsible adoption does not begin with giving an AI system control of a building. It begins with a clearly defined problem, suitable data, human accountability and a controlled test.

For Singapore facility managers, warehouse operators, building owners and engineering SMEs, the most practical starting point is usually assistive AI: tools that summarise work orders, search approved procedures, classify documents, draft inspection reports or highlight unusual energy readings for a person to review.

This guide sets out a governance-first path for using AI safely while keeping statutory duties, worksite controls and management accountability in place.

1. Select one low-risk use case

Begin with a task where AI can assist an existing process without making an irreversible decision. Suitable examples include:

  • Summarising maintenance work orders and service updates.
  • Searching an approved set of standard operating procedures.
  • Drafting inspection or handover reports for human review.
  • Classifying invoices, service records or equipment documents.
  • Reviewing energy data and flagging unusual patterns for investigation.

Choose a use case with a clear owner, a measurable baseline and a straightforward fallback to the current process. Avoid starting with automated control of ACMV, electrical, refrigeration or life-safety systems. Do not use an AI recommendation as a substitute for a competent person, licensed professional, permit-to-work process, lockout/tagout procedure, statutory inspection or emergency response.

2. Create a simple use-case register

Before a pilot begins, record the purpose and boundaries of the proposed application. A basic register should include:

  • The business problem and expected benefit.
  • The people who will use, approve and support the system.
  • The data sources involved.
  • What the AI may do and what it must not do.
  • Required human approval points.
  • Possible safety, privacy, security and operational impacts.
  • How incidents, errors and user feedback will be recorded.
  • The conditions for continuing, pausing or stopping the pilot.

This creates a shared understanding between operations, management, IT and any external technology provider. It also prevents a small experiment from quietly becoming an uncontrolled production system.

3. Classify the data before using it

Facility operations may involve work orders, access records, CCTV-related information, employee details, contractor records, equipment readings, floor plans and incident documentation. Not all data should be uploaded to an AI tool in the same way.

Separate information into practical categories such as public, internal operational, confidential commercial, personal or safety-sensitive data. Check whether the proposed tool stores prompts, uses customer information for model improvement, transfers data to third parties or allows administrators to access conversation history.

For personal data, review the intended purpose, notice and consent position where relevant, retention, access rights and supplier responsibilities. The Personal Data Protection Commission’s guidance on personal data in AI recommendation and decision systems can support this review. Where the position is unclear, obtain appropriate privacy or legal advice before proceeding.

Use data minimisation wherever possible. Remove names, identification numbers and unnecessary free-text details from test data. Create a controlled sample rather than giving a new tool access to an entire document repository.

4. Keep people responsible for decisions

Human oversight should be designed into the workflow, not added as a general instruction after deployment. Define exactly when a person must review an output and what evidence they must check.

For example, an AI system may draft a maintenance summary, but the supervisor confirms the asset, location, priority, isolation status and required follow-up. An analytics tool may flag abnormal energy use, but an engineer investigates the trend and decides whether any action is justified.

Do not allow an AI assistant to approve permits, close safety findings, override alarms, instruct workers to enter hazardous areas or change building controls without the appropriate existing authority and technical safeguards. The final decision should remain with the designated responsible person.

5. Test with realistic FM scenarios

A demonstration using ideal data is not enough. Build test cases from real operational conditions, including incomplete work orders, inconsistent asset names, ambiguous instructions, outdated procedures, unusual readings and conflicting records.

Check whether the system:

  • Invents facts, values, equipment details or references.
  • Confuses similar assets, locations or work activities.
  • Produces unsafe or incomplete instructions.
  • Reveals personal, commercial or operationally sensitive information.
  • Follows an adversarial or misleading prompt.
  • Handles a request outside its intended scope.
  • Provides enough evidence for a reviewer to verify the answer.

IMDA’s testing material for LLM-based applications highlights risks including hallucination, undesirable content, data disclosure and adversarial prompts. Testing should involve people who understand both the technology and the facility process. Record test inputs, outputs, reviewer comments and corrective actions.

6. Secure the application and connected environment

AI security is not limited to the model. Review the complete application and its connections. Use role-based access, strong account controls, approved integrations, logging and appropriate separation between test and production environments.

Restrict access to building-management systems, work-order platforms, sensors and operational technology. An AI application that can read information does not automatically need permission to write, execute commands or change settings. Treat uploaded documents, external links and generated instructions as possible sources of error or manipulation.

Check the supplier’s security approach, data handling, support process, subcontractors, update practices, incident notification arrangements and ability to delete or return information. CSA’s guidance on securing AI systems provides a useful lifecycle perspective, including supply-chain and adversarial machine-learning risks.

7. Train users on limitations and escalation

Users should know what the tool is for, what information they may enter, how to verify an answer and how to report a problem. Short, task-specific training is often more useful than a general introduction to AI.

Provide examples of acceptable and unacceptable use. Make it clear that fluent wording is not proof of accuracy. Staff should escalate outputs that affect safety, statutory compliance, personal data, security, equipment isolation or customer commitments.

8. Measure the pilot before scaling

Compare the pilot with the existing process. Useful measures may include time saved, rework, correction rates, user adoption, unresolved errors, response quality and the number of escalations. Do not measure success only by how quickly the AI produces an answer.

Set a formal go/no-go review. Continue only if the use case delivers a worthwhile benefit without creating unacceptable safety, privacy, security or operational risks. If the system performs poorly, narrow the scope, improve the data, strengthen approval controls or stop the pilot.

9. Scale in stages

After a controlled assistive use case is stable, an SME may consider broader analytics or workflow automation. Each new application should undergo its own review because risk depends on the data, users, environment and consequences of error.

Applications involving safety monitoring, maintenance decisions or automated building controls require a higher level of engineering review and operational control. They should not be treated as a simple extension of a successful document-summary pilot.

Where ISS can help

Responsible AI adoption connects technology with engineering, facility-management processes and workplace realities. ISS can discuss requirements for AI automation, operational workflows, digital services and facility or engineering environments, helping your team define a practical starting point and the controls needed before implementation.

Contact ISS at intelligencesolutionservice.com to discuss your engineering, facility-management or AI automation requirements.

Reference points