Prima — Critical Spares & Spare Parts Policy · A4 · 19pp · Draft v0.1
DRAFT
Draft
Part ofPetroCompute
Critical Spares & Spare Parts Policy
What is held on site,
why, and how fast
a failure is closed

The criticality method that decides what qualifies as a critical spare, the stocking classes and holding levels, the register by discipline, and the storage, replenishment and obsolescence regime behind it. Written against the installed design for 13,824 GPUs at Knowledge Oasis Muscat.

Document
PRM-SPR-2026-001
Version
0.1 — Draft
Classification
Internal — controlled
Owner
Facilities Manager
Applies to
KOM Muscat
S1
Held on site,
no exceptions
4h
Target to part
in hand, class S1
3
Tests that put a
part on the list
98%
Fill rate target
on first demand
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled01 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 02 / 19
01Purpose, scope and what this document is not

Redundancy buys time; it does not repair anything. When one half of an N+1 pair fails, the Facility is running without protection and stays that way until the part is replaced. The interval between the failure and the replacement is the real exposure, and it is set almost entirely by whether the part is on the shelf.

This document therefore does two things. It defines the method by which a part is judged critical — so that the list is defensible rather than a collection of opinions — and it sets out the register itself, with the holding level for each line and the reasoning behind it.

1.1 Scope

The KOM Oman AI Factory at Knowledge Oasis Muscat: the electrical chain from utility intake to rack, the cooling plant and secondary loops, the network fabric, the compute platform, fire detection and suppression, the security estate, and the BMS and EPMS control layer. Design basis is 13,824 GPUs in 1,728 eight-GPU nodes, direct liquid cooled, at a 37.5 MW site allocation, Tier III Standard topology, ready for service December 2026.

1.2 Ownership boundary

The register covers Prima-owned plant and Prima-owned IT. Where a customer owns equipment in the hall under a colocation arrangement, spares for that equipment are the customer's responsibility and sit outside this register — the boundary in each case is the one drawn in PRM-DEM-2026-001. Prima will hold customer-owned spares on request as a chargeable service, under the same storage and handling regime at section 09.

1.3 What this document is not

It is not an inventory record, and nothing here should be read as evidence that a part is in stock. No equipment has yet been delivered. Quantities marked indicative are derived from the design basis and manufacturers' published failure data; they become firm at the equipment order, when model numbers, actual port counts and rack layouts are fixed. The first physical stock take is scheduled against gate L3 in the commissioning programme.

Honest positionTwo things in this document are real today: the method and the policy. The quantities are engineering estimates against a design, not a count of parts on a shelf. Section 04 shows the arithmetic behind each so that a reviewer can check the reasoning rather than take the number on trust.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled02 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 03 / 19
02Criticality — the three tests that put a part on the list

A part is critical if it passes any one of three tests. The tests are applied to the part, not to the system it sits in — a cheap relay inside a switchboard can be more critical than the switchboard, because the relay is what actually fails.

Test 1 · Consequence

Failure of this part interrupts service, or removes a layer of redundancy the availability commitment depends on. A part whose failure is invisible to the load still passes if it takes N+1 down to N.

What breaks when it fails
Test 2 · Exposure

The lead time to obtain it exceeds the exposure window the design can tolerate — see 3.2. A part available next morning locally is not critical; the same part on a twelve-week import is.

How long we would wait
Test 3 · No workaround

There is no field workaround that restores protection. Where a documented MOP can bypass, re-route or cross-connect around the failure without loss of redundancy, the part may fall out of scope.

Whether we can work around it
2.1 What the tests deliberately exclude

Two categories are kept off the register on purpose, because carrying them would be capital held against a risk that is already managed elsewhere.

Very long-lead major plantTransformers, main switchgear sections, chiller compressors and CDU plate packs run to 26–52 weeks and cost multiples of the rest of the register combined. These are not stocked. The mitigation is topology: the design carries N+1 at plant level, so a single unit loss degrades protection but not service, and replacement runs as a project rather than a repair. Section 05 and 06 name each of these explicitly rather than omitting them, and state the exposure that results.
Parts covered by a contracted responseWhere a manufacturer holds a part in-region under a contracted response time shorter than our own exposure window, the part is recorded as class S2 and the contract reference is the control. The obligation is on the contract, not the shelf — but the part still appears on the register, because a reviewer is entitled to see that the decision was made rather than overlooked.
2.2 Review of criticality
  • Annually, against actual consumption. A part consumed twice in a year is under-stocked regardless of what the model says; a part untouched in three years is reviewed for de-listing.
  • On any change to the plant — equipment replacement, firmware change that alters a part number, or a topology change that alters redundancy.
  • After any incident in which the absence of a part extended the outage. This is recorded as a finding against the register, not only against the incident.
  • On a manufacturer's end-of-life notice, which triggers the obsolescence path at 10.3.
Consequence of the methodBecause Test 2 is written in terms of an exposure window rather than a fixed lead time, the register changes as the supply position changes. A part that becomes locally stocked drops from S1 to S2 without argument; a part whose supplier withdraws from the region moves the other way. The list is a function of the method, not a fixed inheritance.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled03 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 04 / 19
03Stocking classes and the exposure window

Every line on the register carries one of four classes. The class states where the part lives and how quickly it can be in an engineer's hands — not how important it is.

ClassMeaningTime to part in handControl
S1On siteHeld in the Facility spares store, on the same site as the plant. The default for anything that passes Test 1 and cannot be worked around.Under 4 hours, any hour of any dayPhysical stock, min/max levels
S2In regionHeld by the manufacturer or a distributor within the Gulf, under a contracted response obligation. Used where the part is bulky, costly, or has a shelf life shorter than its expected time in stock.Under 24 hours, contractedContract clause, tested annually
S3Order on failureNot stocked. Ordered when it fails, because the design tolerates the wait or the part almost never fails.Lead time as publishedAccepted exposure, stated
S4Not stocked — projectMajor plant. Replacement is a capital project, not a repair. Redundancy carries the service in the meantime.26–52 weeksN+1 topology
3.1 Lead-time bands

Bands are used throughout the register in place of specific dates, because a published lead time from a manufacturer is a forecast and not a commitment. The band is what the stocking decision is made against.

Band A
Under 2 weeks
Locally available or air-freight commodity. Rarely justifies S1 on lead time alone — only on consequence.
Band B
2 to 12 weeks
Imported, made to order, or region-allocated. The band in which most S1 decisions are made.
Band C
12 weeks and beyond
Major plant, long-lead electrical and thermal equipment. S4 territory; mitigated by topology, not by stock.
3.2 The exposure window

The exposure window is the period the design can run without the failed part before the availability commitment is genuinely at risk. It is not a comfort figure; it is derived from what redundancy remains after the failure.

Zero windowThe failure has already interrupted service, or the remaining path is single and unprotected. Part must be on site — class S1, no exceptions, whatever the cost of holding it.
Short window — daysRedundancy is degraded from N+1 to N: the load is carried, but a second failure in the same subsystem now interrupts service. Class S1 where the lead time is Band B or C.
Long window — weeksFull designed redundancy remains after the failure, or the function is not in the availability path. Class S2 or S3 is acceptable, and the accepted exposure is stated on the line.
How it is appliedTest 2 compares the lead-time band against the window. Band B or C against a zero or short window is always S1. Band A against a long window is always S3. Everything between is a judgement recorded on the line, with the reasoning shown.
Why this matters to an offtakerThe 99.982% monthly commitment in PRM-SLA-2026-001 tolerates roughly 8 minutes of unavailability per month. That budget is not consumed by waiting for a spare — it is consumed by the second failure that arrives while the first is still unrepaired. The register exists to keep that window as short as physically possible.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled04 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 05 / 19
04Holding levels — how a quantity is arrived at

Three different methods produce the quantities in the register, depending on how the part fails. Mixing them would be the common error — a wear part and a random-failure part need different arithmetic.

4.1 Random-failure population items

Optics, drives, fan modules, power supplies. These fail at a roughly constant annual rate across a large installed population, so the holding is a percentage of the installed base, floored at a minimum that covers a cluster failure.

MethodHold = installed base × annual failure rate × replenishment lead time in years × safety factor 2, subject to a stated floor per part type.
Worked example — opticsManufacturers publish an annual failure rate of roughly 0.5% to 1% for high-speed transceivers. On a fabric of the order of 30,000 endpoints at 1%, that is around 300 failures a year, or about 25 a month. Against an 8-week replenishment lead time and a safety factor of 2, the holding works to ≈ 2% of installed base per optic type. Per-type matters more than the total: a 2% holding of the wrong wavelength is a zero holding.
Worked example — NVMeEnterprise NVMe annualised failure rates sit around 0.4% to 0.7%. The floor rather than the percentage governs here, because a batch fault can present as several simultaneous failures — hence a minimum of 12 per capacity and interface type regardless of population.
Safety factorThe factor of 2 is deliberate and covers the two things the arithmetic does not: infant mortality in the first year, and a replenishment order that is itself delayed.
4.2 Wear and consumable items

Filters, seals, coolant, gaskets, batteries, fuel filters. These fail predictably against hours run or service interval, so the holding is one full service set plus one: enough to complete the next scheduled service and to deal with an unplanned replacement before the next order lands.

MethodHold = one complete set for the next scheduled service interval, plus one spare set. Tied directly to the preventive maintenance schedule and to the relevant MOP.
CoolantTreated as a special case. Held volume covers the largest single secondary loop plus 10%, so that one loop can be drained and refilled without waiting on delivery. Coolant has a shelf life and is rotated under 9.3.
4.3 Single-unit critical items

Control cards, PLC modules, protection relays, static switches, pumps. These are one-off items whose failure removes redundancy immediately. The arithmetic is not statistical.

MethodHold one per distinct part number in service, irrespective of how many are installed — a second is held only where the same part appears in more than four positions, or where the item has a history of consecutive failure.
ReasoningThe failure is rare, but the exposure window is zero or short and the lead time is almost always Band B. One on the shelf converts a multi-week exposure into a same-shift repair, and that single unit is the highest-value line in the entire register per riyal held.
Firming upEvery quantity below is indicative against the design. Part numbers, exact port counts by optic type, rack layout and the number of distinct control-card variants are fixed at the equipment order, and the register is reissued at version 1.0 at that point. The first physical count is taken against commissioning gate L3.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled05 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 06 / 19
05Register — electricalUPS and generation

The electrical chain carries the shortest exposure windows in the Facility, because a single failure here can take redundancy to zero in one step. Holdings are correspondingly conservative.

ItemClassHoldLeadWhy it is on the list
Uninterruptible power supply
UPS power modulePer installed frame typeS11Band BLoss of one module takes the string from N+1 to N. Module swap is a same-shift MOP; the wait for one is six to ten weeks.
UPS control and logic cardEach distinct card variantS11 eaBand BSingle-unit critical. A failed logic card can force a transfer to bypass, removing battery protection entirely until replaced.
UPS static switch assemblyPer frame typeS11Band BZero exposure window — the load has no protected path while the static switch is out.
UPS battery blockSame make, model and date bandS18Band BBlocks fail individually; one bad block impairs the whole string. Held to the largest string, and rotated on age under 9.3.
Battery monitoring modulePer systemS21Band AIts failure does not affect the load, but the string is unmonitored, so the next block failure would be invisible.
Standby generation
Starter battery setPer generatorS11 setBand AThe single most common cause of a generator failing to start on demand. Cheap, and its absence would be indefensible.
AVR and governor control modulePer generator typeS11 eaBand BSingle-unit critical. Generator will not accept load without it, and the set is the only supply during a utility failure.
Fuel filter and separator setPer generator, per serviceS12 setsBand AConsumable on the service interval; also the first item replaced after a fuel-quality event.
Fuel injector setPer engine typeS21Band BManufacturer holds in-region under contract. Failure is rare and the set is a workshop-level repair, not a shift task.
Fuel transfer and polishing pumpPer systemS11Band BWithout transfer the day tank is not replenished, capping autonomy at the tank rather than the bulk store.
Coolant and lubricantPer engine specificationS11 changeBand ARequired after any extended run and before return to standby. Held per engine.
Note on battery date bandsReplacement blocks are held from the same manufacturing date band as the installed string wherever possible. Mixing a new block into an aged string loads it unevenly and shortens the life of both — which is why the holding is rotated rather than simply kept.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled06 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 07 / 19
05Register — electrical, continuedDistribution and metering
ItemClassHoldLeadWhy it is on the list
Switchgear and distribution
Air circuit breakerEach frame size in serviceS11 eaBand BSingle-unit critical. Racking in a spare restores the path within the shift; ordering one is a two to three month exposure.
Moulded case circuit breakerAcross the ranges in serviceS16Band APopulation item at the distribution level. Held as a small pool rather than per position.
Protection relayEach distinct modelS11 eaBand BIts failure either trips spuriously or fails to trip. Both are unacceptable, and settings must be reloaded from the register under change control.
Current transformerPer ratio in serviceS12 eaBand AMetering and protection both depend on it. Cheap, small, and its absence would stall a protection repair.
Automatic transfer switch control modulePer switch typeS11Band BZero exposure window on a utility failure — no automatic transfer without it. Manual transfer is possible but is not what the design commits to.
Busway tap-off unitPer rating in serviceS12 eaBand BRequired for any rack addition or replacement, and the only route to restoring a failed rack feed.
Rack PDU, completePer model in serviceS14Band BA/B design means one PDU failure does not drop the rack, but the rack then has a single feed. Pool sized to the largest hall.
Rack PDU controller cardPer modelS12Band ALoses metering and remote switching while the outlets keep working — visibility is part of the service.
ATS and switchgear auxiliary contacts, coilsAssortedS11 setBand ASmall parts that stop a repair completing. Held as a kit rather than itemised.
Metering and monitoring
EPMS meterPer modelS11Band BPower reporting to the customer depends on it, and the availability calculation is drawn from it.
Monitoring gateway or protocol converterPer typeS11Band AIts loss blinds the BMS to a whole subsystem while leaving the plant running — an unmonitored plant is treated as a degraded plant.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled07 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 08 / 19
05Register — electrical, continuedMajor plant

Three electrical items are large enough, and long enough on lead time, that holding them would be capital tied up against a risk the topology already manages. Each is named here rather than quietly omitted, with the exposure that results from not stocking it stated on the line.

ItemClassHoldLeadWhy it is on the list
Major plant — deliberately not stocked
Distribution transformerS40Band CNot stocked. 26 to 52 weeks and a capital item. Mitigation is N+1 at the transformer level: one unit lost degrades protection, service continues. Exposure is stated and accepted.
Switchgear section or cubicleS40Band CNot stocked. Replacement is a project with an outage plan. Component-level spares above cover everything repairable in the field.
UPS frame, completeS40Band CNot stocked. Module-level and card-level spares cover field repair; a whole-frame loss is carried by the parallel frame.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled08 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 09 / 19
06Register — mechanical and coolingLiquid loop

Direct liquid cooling changes the spares picture materially against an air-cooled facility. The secondary loop sits inside the hall, at the rack, so a proportion of the register is wet parts in the same room as the compute — and thermal ride-through at these densities is measured in seconds, not minutes.

ItemClassHoldLeadWhy it is on the list
Coolant distribution units
CDU circulation pumpPer CDU modelS11Band BZero to short exposure window. Pump loss on a loop drops flow to the racks it serves; the design carries a standby pump, so one failure removes that protection.
Pump seal and gasket kitPer pump modelS12 eaBand AWear item and the most common wet-side repair. A seal failure is also a leak, so speed matters twice.
CDU controller or PLC modulePer modelS11Band BSingle-unit critical. Without control the CDU cannot modulate to load, and flow is either fixed or lost.
Temperature and pressure transmitterPer type in serviceS13 eaBand AControl and protection both read from these. A failed transmitter can drive the CDU to a wrong setpoint, which is worse than losing it outright.
Motorised control valvePer size and typeS11 eaBand BIts failure fixes the loop at one position — either starving racks of flow or over-cooling with no ability to trim.
Coolant filter cartridgePer CDUS12 setsBand AConsumable on interval. Also replaced after any loop intervention, so consumption is higher than the schedule alone suggests.
Rack-level wet parts
Quick-disconnect couplingPer rack loop typeS112Band BHigh population, inside the hall, and the interface handled every time a node is removed. Wear and mishandling both consume these.
Flexible hose assemblyRack supply and returnS18 setsBand BRubber against a pressurised loop above live electronics. Replaced on age as well as on failure, under 9.3.
Cold plate and manifoldPer node generationS14Band BNode-level repair. Without one, a node with a failed cold plate is out of service even though the GPUs are healthy.
Leak detection sensor and cablePer zone typeS12 eaBand AThe control that makes a leak survivable rather than catastrophic. Its own failure must never be the reason detection was late.
Coolant
Technology cooling system fluidApproved specification onlyS11 loop +10%Band BEnough to drain and refill the largest single secondary loop without waiting on delivery. Shelf life managed under 9.3.
Water treatment chemistryPer specificationS11 intervalBand ALoop chemistry out of specification corrodes cold plates from the inside — a slow failure with an expensive ending.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled09 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 10 / 19
06Register — mechanical and cooling, continuedPlant and air side
ItemClassHoldLeadWhy it is on the list
Chilled water plant
Chiller controller boardPer chiller modelS11Band BSingle-unit critical. A chiller without control is a chiller out of service, and the plant is then running on the remaining units.
Chiller sensor and transducer setPer modelS11 setBand ASmall parts that hold a unit offline for weeks if not to hand. Held as a kit.
Primary circulation pumpPer dutyS21Band BManufacturer holds in-region. Standby pump carries the duty, giving a window measured in days rather than hours.
Pump seal kit, primaryPer pump modelS12 eaBand AWear item on the service interval.
Isolation and balancing valvePer sizeS11 eaBand BNeeded to isolate a failed unit without draining the system. Its absence turns a unit repair into a plant shutdown.
Make-up water pumpPer systemS11Band BWithout make-up, evaporative losses reduce system volume until level protection trips the plant.
Dry cooler fan motorPer modelS12Band BPopulation item across many fans. Heat rejection degrades progressively as fans fail, so the pool is sized to allow a run of failures.
Air side and hall environment
CRAH EC fan modulePer unit typeS13Band BPopulation item. Fans are the most-replaced part in any air-side unit, and each loss reduces unit capacity rather than stopping it.
CRAH filter setPer unitS12 setsBand AConsumable on interval. Also replaced after any construction or hot-work activity in the hall.
Humidity and temperature sensorPer hall zoneS14Band AThe ASHRAE envelope commitment in PRM-SLA-2026-001 is measured from these. A drifting sensor is a compliance problem as well as a control problem.
Condensate pumpPer unitS12Band ACheap; its failure puts water on a floor above live electrical distribution.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled10 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 11 / 19
06Register — mechanical and cooling, continuedMajor plant

Three thermal items are large enough, and long enough on lead time, that holding them would be capital against a risk the topology already manages. Each is named rather than omitted, with the resulting exposure stated.

ItemClassHoldLeadWhy it is on the list
Major plant — deliberately not stocked
Chiller compressorS40Band CNot stocked. 20 to 40 weeks, and a workshop rebuild rather than a field swap. N+1 at plant level carries the load; the exposure is stated and accepted.
CDU heat exchanger plate packS40Band CNot stocked. Long lead and unit-specific. Loop-level redundancy carries the racks while a replacement is procured.
Chiller, complete unitS40Band CNot stocked. Replacement is a capital project with a lifting and outage plan. Component spares above cover all field-repairable failures.
The liquid-cooling exceptionWet parts are the one category where the register is deliberately over-stocked against pure statistics. The reason is not failure rate but consequence: a leak inside a hall at these densities is simultaneously a thermal event, an electrical hazard and a customer-visible incident. Holding twice the modelled quantity of couplings, hoses and seals is cheap against that.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled11 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 12 / 19
07Register — network fabric and compute platformPopulation items

This is where the percentage method at 4.1 does the work. Quantities scale with the installed base of 1,728 nodes and 13,824 GPUs and are held per type — a correct total made up of the wrong variants is a zero holding.

ItemClassHoldLeadWhy it is on the list
Network fabric
Optical transceiverPer speed, reach and connector typeS1≥ 2% eaBand BThe highest-consumption item in the Facility. Worked in 4.1: ~1% annual failure rate against an 8-week replenishment, doubled for safety. Held per type without exception.
Direct-attach and active optical cablePer length and speedS1≥ 2% eaBand BSame failure profile as optics, and the cable is handled during every node intervention.
Fibre patch cord and MPO trunkPer type and lengthS120 eaBand AConsumed by moves and additions as much as by failure. Cheap, and their absence stops a repair completing.
Leaf switch, completePer modelS11Band BSingle-unit critical at the rack. A leaf loss takes its rack off the fabric; the design tolerates it, but only until the next failure.
Spine switch line cardPer modelS11Band BSpine capacity degrades with each card lost. Replacement is a hot operation under an approved MOP.
Switch power supply unitPer chassis typeS14Band APopulation item across the fabric. Dual-PSU design means one loss is survivable, so the pool covers a run of failures.
Switch fan trayPer chassis typeS13Band AThermal protection will throttle or shut a switch down on fan loss, converting a cooling fault into a fabric fault.
Management and out-of-band switchPer modelS11Band ALoss of out-of-band access means remote hands become physical hands. Small, cheap, disproportionately valuable.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled12 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 13 / 19
07Register — compute platform1,728 nodes

Quantities scale with the installed base of 1,728 eight-GPU nodes. Nodes themselves are Band C on new supply, which is why a cold spare exists at all — it is the only route to restoring capacity inside a month while the failed unit goes to RMA.

ItemClassHoldLeadWhy it is on the list
Compute platform
GPU node, completeCold spare, per configurationS18Band CRoughly 0.5% of the installed base. Nodes are Band C on new supply, so a cold spare is the only route to restoring capacity inside a month while the failed unit goes to RMA.
Node power supply unitPer node typeS112Band BPopulation item, dual-PSU per node. Consumption is predictable and replacement is a shift-level task.
Node fan modulePer node typeS116Band AHighest-count moving part in the compute estate, even in a liquid-cooled design.
NVMe drivePer capacity and interfaceS112 eaBand BFloor rather than percentage governs, per 4.1 — a batch fault presents as several failures at once.
Memory modulePer type and capacityS116Band BCorrectable errors accumulate before hard failure, so replacement is often planned. Held to allow a rolling replacement without an order.
Network interface cardPer node typeS16Band BA failed NIC removes a node from the fabric while leaving it powered and apparently healthy.
Storage node drivePer tier and typeS18 eaBand BStorage rebuild time is the exposure. Holding covers a concurrent multi-drive failure in one array.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled13 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 14 / 19
08Register — life safety, security and controls

Nothing in this section carries load, and every line still passes Test 1. These are the systems that make a failure survivable and an access decision auditable — their loss does not stop the Facility, it stops the Facility being defensible.

ItemClassHoldLeadWhy it is on the list
Fire detection and suppression
Aspirating smoke detector headPer hall zoneS12Band BEarly detection is the whole basis of the fire strategy. A blind zone is an unprotected zone and is treated as a reportable condition.
Point detector and sounderPer typeS14 eaBand APopulation items across the building. Held as a pool.
Fire panel loop cardPer panel typeS11Band BSingle-unit critical. A failed loop card takes a whole detection circuit out at once.
Suppression release actuatorPer system typeS11Band BReplaced after every discharge and after every commissioning exercise in which release is tested to the point of actuation.
Suppression agent cylinderPer zoneS21 zoneBand BRefill and recertification are specialist and regulated. Contracted in-region hold rather than stored on site.
Security and access control
Door controller boardPer modelS11Band BSingle-unit critical. Its failure takes a group of doors to their fail-safe or fail-secure state, and either is a departure from the access design in PRM-SEC-2026-001.
Card and biometric readerPer layer and modelS12 eaBand BMulti-factor at each layer means a failed reader can block a legitimate entry or force a documented override — both are audit events.
CCTV cameraPer model and mount typeS14Band BThe 90-day retention commitment presumes every camera is recording. A dark camera is a gap in the record.
Recorder storage drivePer array typeS14Band BRetention depends on array health. A degraded array silently shortens the retention period.
Turnstile or portal control modulePer portalS11Band BA failed portal forces manual admission with escort, which is workable but consumes officer time and creates exceptions.
Intercom and duress stationPer typeS12Band ALife-safety adjacent. Cheap, and absence would be a finding in any audit.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled14 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 15 / 19
08Register — building and power management controlsControl layer

The control layer does not carry load and does not cool anything. What it does is make the plant visible and automatic — and every line here fails in the same way, by leaving the plant running while nobody can see or sequence it.

ItemClassHoldLeadWhy it is on the list
Building and power management controls
BMS or EPMS input-output modulePer module typeS12 eaBand BLoses visibility and automatic control of a plant group while the plant keeps running — an unmonitored plant is a degraded plant.
BMS controllerPer controller typeS11Band BSingle-unit critical. Sequencing, lead-lag rotation and alarm logic all sit here.
Network gateway and protocol converterPer typeS11 eaBand AA single converter failure can orphan an entire subsystem from the control layer.
Uninterruptible supply for controlsPer panelS11Band AControls must survive the transfer they are supposed to manage. Frequently overlooked, which is exactly why it is listed.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled15 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 16 / 19
09Storage, handling, rotation and shelf life

A part that is on site but degraded, uncalibrated or unfindable at three in the morning is not a spare. This section covers the conditions the store must hold and the disciplines that keep the stock genuinely usable.

9.1 The store
Location and accessA dedicated, access-controlled room inside the building envelope, at Layer 3 of the access model in PRM-SEC-2026-001. Reachable without passing through a data hall, so that a fetch during an incident does not add a hall entry.
EnvironmentTemperature and humidity controlled to the manufacturers' storage specifications, monitored by the BMS and alarmed. Electronics are stored inside the ASHRAE storage envelope, not merely inside the building.
Electrostatic protectionESD-protected area with grounded benching and wrist-strap points. All boards and cards remain in their original static shielding until the point of fitting.
Layout and labellingFixed locations by discipline, each bin labelled with the part reference, the holding level and the reorder point. A part found in the wrong bin is treated as a stock error and recorded.
Wet parts and fluidsBunded storage for coolant and chemistry, separated from electronics, with spill containment and the relevant safety data sheets held at the point of storage.
FindabilityThe location of every line is in the asset system and printed on the store plan at the door. The test applied is whether the engineer on shift can find it without calling anyone.
9.2 Issue and return
  1. Every issue is recorded against the work order or incident that consumed it, under PRM-SOP-OPS-009. An unrecorded issue is how a register silently becomes fiction.
  2. Reorder is triggered on issue, not on the next stock take. The replenishment order is raised the same business day.
  3. A part removed as suspect is quarantined, not returned to stock. Suspect parts are tagged, segregated and either tested or sent to RMA — never put back on the shelf.
  4. Serial numbers are recorded both ways. The part fitted and the part removed are both logged against the asset, so warranty and failure history follow the equipment rather than the paperwork.
  5. Emergency issue outside hours is permitted to any Shift Lead without prior approval; the record is completed within the shift. Access to a spare is never the thing that delays a repair.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled16 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 17 / 19
09Storage, handling, rotation and shelf life, continuedRotation
9.3 Shelf life and rotation
ItemIntervalAction
UPS battery blocksAnnuallyCharged and tested; rotated into the installed string and replaced in stock, so the shelf holding is never older than the string it serves.
Generator starter batteries6 monthsCharged and load-tested. Replaced at 80% of rated capacity rather than on failure.
Coolant and chemistryPer specificationRotated first-in first-out against the manufacturer's shelf life. Expired fluid is disposed of under the environmental consignment procedure, never used.
Flexible hoses and elastomer seals3 years in stockReplaced on age whether used or not. Rubber ages on a shelf as well as in service.
Test and calibration instrumentsAnnuallyCalibrated to a traceable standard. An uncalibrated instrument invalidates any test result it produced — including commissioning results.
Firmware on stocked sparesOn every plant updateStocked cards and switches are brought to the installed firmware revision. A spare at the wrong revision can fail to join the system it was held for.
The firmware trapThe most common way a correctly stocked spare fails at the moment of use is revision mismatch. A control card two firmware versions behind the plant may refuse to communicate, and the engineer discovers it mid-repair with redundancy already gone. Bringing stock to revision is therefore part of every plant update MOP, not a separate task.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled17 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 18 / 19
10Replenishment, obsolescence, governance and measures
10.1 Replenishment
Reorder pointSet at minimum level plus expected consumption over the replenishment lead time. For single-unit items the reorder point is one — the order is raised the moment the shelf goes empty.
TriggerAutomatic on issue. The asset system raises the requisition; the Facilities Manager approves within one business day.
ExpediteWhere the issue has taken redundancy to zero, the replenishment is expedited on the COO's authority and the exposure is reported daily until closed.
Below minimumAny line below its minimum is a reportable condition, listed in the monthly operations report with the date it is expected to be back in stock. It is not carried silently.
Supplier concentrationReviewed annually. Where a Band B or C line has a single source with no in-region alternative, that concentration is recorded as a risk with the mitigation stated — dual sourcing where the part allows it, a higher holding where it does not.
10.2 Consumption review

The register is a model until it meets reality. Consumption is reviewed quarterly against the assumptions in section 04, and the model is corrected rather than defended.

  • Consumed more than modelled — the holding is raised and the failure rate assumption revised. Repeat consumption of the same part triggers a root-cause review under PRM-IRP-2026-001, because a part failing twice is usually a symptom rather than a fault.
  • Untouched for three years — reviewed for de-listing, unless it is a single-unit critical item, where a zero consumption rate is the expected and desirable outcome.
  • Consumed and not replaced within lead time — recorded as a supply failure against the supplier, and considered at the annual sourcing review.
10.3 Obsolescence
On an end-of-life noticeThe Facilities Manager assesses remaining life of the installed population against the last-buy date, and either places a final buy sized to that remaining life or qualifies a successor part.
Final buy sizingInstalled population multiplied by the expected annual failure rate, multiplied by remaining service life in years, plus the standing holding. Documented and approved by the COO because it is capital held against a closing window.
Successor qualificationA replacement part is not accepted on a datasheet. It is fitted, commissioned and tested against the affected MOP before the original is de-listed.
Register effectBoth parts appear on the register during transition, with the transition period stated, so that a reviewer sees two variants rather than an unexplained duplicate.
10.4 Governance
Register ownerFacilities Manager. Owns the criticality assessment, the holding levels and the store. Approves replenishment.
Platform scopeEngineering Manager owns the fabric and compute lines at section 07, under the same method and the same store.
Approval of the policyCOO. Approves this document, any final buy, and any decision to accept an exposure rather than hold a part.
AuditPhysical stock take quarterly, full reconciliation annually. Discrepancy between record and shelf is a finding with a named owner, not a correction.
ReviewAnnually, and on any change to the plant, the topology or the supply position. Recorded even where nothing changes.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled18 / 19
DRAFT
PRIMA
Critical Spares & Spare Parts PolicyPRM-SPR-2026-001 · 19 / 19
10Replenishment, obsolescence, governance and measures, continuedMeasures
10.5 Measures

Reported to the COO on the cadence shown, and to customers and lenders on request. Fill rate is the measure that matters most: it states how often the shelf answered the question it exists to answer.

MeasureTargetReported
Fill rate — demand met from stock on first request≥ 98%Monthly
Class S1 lines at or above minimum level100%Monthly
Time from failure to part in hand, class S1≤ 4 hoursMonthly
Replenishment orders raised within one business day of issue≥ 95%Monthly
Stock-take discrepancies, by line0Quarterly
Stocked spares at the installed firmware revision100%Quarterly
Shelf-life items within date100%Quarterly
Repairs extended by absence of a spare0Monthly
Class S2 contracted response times testedAnnually, allAnnually
10.6 What is still open on this register

Stated plainly so that a reviewer is not left to infer it.

  • Quantities are indicative against the design basis, and become firm at the equipment order when part numbers, port counts by optic type and rack layout are fixed. The register is reissued at version 1.0 at that point.
  • No stock exists yet. First procurement is scheduled against the L2 and L3 commissioning gates in PRM-CDP-2026-001, so that spares are on site before the plant they protect is carrying anything.
  • Class S2 lines depend on contracts not yet placed. Each in-region holding obligation must be written into the relevant supply or maintenance agreement; until it is, those lines carry the published lead time and not the contracted response.
  • Preventive maintenance completion rates — the other half of the diligence line this register answers — require operating history and will first exist twelve months after service commences. They cannot be produced now by any means.
RelatedPRM-OPS-2026-001 · PRM-CDP-2026-001 · PRM-IRP-2026-001 · PRM-SLA-2026-001 · PRM-DEM-2026-001 · PRM-SEC-2026-001 · PRM-HR-2026-001.
Office of the Facilities Manager

For the current holding level of any line, the criticality assessment behind it, the store plan, or the stock-take and fill-rate record once operations commence.

info@primasecurity.ai
primacompute.com
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled19 / 19