
The criticality method that decides what qualifies as a critical spare, the stocking classes and holding levels, the register by discipline, and the storage, replenishment and obsolescence regime behind it. Written against the installed design for 13,824 GPUs at Knowledge Oasis Muscat.

Redundancy buys time; it does not repair anything. When one half of an N+1 pair fails, the Facility is running without protection and stays that way until the part is replaced. The interval between the failure and the replacement is the real exposure, and it is set almost entirely by whether the part is on the shelf.
This document therefore does two things. It defines the method by which a part is judged critical — so that the list is defensible rather than a collection of opinions — and it sets out the register itself, with the holding level for each line and the reasoning behind it.
The KOM Oman AI Factory at Knowledge Oasis Muscat: the electrical chain from utility intake to rack, the cooling plant and secondary loops, the network fabric, the compute platform, fire detection and suppression, the security estate, and the BMS and EPMS control layer. Design basis is 13,824 GPUs in 1,728 eight-GPU nodes, direct liquid cooled, at a 37.5 MW site allocation, Tier III Standard topology, ready for service December 2026.
The register covers Prima-owned plant and Prima-owned IT. Where a customer owns equipment in the hall under a colocation arrangement, spares for that equipment are the customer's responsibility and sit outside this register — the boundary in each case is the one drawn in PRM-DEM-2026-001. Prima will hold customer-owned spares on request as a chargeable service, under the same storage and handling regime at section 09.
It is not an inventory record, and nothing here should be read as evidence that a part is in stock. No equipment has yet been delivered. Quantities marked indicative are derived from the design basis and manufacturers' published failure data; they become firm at the equipment order, when model numbers, actual port counts and rack layouts are fixed. The first physical stock take is scheduled against gate L3 in the commissioning programme.

A part is critical if it passes any one of three tests. The tests are applied to the part, not to the system it sits in — a cheap relay inside a switchboard can be more critical than the switchboard, because the relay is what actually fails.
Failure of this part interrupts service, or removes a layer of redundancy the availability commitment depends on. A part whose failure is invisible to the load still passes if it takes N+1 down to N.
The lead time to obtain it exceeds the exposure window the design can tolerate — see 3.2. A part available next morning locally is not critical; the same part on a twelve-week import is.
There is no field workaround that restores protection. Where a documented MOP can bypass, re-route or cross-connect around the failure without loss of redundancy, the part may fall out of scope.
Two categories are kept off the register on purpose, because carrying them would be capital held against a risk that is already managed elsewhere.
| Very long-lead major plant | Transformers, main switchgear sections, chiller compressors and CDU plate packs run to 26–52 weeks and cost multiples of the rest of the register combined. These are not stocked. The mitigation is topology: the design carries N+1 at plant level, so a single unit loss degrades protection but not service, and replacement runs as a project rather than a repair. Section 05 and 06 name each of these explicitly rather than omitting them, and state the exposure that results. |
|---|---|
| Parts covered by a contracted response | Where a manufacturer holds a part in-region under a contracted response time shorter than our own exposure window, the part is recorded as class S2 and the contract reference is the control. The obligation is on the contract, not the shelf — but the part still appears on the register, because a reviewer is entitled to see that the decision was made rather than overlooked. |

Every line on the register carries one of four classes. The class states where the part lives and how quickly it can be in an engineer's hands — not how important it is.
| Class | Meaning | Time to part in hand | Control |
|---|---|---|---|
| S1On site | Held in the Facility spares store, on the same site as the plant. The default for anything that passes Test 1 and cannot be worked around. | Under 4 hours, any hour of any day | Physical stock, min/max levels |
| S2In region | Held by the manufacturer or a distributor within the Gulf, under a contracted response obligation. Used where the part is bulky, costly, or has a shelf life shorter than its expected time in stock. | Under 24 hours, contracted | Contract clause, tested annually |
| S3Order on failure | Not stocked. Ordered when it fails, because the design tolerates the wait or the part almost never fails. | Lead time as published | Accepted exposure, stated |
| S4Not stocked — project | Major plant. Replacement is a capital project, not a repair. Redundancy carries the service in the meantime. | 26–52 weeks | N+1 topology |
Bands are used throughout the register in place of specific dates, because a published lead time from a manufacturer is a forecast and not a commitment. The band is what the stocking decision is made against.
The exposure window is the period the design can run without the failed part before the availability commitment is genuinely at risk. It is not a comfort figure; it is derived from what redundancy remains after the failure.
| Zero window | The failure has already interrupted service, or the remaining path is single and unprotected. Part must be on site — class S1, no exceptions, whatever the cost of holding it. |
|---|---|
| Short window — days | Redundancy is degraded from N+1 to N: the load is carried, but a second failure in the same subsystem now interrupts service. Class S1 where the lead time is Band B or C. |
| Long window — weeks | Full designed redundancy remains after the failure, or the function is not in the availability path. Class S2 or S3 is acceptable, and the accepted exposure is stated on the line. |
| How it is applied | Test 2 compares the lead-time band against the window. Band B or C against a zero or short window is always S1. Band A against a long window is always S3. Everything between is a judgement recorded on the line, with the reasoning shown. |

Three different methods produce the quantities in the register, depending on how the part fails. Mixing them would be the common error — a wear part and a random-failure part need different arithmetic.
Optics, drives, fan modules, power supplies. These fail at a roughly constant annual rate across a large installed population, so the holding is a percentage of the installed base, floored at a minimum that covers a cluster failure.
| Method | Hold = installed base × annual failure rate × replenishment lead time in years × safety factor 2, subject to a stated floor per part type. |
|---|---|
| Worked example — optics | Manufacturers publish an annual failure rate of roughly 0.5% to 1% for high-speed transceivers. On a fabric of the order of 30,000 endpoints at 1%, that is around 300 failures a year, or about 25 a month. Against an 8-week replenishment lead time and a safety factor of 2, the holding works to ≈ 2% of installed base per optic type. Per-type matters more than the total: a 2% holding of the wrong wavelength is a zero holding. |
| Worked example — NVMe | Enterprise NVMe annualised failure rates sit around 0.4% to 0.7%. The floor rather than the percentage governs here, because a batch fault can present as several simultaneous failures — hence a minimum of 12 per capacity and interface type regardless of population. |
| Safety factor | The factor of 2 is deliberate and covers the two things the arithmetic does not: infant mortality in the first year, and a replenishment order that is itself delayed. |
Filters, seals, coolant, gaskets, batteries, fuel filters. These fail predictably against hours run or service interval, so the holding is one full service set plus one: enough to complete the next scheduled service and to deal with an unplanned replacement before the next order lands.
| Method | Hold = one complete set for the next scheduled service interval, plus one spare set. Tied directly to the preventive maintenance schedule and to the relevant MOP. |
|---|---|
| Coolant | Treated as a special case. Held volume covers the largest single secondary loop plus 10%, so that one loop can be drained and refilled without waiting on delivery. Coolant has a shelf life and is rotated under 9.3. |
Control cards, PLC modules, protection relays, static switches, pumps. These are one-off items whose failure removes redundancy immediately. The arithmetic is not statistical.
| Method | Hold one per distinct part number in service, irrespective of how many are installed — a second is held only where the same part appears in more than four positions, or where the item has a history of consecutive failure. |
|---|---|
| Reasoning | The failure is rare, but the exposure window is zero or short and the lead time is almost always Band B. One on the shelf converts a multi-week exposure into a same-shift repair, and that single unit is the highest-value line in the entire register per riyal held. |

The electrical chain carries the shortest exposure windows in the Facility, because a single failure here can take redundancy to zero in one step. Holdings are correspondingly conservative.
| Item | Class | Hold | Lead | Why it is on the list |
|---|---|---|---|---|
| Uninterruptible power supply | ||||
| UPS power modulePer installed frame type | S1 | 1 | Band B | Loss of one module takes the string from N+1 to N. Module swap is a same-shift MOP; the wait for one is six to ten weeks. |
| UPS control and logic cardEach distinct card variant | S1 | 1 ea | Band B | Single-unit critical. A failed logic card can force a transfer to bypass, removing battery protection entirely until replaced. |
| UPS static switch assemblyPer frame type | S1 | 1 | Band B | Zero exposure window — the load has no protected path while the static switch is out. |
| UPS battery blockSame make, model and date band | S1 | 8 | Band B | Blocks fail individually; one bad block impairs the whole string. Held to the largest string, and rotated on age under 9.3. |
| Battery monitoring modulePer system | S2 | 1 | Band A | Its failure does not affect the load, but the string is unmonitored, so the next block failure would be invisible. |
| Standby generation | ||||
| Starter battery setPer generator | S1 | 1 set | Band A | The single most common cause of a generator failing to start on demand. Cheap, and its absence would be indefensible. |
| AVR and governor control modulePer generator type | S1 | 1 ea | Band B | Single-unit critical. Generator will not accept load without it, and the set is the only supply during a utility failure. |
| Fuel filter and separator setPer generator, per service | S1 | 2 sets | Band A | Consumable on the service interval; also the first item replaced after a fuel-quality event. |
| Fuel injector setPer engine type | S2 | 1 | Band B | Manufacturer holds in-region under contract. Failure is rare and the set is a workshop-level repair, not a shift task. |
| Fuel transfer and polishing pumpPer system | S1 | 1 | Band B | Without transfer the day tank is not replenished, capping autonomy at the tank rather than the bulk store. |
| Coolant and lubricantPer engine specification | S1 | 1 change | Band A | Required after any extended run and before return to standby. Held per engine. |

| Item | Class | Hold | Lead | Why it is on the list |
|---|---|---|---|---|
| Switchgear and distribution | ||||
| Air circuit breakerEach frame size in service | S1 | 1 ea | Band B | Single-unit critical. Racking in a spare restores the path within the shift; ordering one is a two to three month exposure. |
| Moulded case circuit breakerAcross the ranges in service | S1 | 6 | Band A | Population item at the distribution level. Held as a small pool rather than per position. |
| Protection relayEach distinct model | S1 | 1 ea | Band B | Its failure either trips spuriously or fails to trip. Both are unacceptable, and settings must be reloaded from the register under change control. |
| Current transformerPer ratio in service | S1 | 2 ea | Band A | Metering and protection both depend on it. Cheap, small, and its absence would stall a protection repair. |
| Automatic transfer switch control modulePer switch type | S1 | 1 | Band B | Zero exposure window on a utility failure — no automatic transfer without it. Manual transfer is possible but is not what the design commits to. |
| Busway tap-off unitPer rating in service | S1 | 2 ea | Band B | Required for any rack addition or replacement, and the only route to restoring a failed rack feed. |
| Rack PDU, completePer model in service | S1 | 4 | Band B | A/B design means one PDU failure does not drop the rack, but the rack then has a single feed. Pool sized to the largest hall. |
| Rack PDU controller cardPer model | S1 | 2 | Band A | Loses metering and remote switching while the outlets keep working — visibility is part of the service. |
| ATS and switchgear auxiliary contacts, coilsAssorted | S1 | 1 set | Band A | Small parts that stop a repair completing. Held as a kit rather than itemised. |
| Metering and monitoring | ||||
| EPMS meterPer model | S1 | 1 | Band B | Power reporting to the customer depends on it, and the availability calculation is drawn from it. |
| Monitoring gateway or protocol converterPer type | S1 | 1 | Band A | Its loss blinds the BMS to a whole subsystem while leaving the plant running — an unmonitored plant is treated as a degraded plant. |

Three electrical items are large enough, and long enough on lead time, that holding them would be capital tied up against a risk the topology already manages. Each is named here rather than quietly omitted, with the exposure that results from not stocking it stated on the line.
| Item | Class | Hold | Lead | Why it is on the list |
|---|---|---|---|---|
| Major plant — deliberately not stocked | ||||
| Distribution transformer— | S4 | 0 | Band C | Not stocked. 26 to 52 weeks and a capital item. Mitigation is N+1 at the transformer level: one unit lost degrades protection, service continues. Exposure is stated and accepted. |
| Switchgear section or cubicle— | S4 | 0 | Band C | Not stocked. Replacement is a project with an outage plan. Component-level spares above cover everything repairable in the field. |
| UPS frame, complete— | S4 | 0 | Band C | Not stocked. Module-level and card-level spares cover field repair; a whole-frame loss is carried by the parallel frame. |

Direct liquid cooling changes the spares picture materially against an air-cooled facility. The secondary loop sits inside the hall, at the rack, so a proportion of the register is wet parts in the same room as the compute — and thermal ride-through at these densities is measured in seconds, not minutes.
| Item | Class | Hold | Lead | Why it is on the list |
|---|---|---|---|---|
| Coolant distribution units | ||||
| CDU circulation pumpPer CDU model | S1 | 1 | Band B | Zero to short exposure window. Pump loss on a loop drops flow to the racks it serves; the design carries a standby pump, so one failure removes that protection. |
| Pump seal and gasket kitPer pump model | S1 | 2 ea | Band A | Wear item and the most common wet-side repair. A seal failure is also a leak, so speed matters twice. |
| CDU controller or PLC modulePer model | S1 | 1 | Band B | Single-unit critical. Without control the CDU cannot modulate to load, and flow is either fixed or lost. |
| Temperature and pressure transmitterPer type in service | S1 | 3 ea | Band A | Control and protection both read from these. A failed transmitter can drive the CDU to a wrong setpoint, which is worse than losing it outright. |
| Motorised control valvePer size and type | S1 | 1 ea | Band B | Its failure fixes the loop at one position — either starving racks of flow or over-cooling with no ability to trim. |
| Coolant filter cartridgePer CDU | S1 | 2 sets | Band A | Consumable on interval. Also replaced after any loop intervention, so consumption is higher than the schedule alone suggests. |
| Rack-level wet parts | ||||
| Quick-disconnect couplingPer rack loop type | S1 | 12 | Band B | High population, inside the hall, and the interface handled every time a node is removed. Wear and mishandling both consume these. |
| Flexible hose assemblyRack supply and return | S1 | 8 sets | Band B | Rubber against a pressurised loop above live electronics. Replaced on age as well as on failure, under 9.3. |
| Cold plate and manifoldPer node generation | S1 | 4 | Band B | Node-level repair. Without one, a node with a failed cold plate is out of service even though the GPUs are healthy. |
| Leak detection sensor and cablePer zone type | S1 | 2 ea | Band A | The control that makes a leak survivable rather than catastrophic. Its own failure must never be the reason detection was late. |
| Coolant | ||||
| Technology cooling system fluidApproved specification only | S1 | 1 loop +10% | Band B | Enough to drain and refill the largest single secondary loop without waiting on delivery. Shelf life managed under 9.3. |
| Water treatment chemistryPer specification | S1 | 1 interval | Band A | Loop chemistry out of specification corrodes cold plates from the inside — a slow failure with an expensive ending. |

| Item | Class | Hold | Lead | Why it is on the list |
|---|---|---|---|---|
| Chilled water plant | ||||
| Chiller controller boardPer chiller model | S1 | 1 | Band B | Single-unit critical. A chiller without control is a chiller out of service, and the plant is then running on the remaining units. |
| Chiller sensor and transducer setPer model | S1 | 1 set | Band A | Small parts that hold a unit offline for weeks if not to hand. Held as a kit. |
| Primary circulation pumpPer duty | S2 | 1 | Band B | Manufacturer holds in-region. Standby pump carries the duty, giving a window measured in days rather than hours. |
| Pump seal kit, primaryPer pump model | S1 | 2 ea | Band A | Wear item on the service interval. |
| Isolation and balancing valvePer size | S1 | 1 ea | Band B | Needed to isolate a failed unit without draining the system. Its absence turns a unit repair into a plant shutdown. |
| Make-up water pumpPer system | S1 | 1 | Band B | Without make-up, evaporative losses reduce system volume until level protection trips the plant. |
| Dry cooler fan motorPer model | S1 | 2 | Band B | Population item across many fans. Heat rejection degrades progressively as fans fail, so the pool is sized to allow a run of failures. |
| Air side and hall environment | ||||
| CRAH EC fan modulePer unit type | S1 | 3 | Band B | Population item. Fans are the most-replaced part in any air-side unit, and each loss reduces unit capacity rather than stopping it. |
| CRAH filter setPer unit | S1 | 2 sets | Band A | Consumable on interval. Also replaced after any construction or hot-work activity in the hall. |
| Humidity and temperature sensorPer hall zone | S1 | 4 | Band A | The ASHRAE envelope commitment in PRM-SLA-2026-001 is measured from these. A drifting sensor is a compliance problem as well as a control problem. |
| Condensate pumpPer unit | S1 | 2 | Band A | Cheap; its failure puts water on a floor above live electrical distribution. |

Three thermal items are large enough, and long enough on lead time, that holding them would be capital against a risk the topology already manages. Each is named rather than omitted, with the resulting exposure stated.
| Item | Class | Hold | Lead | Why it is on the list |
|---|---|---|---|---|
| Major plant — deliberately not stocked | ||||
| Chiller compressor— | S4 | 0 | Band C | Not stocked. 20 to 40 weeks, and a workshop rebuild rather than a field swap. N+1 at plant level carries the load; the exposure is stated and accepted. |
| CDU heat exchanger plate pack— | S4 | 0 | Band C | Not stocked. Long lead and unit-specific. Loop-level redundancy carries the racks while a replacement is procured. |
| Chiller, complete unit— | S4 | 0 | Band C | Not stocked. Replacement is a capital project with a lifting and outage plan. Component spares above cover all field-repairable failures. |

This is where the percentage method at 4.1 does the work. Quantities scale with the installed base of 1,728 nodes and 13,824 GPUs and are held per type — a correct total made up of the wrong variants is a zero holding.
| Item | Class | Hold | Lead | Why it is on the list |
|---|---|---|---|---|
| Network fabric | ||||
| Optical transceiverPer speed, reach and connector type | S1 | ≥ 2% ea | Band B | The highest-consumption item in the Facility. Worked in 4.1: ~1% annual failure rate against an 8-week replenishment, doubled for safety. Held per type without exception. |
| Direct-attach and active optical cablePer length and speed | S1 | ≥ 2% ea | Band B | Same failure profile as optics, and the cable is handled during every node intervention. |
| Fibre patch cord and MPO trunkPer type and length | S1 | 20 ea | Band A | Consumed by moves and additions as much as by failure. Cheap, and their absence stops a repair completing. |
| Leaf switch, completePer model | S1 | 1 | Band B | Single-unit critical at the rack. A leaf loss takes its rack off the fabric; the design tolerates it, but only until the next failure. |
| Spine switch line cardPer model | S1 | 1 | Band B | Spine capacity degrades with each card lost. Replacement is a hot operation under an approved MOP. |
| Switch power supply unitPer chassis type | S1 | 4 | Band A | Population item across the fabric. Dual-PSU design means one loss is survivable, so the pool covers a run of failures. |
| Switch fan trayPer chassis type | S1 | 3 | Band A | Thermal protection will throttle or shut a switch down on fan loss, converting a cooling fault into a fabric fault. |
| Management and out-of-band switchPer model | S1 | 1 | Band A | Loss of out-of-band access means remote hands become physical hands. Small, cheap, disproportionately valuable. |

Quantities scale with the installed base of 1,728 eight-GPU nodes. Nodes themselves are Band C on new supply, which is why a cold spare exists at all — it is the only route to restoring capacity inside a month while the failed unit goes to RMA.
| Item | Class | Hold | Lead | Why it is on the list |
|---|---|---|---|---|
| Compute platform | ||||
| GPU node, completeCold spare, per configuration | S1 | 8 | Band C | Roughly 0.5% of the installed base. Nodes are Band C on new supply, so a cold spare is the only route to restoring capacity inside a month while the failed unit goes to RMA. |
| Node power supply unitPer node type | S1 | 12 | Band B | Population item, dual-PSU per node. Consumption is predictable and replacement is a shift-level task. |
| Node fan modulePer node type | S1 | 16 | Band A | Highest-count moving part in the compute estate, even in a liquid-cooled design. |
| NVMe drivePer capacity and interface | S1 | 12 ea | Band B | Floor rather than percentage governs, per 4.1 — a batch fault presents as several failures at once. |
| Memory modulePer type and capacity | S1 | 16 | Band B | Correctable errors accumulate before hard failure, so replacement is often planned. Held to allow a rolling replacement without an order. |
| Network interface cardPer node type | S1 | 6 | Band B | A failed NIC removes a node from the fabric while leaving it powered and apparently healthy. |
| Storage node drivePer tier and type | S1 | 8 ea | Band B | Storage rebuild time is the exposure. Holding covers a concurrent multi-drive failure in one array. |

Nothing in this section carries load, and every line still passes Test 1. These are the systems that make a failure survivable and an access decision auditable — their loss does not stop the Facility, it stops the Facility being defensible.
| Item | Class | Hold | Lead | Why it is on the list |
|---|---|---|---|---|
| Fire detection and suppression | ||||
| Aspirating smoke detector headPer hall zone | S1 | 2 | Band B | Early detection is the whole basis of the fire strategy. A blind zone is an unprotected zone and is treated as a reportable condition. |
| Point detector and sounderPer type | S1 | 4 ea | Band A | Population items across the building. Held as a pool. |
| Fire panel loop cardPer panel type | S1 | 1 | Band B | Single-unit critical. A failed loop card takes a whole detection circuit out at once. |
| Suppression release actuatorPer system type | S1 | 1 | Band B | Replaced after every discharge and after every commissioning exercise in which release is tested to the point of actuation. |
| Suppression agent cylinderPer zone | S2 | 1 zone | Band B | Refill and recertification are specialist and regulated. Contracted in-region hold rather than stored on site. |
| Security and access control | ||||
| Door controller boardPer model | S1 | 1 | Band B | Single-unit critical. Its failure takes a group of doors to their fail-safe or fail-secure state, and either is a departure from the access design in PRM-SEC-2026-001. |
| Card and biometric readerPer layer and model | S1 | 2 ea | Band B | Multi-factor at each layer means a failed reader can block a legitimate entry or force a documented override — both are audit events. |
| CCTV cameraPer model and mount type | S1 | 4 | Band B | The 90-day retention commitment presumes every camera is recording. A dark camera is a gap in the record. |
| Recorder storage drivePer array type | S1 | 4 | Band B | Retention depends on array health. A degraded array silently shortens the retention period. |
| Turnstile or portal control modulePer portal | S1 | 1 | Band B | A failed portal forces manual admission with escort, which is workable but consumes officer time and creates exceptions. |
| Intercom and duress stationPer type | S1 | 2 | Band A | Life-safety adjacent. Cheap, and absence would be a finding in any audit. |

The control layer does not carry load and does not cool anything. What it does is make the plant visible and automatic — and every line here fails in the same way, by leaving the plant running while nobody can see or sequence it.
| Item | Class | Hold | Lead | Why it is on the list |
|---|---|---|---|---|
| Building and power management controls | ||||
| BMS or EPMS input-output modulePer module type | S1 | 2 ea | Band B | Loses visibility and automatic control of a plant group while the plant keeps running — an unmonitored plant is a degraded plant. |
| BMS controllerPer controller type | S1 | 1 | Band B | Single-unit critical. Sequencing, lead-lag rotation and alarm logic all sit here. |
| Network gateway and protocol converterPer type | S1 | 1 ea | Band A | A single converter failure can orphan an entire subsystem from the control layer. |
| Uninterruptible supply for controlsPer panel | S1 | 1 | Band A | Controls must survive the transfer they are supposed to manage. Frequently overlooked, which is exactly why it is listed. |

A part that is on site but degraded, uncalibrated or unfindable at three in the morning is not a spare. This section covers the conditions the store must hold and the disciplines that keep the stock genuinely usable.
| Location and access | A dedicated, access-controlled room inside the building envelope, at Layer 3 of the access model in PRM-SEC-2026-001. Reachable without passing through a data hall, so that a fetch during an incident does not add a hall entry. |
|---|---|
| Environment | Temperature and humidity controlled to the manufacturers' storage specifications, monitored by the BMS and alarmed. Electronics are stored inside the ASHRAE storage envelope, not merely inside the building. |
| Electrostatic protection | ESD-protected area with grounded benching and wrist-strap points. All boards and cards remain in their original static shielding until the point of fitting. |
| Layout and labelling | Fixed locations by discipline, each bin labelled with the part reference, the holding level and the reorder point. A part found in the wrong bin is treated as a stock error and recorded. |
| Wet parts and fluids | Bunded storage for coolant and chemistry, separated from electronics, with spill containment and the relevant safety data sheets held at the point of storage. |
| Findability | The location of every line is in the asset system and printed on the store plan at the door. The test applied is whether the engineer on shift can find it without calling anyone. |

| Item | Interval | Action |
|---|---|---|
| UPS battery blocks | Annually | Charged and tested; rotated into the installed string and replaced in stock, so the shelf holding is never older than the string it serves. |
| Generator starter batteries | 6 months | Charged and load-tested. Replaced at 80% of rated capacity rather than on failure. |
| Coolant and chemistry | Per specification | Rotated first-in first-out against the manufacturer's shelf life. Expired fluid is disposed of under the environmental consignment procedure, never used. |
| Flexible hoses and elastomer seals | 3 years in stock | Replaced on age whether used or not. Rubber ages on a shelf as well as in service. |
| Test and calibration instruments | Annually | Calibrated to a traceable standard. An uncalibrated instrument invalidates any test result it produced — including commissioning results. |
| Firmware on stocked spares | On every plant update | Stocked cards and switches are brought to the installed firmware revision. A spare at the wrong revision can fail to join the system it was held for. |

| Reorder point | Set at minimum level plus expected consumption over the replenishment lead time. For single-unit items the reorder point is one — the order is raised the moment the shelf goes empty. |
|---|---|
| Trigger | Automatic on issue. The asset system raises the requisition; the Facilities Manager approves within one business day. |
| Expedite | Where the issue has taken redundancy to zero, the replenishment is expedited on the COO's authority and the exposure is reported daily until closed. |
| Below minimum | Any line below its minimum is a reportable condition, listed in the monthly operations report with the date it is expected to be back in stock. It is not carried silently. |
| Supplier concentration | Reviewed annually. Where a Band B or C line has a single source with no in-region alternative, that concentration is recorded as a risk with the mitigation stated — dual sourcing where the part allows it, a higher holding where it does not. |
The register is a model until it meets reality. Consumption is reviewed quarterly against the assumptions in section 04, and the model is corrected rather than defended.
| On an end-of-life notice | The Facilities Manager assesses remaining life of the installed population against the last-buy date, and either places a final buy sized to that remaining life or qualifies a successor part. |
|---|---|
| Final buy sizing | Installed population multiplied by the expected annual failure rate, multiplied by remaining service life in years, plus the standing holding. Documented and approved by the COO because it is capital held against a closing window. |
| Successor qualification | A replacement part is not accepted on a datasheet. It is fitted, commissioned and tested against the affected MOP before the original is de-listed. |
| Register effect | Both parts appear on the register during transition, with the transition period stated, so that a reviewer sees two variants rather than an unexplained duplicate. |
| Register owner | Facilities Manager. Owns the criticality assessment, the holding levels and the store. Approves replenishment. |
|---|---|
| Platform scope | Engineering Manager owns the fabric and compute lines at section 07, under the same method and the same store. |
| Approval of the policy | COO. Approves this document, any final buy, and any decision to accept an exposure rather than hold a part. |
| Audit | Physical stock take quarterly, full reconciliation annually. Discrepancy between record and shelf is a finding with a named owner, not a correction. |
| Review | Annually, and on any change to the plant, the topology or the supply position. Recorded even where nothing changes. |

Reported to the COO on the cadence shown, and to customers and lenders on request. Fill rate is the measure that matters most: it states how often the shelf answered the question it exists to answer.
| Measure | Target | Reported |
|---|---|---|
| Fill rate — demand met from stock on first request | ≥ 98% | Monthly |
| Class S1 lines at or above minimum level | 100% | Monthly |
| Time from failure to part in hand, class S1 | ≤ 4 hours | Monthly |
| Replenishment orders raised within one business day of issue | ≥ 95% | Monthly |
| Stock-take discrepancies, by line | 0 | Quarterly |
| Stocked spares at the installed firmware revision | 100% | Quarterly |
| Shelf-life items within date | 100% | Quarterly |
| Repairs extended by absence of a spare | 0 | Monthly |
| Class S2 contracted response times tested | Annually, all | Annually |
Stated plainly so that a reviewer is not left to infer it.
For the current holding level of any line, the criticality assessment behind it, the store plan, or the stock-take and fill-rate record once operations commence.