
The governance framework of Prima Artificial Intelligence LLC for the development and operation of the KOM Oman AI Factory — a Tier III AI computing facility deploying approximately 13,824 NVIDIA Blackwell-generation GPUs across two phases at Knowledge Oasis Muscat. Prepared for institutional investors, hyperscale customers, infrastructure funds and commercial lenders, and submitted to the Board of Directors for adoption and implementation in full before the commencement of commercial operations.

| Prepared by | Office of the Chief Executive Officer, with the General Counsel acting as Corporate Secretary |
|---|---|
| Reviewed by | Executive Committee; external governance counsel; Audit & Risk Committee of the Board |
| Status | Draft for review. Not yet adopted. Submitted to the Board of Directors of Prima Artificial Intelligence LLC for consideration and adoption by resolution. |
| Effective | On adoption by the Board. All governance bodies, delegations and controls described herein are to be established and evidenced in full before commencement of commercial operations (ready-for-service) |
| Custodian | General Counsel & Corporate Secretary — controlled master copy and register of amendments |
| Next review | Annual — no later than the second quarter following adoption (Section 17) |
| Version | Date | Description | Status |
|---|---|---|---|
| 0.1 | July 2026 | Initial draft — governance baseline for the development phase and the operating governance required before ready-for-service. Issued for Board and stakeholder review; substantive revision anticipated. | Current |
| Controlled copies | Members of the Board of Directors; Executive Leadership Team; General Counsel & Corporate Secretary |
|---|---|
| Disclosure | Investor and lender data rooms under non-disclosure agreement; prospective customers in due diligence; external auditors and certification bodies on request |
| Related documents | PRM-ORG-2026-001 Organizational Structure · PRM-DOA-2026-001 Delegation of Authority Matrix · the governance document register at Section 16 |
This document contains confidential and proprietary information of Prima Artificial Intelligence LLC. It is provided for the purpose of due diligence and governance review only and may not be reproduced or disclosed, in whole or in part, without the prior written consent of the General Counsel. In the event of conflict between this Charter and the constitutional documents of the company or applicable law of the Sultanate of Oman, the constitutional documents and applicable law prevail.


This Charter defines how Prima Artificial Intelligence LLC is directed and controlled. It establishes the mandate of the Board of Directors, the authority delegated to executive management, the committee structure through which material decisions are prepared and taken, and the risk, compliance and reporting disciplines that apply across the Company.
The Company is in the development phase of the KOM Oman AI Factory. This Charter therefore serves a dual purpose: it governs the Company today — through construction, procurement, financing and hiring — and it defines the operating governance that must be demonstrably in place before the Facility accepts its first production workload. Each governance body described herein carries an explicit stand-up milestone tied to the ready-for-service date.
It is written to be relied upon in due diligence as the authoritative statement of the Company’s decision rights and control environment, subject to the constitutional documents and applicable law.
Prima governs the Facility as critical infrastructure. The governance model is built on three convictions: that availability and security are produced by disciplined process rather than heroics; that decision rights must be explicit, singular and matched to accountability; and that a lean organization of 104 FTE stays fast only when routine decisions are delegated and reserved matters are few, clear and genuinely material. Authority is delegated to the lowest level at which the risk of the decision can be competently owned — and no lower.
| Reference | Application in this Charter |
|---|---|
| OECD Principles of Corporate Governance2023 | Board responsibilities, shareholder rights, disclosure and the treatment of stakeholders (Sections 4, 15) |
| Uptime Institute Tier III & M&O discipline | Operational governance: staffing, maintenance authority, change control and incident command (Sections 6, 8, 13) |
| ISO/IEC 27001:2022 · SOC 2AICPA TSC | Information security governance, management review and control ownership (Sections 6, 10, 11) |
| ISO 22301:2019 | Business continuity management system and crisis governance (Section 13) |
| COSO ERM (2017) · ISO 31000 | Enterprise risk management, risk appetite and the three-lines model (Section 10) |
| NIST Cybersecurity Framework 2.0 | Cyber risk oversight and the mandate of the Cybersecurity Committee (Sections 6, 10) |
| Oman Commercial Companies Law & PDPL | Statutory duties of directors, corporate records and personal data protection in the Sultanate of Oman (Sections 4, 11) |

Eight principles govern every body, delegation and control in this Charter. They are binding on directors, officers, employees and — through contract — on managed service providers acting for the Company.
Every decision, asset, risk and KPI has a single named owner. Committees advise and coordinate; they do not dilute individual accountability. Where this Charter assigns a matter to a role, that officer answers for the outcome.
Decisions are recorded, minuted and traceable to the authority under which they were taken. Investors, lenders and customers receive accurate, timely and complete reporting; bad news travels faster than good news.
Oversight is separated from execution. The Chair is not the CEO; the Audit & Risk Committee is chaired by a non-executive director; Information Security audits the physical security provider it does not manage; internal audit reports to the Board, not to management.
The Company competes on capability, not concession. The Code of Conduct, anti-bribery and sanctions rules at Section 12 admit no materiality threshold: no payment, gift or arrangement outside policy is small enough to be acceptable.
Material decisions are taken against a stated risk appetite, with the risk assessment on the table. Approval thresholds in the Delegation of Authority scale with the risk carried, not merely with the amount spent.
Customers place regulated workloads and proprietary models inside the Facility. Contractual commitments — SLAs, security obligations, audit rights, confidentiality — are governed as strictly as financial covenants, with breaches escalated to executive level.
The Facility is run to Uptime Tier III concurrent-maintainability discipline: documented procedures, rehearsed failure responses, controlled change, and preventive maintenance executed on schedule. Deviation from procedure is itself a reportable incident.
Physical and cyber security take precedence over convenience and schedule. Security requirements are set independently of the functions they constrain, and the CISO holds an unqualified right of escalation to the CEO and to the Audit & Risk Committee.

Governance operates in four tiers. Authority flows down through documented delegation; accountability and reporting flow up through the structures in Sections 14 and 15.
| Tier | Mandate |
|---|---|
| Board of DirectorsOversight · reserved matters | Sets strategy, appetite and reserved matters; appoints and evaluates the CEO; approves this Charter — Section 4 |
| Chief Executive OfficerSole executive delegate | All delegation in this Charter flows through the office of the CEO — Section 5.1 |
| Executive Leadership TeamCOO · CTO · CCO · CFO · GC | Directs the Company within delegated authority and answers to the Board for performance — Section 5 |
| Divisions104 FTE, full build-out | Operations (COO · 52) · Technology (CTO · 33) · Commercial (CCO · 7) · Finance (CFO · 4) · Corporate functions (GC · HR · 3) |
| Tier | Mandate | Instruments |
|---|---|---|
| Oversight | Board and its committees set strategy, appetite and reserved matters; appoint and evaluate the CEO; approve this Charter | Charter · reserved matters · board resolutions |
| Executive | CEO and Executive Leadership Team direct the Company within delegated authority and answer to the Board for performance | Delegation of Authority · executive KPIs |
| Management | Eight standing committees prepare, coordinate and control cross-functional decisions — capital, change, risk, security, safety, procurement | Committee terms of reference · RACI |
| Operational | Functions execute under documented procedures; the NOC and shift organization hold defined emergency authority around the clock | SOPs · MOPs · EOPs · runbooks |
During the development phase the same hierarchy governs a narrower agenda: construction, long-lead procurement, financing, certification and hiring. Committees stand up in two waves — the Executive, Investment and Procurement Committees at adoption of this Charter; the operational committees (Change Advisory Board, Operational Risk, Cybersecurity, Health & Safety) no later than 120 days before ready-for-service, so that each has rehearsed its mandate before the first customer workload.

The Board carries ultimate responsibility for the stewardship of the Company. Acting collectively, it:
The Board comprises five to seven directors: a non-executive Chair, directors nominated by the shareholders in accordance with the shareholders’ agreement, at least two independent non-executive directors with data centre, infrastructure finance or cybersecurity expertise, and the CEO as the sole executive director. The roles of Chair and CEO are held by different individuals; the General Counsel acts as Corporate Secretary. Conflicted directors recuse from deliberation and vote per Section 12.
The Board holds all powers of the Company other than those reserved to shareholders by law or the constitutional documents. It delegates the executive management of the Company to the CEO — and through the CEO to the Executive Leadership Team — subject to the reserved matters at 4.5 and the monetary limits at Section 9, exercised solely through this Charter and the Delegation of Authority Matrix.
| Meeting | Frequency | Standing agenda |
|---|---|---|
| Ordinary Board meeting | Quarterly | CEO report; project / operations dashboard; financial statements; risk and compliance report; committee reports; reserved-matter approvals |
| Strategy & budget session | Annually · Q4 | Multi-year strategy, capacity roadmap, annual budget and capital plan, executive objectives for the following year |
| Extraordinary meeting | As required | Convened by the Chair, the CEO or any two directors on not less than five business days’ notice (waivable in urgency); written resolutions permitted by unanimity |

The following matters require prior Board approval. Monetary figures are in US dollars and refer to aggregate commitment over the life of the obligation.
| Category | Matters reserved to the Board |
|---|---|
| Strategy & plans | Corporate strategy; annual business plan and budget; any material change to the scope, phasing or Tier objective of the Facility |
| Capital & finance | Capital expenditure above US$ 5,000,000 per project; unbudgeted expenditure above US$ 1,000,000; incurrence of debt, guarantees or security over assets; hedging policy; dividend and distribution decisions |
| Transactions | Acquisition or disposal of any business, real property or asset above US$ 2,500,000; joint ventures; related-party transactions of any value |
| Customers | Any customer contract above US$ 10,000,000 total contract value or 5 MW of committed capacity; any contract materially departing from the Board-approved form of service agreement or SLA |
| People | Appointment, removal and remuneration of the CEO and executive officers; incentive schemes; any collective employment commitment |
| Risk & compliance | Risk appetite statement; Risk Management Framework; insurance programme; settlement of any claim above US$ 500,000; commencement of material litigation |
| Governance | Adoption and amendment of this Charter, the Delegation of Authority, the Code of Conduct and the policies listed at Section 16; appointment of external auditors; any change to constitutional documents (with shareholders) |
| Committee | Mandate | Composition · cadence |
|---|---|---|
| Audit & Risk Committee | Financial reporting integrity; external and internal audit; internal controls; risk framework effectiveness; compliance and certification programme; whistleblower reports; cyber risk oversight | Three non-executive directors, independent chair · quarterly |
| Remuneration & Nomination Committee | Executive remuneration and incentive design; succession planning for the CEO and Executive Leadership Team; Board composition and director nomination | Chair and two non-executive directors · semi-annually |
Directors receive the monthly management flash report, the quarterly Board pack and the annual certification and audit reports defined at Section 15. Any director may require additional information from any officer through the Corporate Secretary, commission independent professional advice at the Company’s expense on reasonable notice to the Chair, and access the Facility subject to safety and security protocols. The Board is notified of any Severity-1 incident, any reportable data or security breach, and any regulatory contact of substance within 24 hours (Section 13).

The Executive Leadership Team (ELT) comprises the CEO, COO, CTO, CCO and CFO, with the General Counsel and the HR Manager attending as standing members. Individual accountabilities are summarised below and mapped in matrix form at Appendix D. Each officer operates within the Delegation of Authority at Section 9.
Accountable to the Board for the entire performance of the Company. The CEO holds the single point of executive authority: all delegation in this Charter flows through the office of the CEO. The CEO proposes strategy, budget and capital plans to the Board; chairs the Executive Committee; approves commitments within the limits at Section 9; represents the Company to shareholders, government, anchor customers and financiers; and is the ultimate escalation point for any crisis (Section 13). The CEO may not sub-delegate reserved matters or authority beyond the limits granted.
Accountable for the safe, secure and continuous operation of the Facility: the 24×7 data hall organization, all critical MEP infrastructure from utility intake to rack, the Network Operations Center, and operational oversight of the outsourced physical security provider. The COO owns facility availability against the Tier III concurrent-maintainability standard, the preventive maintenance programme, site health and safety, and incident command up to and including facility-level emergencies. Chairs the Operational Risk Committee and the Health & Safety Committee; holds emergency expenditure authority under Section 13.5.
Accountable for the compute, network and security platform: the NVIDIA Blackwell GPU fleet, Linux estate, Kubernetes and Slurm scheduling stack, storage, the InfiniBand and Ethernet fabrics, and DWDM interconnection. The CTO owns platform availability and performance as sold to customers, the technology roadmap and standards, capacity engineering, and — through the CISO — the information security management system and the ISO 27001 / SOC 2 programme. Chairs the Technology Committee; sponsors the Change Advisory Board; approves technical designs and platform changes within delegated authority.
Accountable for revenue and the customer relationship across its life cycle: pipeline and customer acquisition, contract negotiation within the Board-approved form of agreement, capacity allocation and pricing within approved floors, technical pre-sales, onboarding and customer success. The CCO owns SLA performance as experienced by the customer, customer reporting and satisfaction, and the commercial forecast that drives the capacity plan. Brings all non-standard terms to the General Counsel and, above threshold, to the Board.

Accountable for financial stewardship: accounting and financial reporting, budgeting and forecasting, treasury and cash management, tax, insurance placement, procurement and vendor commercial management, and the financial model relied upon by investors and lenders. The CFO owns the internal financial control environment, lender reporting and covenant compliance, and chairs the Investment Committee and the Procurement Committee. Counter-signs all commitments above US$ 250,000 (two-signature rule, Section 9.2).
Accountable for legal affairs and the integrity of the governance system itself: corporate records and Board support, contract review and execution formalities, regulatory and licensing matters, export-control and sanctions screening, data protection, disputes, and the ethics programme at Section 12 including the whistleblower channel. The General Counsel maintains this Charter and the policy register at Section 16, engages external counsel, and holds an unqualified right of escalation to the Chair where legal or ethical concerns are not resolved by management.
Accountable for the people system that a 24×7 critical facility depends on: recruitment against the 104-FTE staffing plan, shift and on-call compensation design, payroll, Omanisation and work-authorisation compliance, training and certification records for operational staff, performance management and workplace administration. HR administers the Code of Conduct attestation cycle and, with the General Counsel, conduct investigations.
| Office | First alternate | Scope of deputisation |
|---|---|---|
| Chief Executive Officer | Chief Operating Officer | Full authority except reserved matters and executive appointments |
| Chief Operating Officer | Operations Manager | Operational and incident authority; not budget or personnel decisions |
| Chief Technology Officer | Engineering Manager, Infrastructure | Platform and change authority; security matters pass to the CISO |
| Chief Financial Officer | Financial Controller | Payments and reporting within approved budget; no new commitments above Director level |

Eight standing committees govern cross-functional decisions. Each operates under written terms of reference approved by the Executive Committee, keeps minutes and action logs, and reports as shown below. Committees decide within the Delegation of Authority of their chair; anything beyond is a recommendation to the CEO or the Board. Committee membership is by role, not by person.
| Committee | Chair | Meets | Reports to |
|---|---|---|---|
| 6.1 · Executive Committee (ExCo) | CEO | Weekly | Board |
| 6.2 · Technology Committee | CTO | Monthly | ExCo |
| 6.3 · Operational Risk Committee | COO | Monthly | ExCo · Audit & Risk Cttee |
| 6.4 · Cybersecurity Committee | CISO | Monthly | ExCo · Audit & Risk Cttee |
| 6.5 · Change Advisory Board (CAB) | Eng. Manager | Weekly | Technology Committee |
| 6.6 · Investment Committee | CFO | Monthly | CEO · Board |
| 6.7 · Health & Safety Committee | COO | Monthly | ExCo |
| 6.8 · Procurement Committee | CFO | Fortnightly | ExCo |
Purpose. The principal instrument of executive coordination: reviews performance against plan, decides cross-functional matters within the CEO’s authority, arbitrates resource conflicts, tracks the risk and action registers, and prepares every matter that goes to the Board.
| Members | CEO, COO, CTO, CCO, CFO; General Counsel and HR standing attendees; others by invitation. |
|---|---|
| Decision authority | All matters within the CEO’s delegation at Section 9; endorses reserved-matter papers before submission to the Board. |

Purpose. Governs the technology platform: architecture standards, technology selection, capacity engineering against the commercial forecast, platform lifecycle and refresh, and the engineering roadmap. Reviews platform KPIs and post-incident engineering actions.
| Members | CTO; Engineering Manager; Network Manager; Infrastructure Architect; CISO; Operations Manager (for operational impact); Solutions Architect (customer requirements). |
|---|---|
| Decision authority | Approves technical standards and designs; endorses technology purchases to the Investment Committee; approves capacity plans within the approved budget. |
Purpose. Owns the operational risk register for the Facility: single points of failure, maintenance deferrals, vendor performance risk, environmental and utility risks. Reviews all Severity-1/2 incidents and near-misses, tracks corrective actions to closure, and approves the annual integrated maintenance plan.
| Members | COO; Operations Manager; Facilities Manager; NOC Manager; CISO; Engineering Manager; General Counsel (compliance interface). |
|---|---|
| Decision authority | Accepts, mitigates or escalates operational risks within COO authority; may suspend non-emergency works Facility-wide; escalates out-of-appetite risks to ExCo and the Audit & Risk Committee. |
Purpose. The management review body of the ISMS: threat landscape and intelligence, vulnerability and patch posture, identity and access reviews, security architecture decisions, supplier security assessments, incident-response readiness, and the ISO 27001 / SOC 2 audit programme. Convenes the security incident-response process when invoked.
| Members | CISO; CTO; Security Engineer; IAM Specialist; Compliance Specialist; NOC Manager; representative of the COO; General Counsel (breach notification). |
|---|---|
| Decision authority | Approves security policies, exceptions (time-bound, risk-accepted in writing) and emergency isolation of systems; directs remediation with priority over project work; reports breaches per Section 11. |
Purpose. Controls every change to production infrastructure — facility, platform and network — under a single change calendar. Classifies changes (standard, normal, emergency), verifies method statements, rollback plans and customer-impact assessments, and enforces change freezes during high-risk windows.
| Members | Engineering Manager (chair); Operations Manager; Facilities Manager; Network Manager; Security Engineer; NOC Manager; Customer Success (impact notice). |
|---|---|
| Decision authority | Approves or rejects normal changes; ratifies emergency changes within 48 hours; changes touching concurrent-maintainability require Facilities Manager and COO sign-off. |

Purpose. Reviews every capital commitment above Director authority: business case, lifecycle cost, vendor and financing structure, risk assessment and alignment with the capacity roadmap. Owns the capital plan, tracks approved projects against budget and benefit, and prepares Board capex papers.
| Members | CFO (chair); CEO; COO; CTO; CCO; Procurement Manager (secretary); General Counsel for contract structure. |
|---|---|
| Decision authority | Approves capex from US$ 250,000 to US$ 5,000,000 within the approved capital plan; recommends larger or unbudgeted commitments to the Board. |
Purpose. Governs occupational health and safety across the site, including contractors: hazard identification, permit-to-work and lock-out/tag-out discipline, arc-flash and confined-space controls, emergency drills, and investigation of all recordable incidents and near-misses. During construction, coordinates with the EPC contractor’s HSE organization and audits its performance.
| Members | COO (chair); Facilities Manager (deputy); Operations Manager; HR Manager; shift representative (rotating); security provider site manager. |
|---|---|
| Decision authority | Any member may stop unsafe work immediately; the committee approves safety procedures, drill schedules and corrective actions; lost-time incidents are reported to the Board. |
Purpose. Ensures procurement is competitive, documented and free of conflicts: tender strategy and waivers, bid evaluation above Director authority, award recommendations, managed-service agreements and renewals, and vendor performance against SLA. Maintains the approved vendor register and the single-source justification log.
| Members | CFO (chair); Procurement Manager (secretary); requesting Director; Treasury & Vendor Manager; General Counsel; CISO for suppliers with system or site access. |
|---|---|
| Decision authority | Approves awards and waivers from US$ 100,000 to US$ 1,000,000; endorses larger awards to the Investment Committee; approves onboarding of critical vendors after security and financial screening. |

Table 7-1 assigns responsibility for the Company’s major decision classes. Exactly one role is Accountable (A) for each decision at a given threshold; monetary thresholds are set by the Delegation of Authority at Section 9.
| Decision | Board | CEO | COO | CTO | CISO | CCO | CFO | GC | Forum / threshold |
|---|---|---|---|---|---|---|---|---|---|
| Strategy, business plan & annual budget | A | R | C | C | C | C | R | C | Q4 strategy session |
| Capital expenditure — budgeted, ≤ US$ 5M | I | A | C | C | — | — | R | C | Investment Cttee ≥ US$ 250k |
| Capital expenditure — > US$ 5M or unbudgeted > US$ 1M | A | R | C | C | — | — | R | C | Reserved matter 4.5 |
| Customer contracts — standard form, ≤ US$ 10M | I | A | C | C | — | R | C | C | CCO signs ≤ US$ 2M |
| Customer contracts — > US$ 10M, > 5 MW or non-standard | A | R | C | C | C | R | C | C | Reserved matter 4.5 |
| Infrastructure expansion — new capacity phase | A | R | C | R | C | C | C | I | Feasibility via Investment Cttee |
| Hiring — within approved 104-FTE plan | — | I | A* | A* | — | A* | A* | — | * within own function · HR R |
| Executive appointments & remuneration | A | R | — | — | — | — | — | C | Rem & Nom Cttee |
| Cybersecurity — policy, exceptions, emergency isolation | I | I | C | C | A | I | — | C | Cybersecurity Cttee 6.4 |
| Operational incidents — SEV-1 command & customer comms | I | I | A | C | C | R | — | I | Escalation per §13 · CCO R for comms |
| Vendor selection & procurement awards | — | I | C | C | C | — | A | C | Procurement Cttee 6.8 |
| Legal — contract execution, disputes, regulatory filings | I | C | — | — | — | C | C | A | Litigation > US$ 500k → Board |
| Budget re-forecast & transfers between budget lines | I | A | C | C | — | C | R | — | > 10 % variance → Board |

Every decision has exactly one A at a given threshold. Committees recommend; the accountable officer decides and signs.
A decision taken without a required consultation is voidable by the next level up and is recorded as a governance exception.
No person approves their own expense, contract, hire or risk acceptance; approvals move to the next level up whenever the requester is the approver.
Decisions above Director authority are minuted with the options considered, the risk assessment and the authority relied upon.
Commitments may not be divided to fall under a lower approval threshold; aggregation is assessed per vendor and per project over 12 months.
The CISO on security grounds, and any employee on life-safety grounds, may halt an approved action pending review one level up.
A matter escalates when it exceeds the holder’s authority, when required consultees disagree, or when the decision timebox lapses.
Where delay would endanger life, the environment, the security of customer systems or the continuity of service, the senior person present may act beyond their standing authority under Section 13.5 (emergency decision authority). Every such decision is reported to the CEO within 12 hours and ratified by the body that would ordinarily have decided — the ExCo within 48 hours, the Board at its next sitting. Emergency authority does not extend to entering new commercial commitments unrelated to the emergency.
Where the CEO and another executive disagree on a matter within the CEO’s authority, the CEO decides and the dissent is minuted. Where the disagreement concerns legality, ethics or safety, the matter must instead be referred to the Chair through the General Counsel.

Twelve functions execute the operating model defined in PRM-ORG-2026-001. Each is summarised here with its governance interface — where its authority comes from and where its performance is reviewed.
Runs the data halls in a four-shift rotation — smart hands, rack installation, hardware replacement, incident response and customer work orders. Each shift is self-sufficient, led by a Shift Lead holding defined emergency authority. Governance interface: Operational Risk Committee; work executed under SOPs and CAB-approved change.
Owns all MEP infrastructure — the electrical chain from utility intake to rack, cooling plant, UPS, generators, fuel and water systems, BMS. Runs the preventive maintenance programme to Tier III concurrent-maintainability discipline and supervises OEM service vendors. Governance interface: Operational Risk and H&S Committees; maintenance windows via CAB.
Continuously staffed monitoring of infrastructure, network and availability. First-line incident detection, classification and escalation into Operations, Facilities and Engineering under Appendix E; single source of the daily operations report (Section 15). The NOC declares incident severity and starts the escalation clock. Governance interface: Operational Risk Committee; Cybersecurity Committee for security events.
Delivered by a specialist provider under a long-term managed service agreement: 24×7 officers, access control, visitor management, CCTV and perimeter patrol. Reports operationally to the COO; audited by Information Security; contract owned by Procurement. Security incidents follow the same severity model as operational incidents. Governance interface: H&S Committee; vendor performance review by Procurement.
Runs the compute platform: Linux fleet, NVIDIA GPU systems, Kubernetes and Slurm scheduling, storage and automation, with a dedicated Infrastructure Architect owning standards. Chairs the CAB. Governance interface: Technology Committee for designs and standards; Investment Committee for platform capex.
Designs and operates the spine-leaf fabric, InfiniBand compute fabric, Ethernet, DWDM interconnection, routing and capacity planning. Changes to production fabric are CAB-controlled with customer-impact assessment; fabric availability is reported as a technology KPI (Section 14). Governance interface: Technology Committee; CAB for production change.

Operates the ISMS: security engineering and monitoring, vulnerability management, identity and access management, and the ISO 27001 / SOC 2 compliance programme. Audits the physical security provider and vendor security. The CISO chairs the Cybersecurity Committee and holds direct escalation rights to the CEO and the Audit & Risk Committee, independent of the CTO reporting line.
Accounting, reporting, budgeting and forecast, treasury and vendor commercial management, and the procurement process under the Procurement Policy. Maintains the fixed-asset register for the GPU fleet and MEP plant, lender reporting and insurance schedules. Governance interface: Investment and Procurement Committees; Audit & Risk Committee for controls and audit.
Enterprise sales and solutions architecture: pipeline, qualification under KYC and export-control screening (Section 11), proposal and contract negotiation on the approved form, and technical pre-sales that translates customer requirements into platform capacity. Pricing within approved floors; deviations escalate per Table 7-1.
Owns the customer after signature: onboarding, service reviews, SLA reporting and credits, escalation liaison during incidents, and renewal. Publishes the customer KPI set at Section 14 and carries the customer’s voice into the Technology Committee and the CAB (impact notices).
Commercial contracts, regulatory compliance and licensing, NDAs, vendor agreements and corporate governance support to the Board. Runs sanctions and export-control screening with Commercial, data-protection compliance, and the ethics programme. External counsel is engaged under the GC’s authority for specialist and disputed matters.
Recruitment against the staffing plan, payroll, Omanisation compliance, training and certification records, employee development and office operations. Administers Code of Conduct attestations and the conflict-of-interest register with the General Counsel; supervises facility-services vendors (cleaning, waste, grounds).

Table 9-1 summarises approval limits by management level; the operative instrument is the Delegation of Authority Matrix (PRM-DOA-2026-001), which names individual holders and is countersigned by each. Limits are per commitment in US dollars, aggregate over the life of the obligation.
| Commitment class | Board | CEO | COO · CTO · CCO · CFO | Director / Dept. Manager | Line Manager |
|---|---|---|---|---|---|
| Capital expenditure — budgeted | > 5,000,000 | ≤ 5,000,000 | ≤ 1,000,000 | ≤ 250,000 | ≤ 25,000 |
| Expenditure — unbudgeted | > 1,000,000 | ≤ 1,000,000 | ≤ 250,000 | ≤ 50,000 | — |
| Operating expenditure — within approved budget | budget | within budget | ≤ 500,000 | ≤ 100,000 | ≤ 10,000 |
| Customer contracts — total contract value, standard form | > 10,000,000 | ≤ 10,000,000 | CCO ≤ 2,000,000 | ≤ 500,000 | — |
| Procurement awards & vendor agreements | > 5,000,000 | ≤ 5,000,000 | ≤ 1,000,000 | ≤ 100,000 | ≤ 10,000 |
| Emergency expenditure — life-safety / service protection (13.5) | ratifies | ≤ 1,000,000 | COO ≤ 500,000 | ≤ 100,000 | Shift Lead ≤ 25,000 |
| Hiring & compensation | Executive officers | Direct reports; any package > 150k/yr | Within own function & approved plan | Backfills within plan | — |
| Risk acceptance — residual risk sign-off | Out of appetite | High | Medium | Low | — |
Commitments of US$ 250,000 or more carry two signatures — the accountable executive and the CFO (or CEO where the CFO is the sponsor). Bank mandates, payment-system approval chains and the contract-signature register are configured to mirror this table exactly; a payment that cannot be traced to a conforming approval is blocked by default. Delegations lapse on change of role and are re-issued in writing; temporary uplifts require CEO approval and expire automatically.
The CFO reports DoA exceptions — approvals out of level, split commitments, retrospective approvals — to the ExCo monthly and to the Audit & Risk Committee quarterly. Internal audit tests a sample of approvals against the matrix annually.

Risk is governed under a Risk Management Framework aligned with COSO ERM and ISO 31000, approved by the Board and operated day-to-day by management. The Board sets appetite; the Audit & Risk Committee tests that exposures remain within it.
Operations, Technology, Commercial and corporate functions identify, assess and mitigate the risks of their own activity, and keep their sections of the risk register current.
The Operational Risk and Cybersecurity Committees, Information Security, Legal & Compliance and Finance set standards, challenge first-line assessments and monitor aggregate exposure.
Outsourced internal audit, external audit and certification bodies report to the Audit & Risk Committee without management filter, under a Board-approved assurance plan.
| Domain | Appetite statement |
|---|---|
| Life safety | Zero appetite. No commercial or schedule consideration justifies a safety risk; any employee may stop work. |
| Service availability | Minimal. Operate to Tier III concurrent maintainability; no planned customer-affecting downtime; single points of failure are register-tracked with dated remediation. |
| Security & compliance | Zero appetite for breaches of law, sanctions, export control or customer security commitments; exceptions to security policy only time-bound and risk-accepted in writing. |
| Financial | Conservative. Committed revenue underpins expansion capex; liquidity covers 12 months of fixed cost; no uncovered FX or interest-rate exposure above policy limits. |
| Growth & innovation | Measured. The Company accepts technology and market risk inherent in AI infrastructure where it is priced, contracted and within the capacity of the balance sheet. |
A single enterprise risk register is maintained by the General Counsel with the CFO, scored for likelihood and impact on a 5×5 scale against defined criteria. First-line owners update their entries monthly; the Operational Risk and Cybersecurity Committees review their domains monthly; the ExCo reviews the top-ten enterprise risks monthly; the Audit & Risk Committee reviews the full register quarterly; the Board reviews appetite and the principal-risk report annually and on any material change. Risk acceptances follow the sign-off levels in Table 9-1.

| Domain | Scope for the Facility | Owner | Oversight forum | Key controls |
|---|---|---|---|---|
| Operational | Failure of power, cooling or platform; maintenance error; SLA breach on the 13,824-GPU cluster | COO | Operational Risk Cttee | Tier III design; PM programme; CAB; drills; spares strategy |
| Cyber | Compromise of platform, customer workloads or OT/BMS systems; data exfiltration; ransomware | CISO | Cybersecurity Cttee · A&R Cttee | ISMS; segmentation incl. OT; IAM; monitoring; IR plan; pen tests |
| Compliance | Breach of export control, sanctions, AML/KYC, data protection or licence conditions | GC | A&R Cttee | Screening at onboarding & renewal; contract clauses; training; Section 11 |
| Financial | Liquidity, counterparty concentration, FX and rate exposure, energy price, covenant breach | CFO | A&R Cttee · Board | Treasury policy; hedging; committed-revenue coverage; covenant monitoring |
| Construction | Delivery: schedule and cost overrun, long-lead equipment, contractor default, commissioning quality | COO | ExCo · Board (monthly in phase) | Fixed-price EPC packages; independent commissioning agent; Tier III certification; contingency |
| Business continuity | Regional events: utility loss, extreme heat, storm, telecom cut, pandemic, civil disruption | COO | Operational Risk Cttee | BCP/DRP under ISO 22301; fuel autonomy; diverse fibre; annual exercises — Section 13 |
| Third-party | Failure or compromise of OEM maintainers, security provider, utilities, carriers or critical suppliers | CFO | Procurement Cttee | Vendor screening & tiering; SLAs; security audits; exit plans for critical services |
The CFO places and annually reviews an insurance programme appropriate to a Tier III facility — property damage and business interruption, construction all-risks during the development phase, general and cyber liability, directors’ and officers’ cover — with limits benchmarked by an independent broker and reported to the Audit & Risk Committee. Insurance is a mitigation of last resort; it never substitutes for a required control.

The compliance programme covers certified management systems, third-party attestations and statutory obligations. Each element has a named owner, an assurance cadence and Board-level visibility through the Audit & Risk Committee.
| Standard / obligation | Scope | Owner | Assurance cadence |
|---|---|---|---|
| ISO/IEC 27001:2022 | Information security management system across platform, corporate IT and OT/BMS | CISO | Certification before RFS; surveillance annually; recert. 3-yearly |
| SOC 2 Type II | Security & availability trust criteria for customer-facing services | CISO | Type I at RFS; Type II report annually thereafter |
| ISO 22301:2019 | Business continuity management system for the Facility and corporate functions | COO | Certification within 12 months of RFS; annual exercise evidence |
| Uptime Institute Tier III | Concurrent maintainability of design and constructed facility; operational sustainability | COO | TCDD at design; TCCF at commissioning; M&O assessment in operations |
| Export control | US EAR obligations attaching to advanced-computing GPUs: end-user and end-use screening, access restrictions, licence conditions, re-export discipline | GC | Screening at onboarding and continuously; annual programme audit; immediate reporting of concerns |
| AML / KYC | Customer, investor and vendor identity, beneficial ownership, source-of-funds and PEP/sanctions screening before contract and at renewal | GC · CFO | Screening logs reviewed quarterly; refresh cycle 12–36 months by risk tier |
| Data protection | Oman PDPL (RD 6/2022) and contractual data obligations; GDPR where customer data requires | GC | Records of processing; DPIAs for new services; breach notification per statute |
Compliance obligations are cascaded into contracts: customer agreements carry the security, audit and export-control clauses the Company itself must honour, and vendor agreements carry flow-down obligations proportionate to access and criticality. No waiver of a compliance obligation may be granted below the General Counsel, and none at all where the obligation is statutory.
Tier III design documents certified (TCDD) · ISMS scoped, policies drafted and approved · governance bodies wave 1 stood up (§3.2) · export-control and AML/KYC programmes live for procurement and pre-sales.
Tier III constructed facility certified (TCCF) · ISO 27001 certification audit passed · SOC 2 Type I report issued · operational committees rehearsed; BCP/DR exercised end-to-end.
SOC 2 Type II annually; ISO surveillance audits · ISO 22301 certification within 12 months · Uptime M&O assessment · annual compliance attestation to the Board.

The GPU fleet is subject to US Export Administration Regulations. The Company maintains a written Export Compliance Programme covering: classification of controlled items; end-user and end-use screening of every customer and access-holding vendor against US, UK, EU and UN restricted lists; contractual prohibitions on prohibited end-uses; physical and logical access restrictions consistent with licence conditions; and record-keeping sufficient for regulator audit. Commercial may not issue a proposal, and Operations may not grant access, before screening clears. Escalation of any red flag is to the General Counsel, with authority to freeze the engagement pending resolution.
Before contract signature the Company identifies each counterparty’s legal identity, ownership to ultimate beneficial owner, and source of funds where relevant; screens against sanctions and PEP lists; and assigns a risk tier that sets the refresh cycle and approval level. Enhanced due diligence applies to state-linked entities and intermediated structures. Suspicious-activity concerns are reported by the General Counsel in accordance with Omani law; tipping-off is prohibited.
As an infrastructure provider the Company does not access customer workload data; contracts define the boundary of responsibility. For personal data the Company does control — employees, visitors, CCTV, business contacts — it maintains records of processing, retention schedules and breach-notification procedures under the Oman PDPL, applying GDPR-equivalent safeguards where customer contracts require them.

The Board-approved Code of Conduct binds every director, employee and contractor, and — through contract — the personnel of managed service providers working on site. It covers lawful and honest dealing, respect and non-discrimination, protection of Company and customer assets and information, and the duty to report suspected breaches. Every person attests on joining and annually; attestation records are kept by HR and reported to the Audit & Risk Committee.
Actual, potential or perceived conflicts — financial interests in vendors or customers, outside positions, family relationships in reporting lines — are declared on appointment, annually, and immediately on arising. The General Counsel keeps the conflicts register. A conflicted person takes no part in the affected evaluation, negotiation or approval; for directors, recusal is minuted. Undeclared conflicts are treated as misconduct.
A confidential reporting channel, operated by an independent external provider in English and Arabic, is available to all personnel and to vendor and customer staff. Reports may be anonymous. The General Counsel triages every report; matters implicating an executive officer or the General Counsel go directly to the chair of the Audit & Risk Committee. Investigations are documented, time-bound and reported quarterly to that Committee. Retaliation in any form is itself a dismissible breach of the Code.
The Company prohibits bribery and corruption in all forms, including facilitation payments, in line with Omani law and the extraterritorial reach of the US FCPA and UK Bribery Act. Gifts and hospitality above a nominal threshold defined in the ABC Policy are pre-approved and recorded in a register reviewed quarterly by the General Counsel. Interactions with public officials, and the use of agents or intermediaries, require prior written GC approval. Procurement decisions are documented so that the basis of every award can be independently reconstructed.
The Company does not transact, directly or indirectly, with sanctioned persons, entities or territories under applicable US, UK, EU, UN or Omani measures. Sanctions screening is embedded in customer, vendor and investor onboarding (11.4) and re-run on list updates. Where sanctions exposure emerges mid-contract, the General Counsel has authority to suspend performance pending legal determination, and the matter is reported to the Board.

Continuity is governed under a Business Continuity Management System aligned with ISO 22301: a Board-endorsed policy, business impact analysis, documented continuity and disaster recovery plans, and an exercise programme. This section defines who decides what when normal operations fail.
The COO owns the BCMS and the readiness of every continuity capability — fuel autonomy, spares, alternate work arrangements, recovery procedures. The CTO owns platform and data recovery, including customer-facing RTO/RPO commitments. The CCO owns customer communication during disruption. The CFO owns emergency funding lines and insurance response. The General Counsel owns regulatory notification. The CEO decides, and the Board is informed within 24 hours of any crisis declaration.
| Level | Definition | Incident command | Notification & cadence |
|---|---|---|---|
| SEV-1 | Customer-affecting loss of service, loss of concurrent maintainability, confirmed security breach, or any threat to life | COO (security: CISO jointly) | CEO immediately; Board ≤ 24 h; affected customers per SLA; updates every 30 min until stable |
| SEV-2 | Redundancy consumed or material degradation without customer impact; near-miss with high potential severity | Operations Manager | COO ≤ 30 min; ExCo same day; updates hourly |
| SEV-3 | Single-system fault within redundancy; isolated customer ticket breaching response target | Shift Lead / NOC | Duty manager; daily ops report |
| SEV-4 | Minor anomaly, no service risk; logged for trend analysis | NOC | Weekly operations review |
Every SEV-1 and SEV-2 incident receives a blameless post-incident review within five business days, chaired by the Operational Risk Committee (or Cybersecurity Committee for security incidents), producing a root-cause analysis, corrective actions with owners and dates, and — where customer-affecting — an RFO report issued by Customer Success. Corrective actions are tracked to closure and audited.

A crisis is any event — operational, security, safety, legal or reputational — whose impact or duration exceeds what the incident organization can manage within normal authority. The CEO, or the COO acting in the CEO’s absence, declares a crisis and convenes the Crisis Management Team: CEO (chair), COO (site command), CTO, CISO, CCO (customer and external communication), CFO, General Counsel and HR, with the security provider’s site manager in attendance for physical events. The CMT assembles — physically or virtually — within 60 minutes of declaration, around the clock. It operates from a pre-agreed battle rhythm: situation report, decisions, communications, next review. All external statements are approved by the CEO on advice of the General Counsel; customer notifications follow contractual timelines owned by the CCO.
During a declared crisis, or where imminent danger to life, the environment, customer systems or service continuity leaves no time to convene normal authority, the senior person present may take any proportionate action — including shutdown, isolation, evacuation and emergency procurement within the monetary limits of Table 9-1. On site at night and weekends this is the Shift Lead; the NOC holds authority to execute pre-approved emergency operating procedures without further approval. Every emergency decision is logged contemporaneously, reported to the CEO within 12 hours, and ratified per Section 7.4. No one will be criticised for a good-faith emergency decision taken within this framework — failing to act is the governance failure.
The Disaster Recovery Plan defines recovery of the platform control plane, network management, BMS/DCIM and corporate systems, with recovery time and recovery point objectives approved by the Technology Committee and reflected in customer contracts by the CCO. DR readiness — backup integrity, restore tests, alternate management paths — is evidenced monthly to the Operational Risk Committee. Customer workload recovery remains the customer’s responsibility unless contracted otherwise; the boundary is stated in each service agreement.
| Exercise | Frequency | Scope |
|---|---|---|
| Emergency operating drills | Monthly, per shift | Utility failure, generator start, cooling loss, fire alarm response — every shift rehearses every scenario annually |
| Security incident-response exercise | Semi-annual | Tabletop plus technical simulation, including OT/BMS compromise and customer notification |
| Crisis Management Team exercise | Annual | Full CMT activation on an unannounced scenario, with Board observer; findings reported to the Board |
| DR restore test | Quarterly | Verified restore of control-plane and management systems against RTO/RPO |

Performance is governed through a fixed KPI set with named owners, defined targets and a single source of truth in the DCIM/BI stack. Targets are set with the annual budget and may be tightened, never silently relaxed; definitions change only by ExCo approval.
| Indicator | Target | Definition |
|---|---|---|
| Facility availability | ≥ 99.982 % | Tier III objective, measured at customer hand-off; monthly |
| Power usage effectiveness (PUE) | ≤ 1.44 annualised | Direct-liquid-cooled design basis; monthly with seasonal profile |
| SEV-1 incidents | 0 | Any occurrence triggers Board reporting and PIR |
| Preventive maintenance completion | ≥ 98 % on schedule | Deferrals require Operational Risk Committee approval |
| Change success rate | ≥ 99 % | CAB-approved changes completed without rollback or incident |
| Indicator | Target | Definition |
|---|---|---|
| SLA attainment | 100 % · credits = 0 | Per contract, reported to each customer monthly |
| Incident response within SLA | ≥ 99 % | First response and restoration clocks, all severities |
| Onboarding lead time | ≤ 30 days | Contract signature to first productive workload, standard config |
| Customer satisfaction | CSAT ≥ 4.5 / 5 | Quarterly survey and executive service reviews |
| Committed capacity contracted | per business plan | MW and GPU-hours contracted vs. plan; monthly to ExCo |
| Indicator | Target | Definition |
|---|---|---|
| GPU fleet availability | ≥ 99.0 % | Sellable node-hours net of failures and maintenance |
| Compute fabric availability | ≥ 99.95 % | InfiniBand and Ethernet fabrics, measured per partition |
| Failed node restore time | ≤ 4 h median | Detection to return-to-service, spares on site |
| Patch latency — critical vulnerabilities | ≤ 14 days | CVSS ≥ 9 remediated or compensated; reported to Cybersecurity Cttee |

| Indicator | Target | Definition |
|---|---|---|
| Revenue vs. plan | ≥ 95 % of budget | Monthly; variance bridge to ExCo |
| EBITDA margin | per business plan | Steady-state target set with budget; quarterly to Board |
| Debt service coverage ratio | ≥ 1.30× | Or per facility agreements if stricter; covenant headroom reported monthly |
| Capex variance — approved projects | ≤ +5 % | Against Investment Committee approval, incl. contingency use |
| Liquidity runway | ≥ 12 months | Cash plus committed facilities over fixed costs |
| Indicator | Target | Definition |
|---|---|---|
| Recordable safety incidents (TRIR) | 0 target | Employees and contractors; monthly to ExCo, quarterly to Board |
| Water usage effectiveness (WUE) | design target | Set at commissioning for the closed-loop liquid cooling plant; monthly |
| Carbon intensity & renewable share | reported | kgCO₂e/kWh and % renewable supply; annually with reduction plan |
| Omanisation | ≥ statutory target | National workforce share with development pathways; quarterly |
| Ethics training completion | 100 % | Induction and annual refresh, incl. contractor site staff |
KPIs flow through the reporting framework at Section 15: daily operational indicators in the NOC report, the full set monthly to the ExCo with variance commentary, and quarterly to the Board with trend and peer benchmarks. Executive scorecards derive directly from this KPI set, and the Remuneration & Nomination Committee ties variable compensation to them — availability, safety and compliance measures gate all other incentives: a SEV-1 breach of the safety or compliance appetite zeroes the affected scorecard for the period.

Reporting follows the management line shown at Appendix C, on a fixed calendar. Every report has a named producer, a defined audience and a stable format, so that trends are comparable period over period. Exceptions and threshold breaches are reported when they occur — never held for the next cycle.
| Cadence | Report | Producer → audience | Content |
|---|---|---|---|
| Daily | Operations report | NOC → COO, duty executives | Availability, incidents and status, works completed and planned, capacity headroom, weather/utility outlook |
| Weekly | Executive dashboard | Divisions → ExCo | KPI snapshot, change calendar, pipeline and onboarding, hiring, top risks movement, action log |
| Monthly | Management pack & Board flash | CFO with divisions → ExCo, Board | Full KPI set with commentary, financials vs. budget, covenant headroom, project status (development phase), DoA exceptions |
| Quarterly | Board pack; committee reports; customer service reviews | CEO / committee chairs → Board; CS → customers | Strategy progress, financial statements, risk register review, compliance and audit status, whistleblower summary, lender reporting |
| Annual | Audited statements; certification attestations; governance review | CFO, GC, auditors → Board, shareholders, lenders | Audited financial statements, ISO/SOC reports, insurance renewal, ESG report, Charter review outcome (Section 17) |
All periodic reporting draws from a single governed data layer — DCIM, the platform telemetry stack and the finance system — so that the Board, lenders and customers see the same numbers. Manual adjustments are disclosed. Report owners certify accuracy; material restatements are reported to the Audit & Risk Committee with cause. External reporting to investors, lenders and customers is released only through the CFO (financial) or CCO (service), on formats agreed in the underlying contracts.

This Charter sits at the top of a controlled document hierarchy. The register below lists the supporting corporate documents; each is version-controlled by the Corporate Secretary, and the versions relied upon in due diligence are those in the controlled data room.
| Reference | Document | Owner | Approver | Review |
|---|---|---|---|---|
| PRM-ORG-2026-001 | Organization Structure | CEO | Board | Annual |
| PRM-DOA-2026-001 | Delegation of Authority Matrix | CFO | Board | Annual |
| PRM-RACI-2026-001 | RACI Matrix — full decision inventory | CEO | ExCo | Annual |
| PRM-ISP-2026-001 | Information Security Policy (ISMS) | CISO | ExCo | Annual |
| PRM-RMF-2026-001 | Risk Management Framework | GC · CFO | Board | Annual |
| PRM-VMP-2026-001 | Vendor Management Policy | CFO | ExCo | Annual |
| PRM-PRC-2026-001 | Procurement Policy | CFO | ExCo | Annual |
| PRM-CSP-2026-001 | Cybersecurity Policy suite (access, network, OT, crypto) | CISO | Cybersecurity Cttee | Annual |
| PRM-IRP-2026-001 | Incident Response Plan | CISO · COO | ExCo | Semi-annual |
| PRM-BCP-2026-001 | Business Continuity & Disaster Recovery Plans | COO | ExCo | Semi-annual |
| PRM-COC-2026-001 | Code of Conduct & ethics policies (COI, ABC, whistleblower) | GC | Board | Annual |
| PRM-PSP-2026-001 | Physical Security Policy | COO · CISO | ExCo | Annual |
| PRM-SEC-2026-001 | Physical Security & Access Control Specification | CISO · COO | ExCo | Annual |
| PRM-SLA-2026-001 | Service Level Agreement — availability, credits, triggers | COO | Board | Annual |
| PRM-EXP-2026-001 | Export Compliance Programme & AML/KYC Procedures | GC | Board | Annual |
Documents are drafted to be certifiable: the ISMS and BCMS documents follow ISO structure so that certification audits test the documents the Company actually uses, not parallel paperwork. Where a document named here does not yet exist at adoption of this Charter, its stand-up date appears in the pre-RFS certification roadmap (Section 11.2) and its owner reports progress monthly.

The Charter is reviewed annually, completing no later than the second quarter, so that any changes take effect with the budget-year governance calendar. The review is led by the General Counsel & Corporate Secretary under the direction of the Audit & Risk Committee, and concludes with Board re-approval of the Charter — amended or unchanged — recorded by resolution.
Between annual reviews, amendments may be initiated by the Board, the CEO or the General Counsel where a material change requires it — new financing covenants, a change in law or sanctions regime, a certification finding, or a structural change to the organization. Interim amendments follow the same drafting and approval path, and are consolidated at the next annual review. Editorial corrections that do not alter authority or obligation may be made by the Corporate Secretary and noted to the Board.
The review reports against fixed indicators: reserved matters decided with complete papers on first presentation; DoA exceptions per period and their disposition; escalations meeting the timeframes at Section 7.3; committee meeting and quorum discipline; audit findings closed on schedule; whistleblower cases resolved within target; and training and attestation completion. Persistent misses are treated as design defects of the framework — not merely performance failures of individuals — and drive amendment.

Core organization at steady state — 104 FTE at full build-out of both phases, ramping from 88 FTE in Phase 1. Full staffing detail in PRM-ORG-2026-001.
| # | Function | Division | Reports to | FTE |
|---|---|---|---|---|
| 01 | Executive management — CEO · COO · CTO · CCO · CFO | Executive | Board | 5 |
| 02 | Data Center OperationsOps Manager · four shifts of 7 · 24×7 | Operations | COO | 29 |
| 03 | Facilities & Critical InfrastructureElectrical · mechanical · HVAC · UPS/gen · BMS | Operations | COO | 13 |
| 04 | Network Operations Center24×7 monitoring & escalation | Operations | COO | 10 |
| 05 | Infrastructure EngineeringLinux · GPU · K8s/Slurm · storage · automation · architect | Technology | CTO | 21 |
| 06 | Network EngineeringInfiniBand · Ethernet · DWDM | Technology | CTO | 6 |
| 07 | Information SecurityCISO · engineering · analysts · IAM · compliance | Technology | CTO | 6 |
| 08 | CommercialDirector · enterprise sales ·2 · customer success ·2 · solutions ·2 | Commercial | CCO | 7 |
| 09 | Finance & ProcurementController · accountant · procurement · treasury/vendor | Corporate | CFO | 4 |
| 10 | HR & Administration | Corporate | CEO | 2 |
| 11 | Legal & Compliance | Corporate | CEO | 1 |
| Core organization — Ops 52 · Tech 33 · Comm 7 · Corp 7 · Exec 5 | 104 |

Financial integrity · audit · internal control · risk framework · compliance · whistleblower · cyber oversight
Executive remuneration · incentives · succession · Board composition
| Committee | Freq. | Mandate | Secondary reporting |
|---|---|---|---|
| Technology Committee | M | Chair CTO · standards, capacity, roadmap | ↳ Change Advisory Board — weekly, chair Eng. Manager |
| Operational Risk Committee | M | Chair COO · risk register, incidents, maintenance plan | ⇢ also reports to Audit & Risk Cttee |
| Cybersecurity Committee | M | Chair CISO · ISMS review, exceptions, IR readiness | ⇢ also reports to Audit & Risk Cttee |
| Investment Committee | M | Chair CFO · capex 250k–5M, capital plan | ⇢ recommends > US$ 5M to the Board |
| Health & Safety Committee | M | Chair COO · HSE programme, drills, investigations | ⇢ lost-time incidents to the Board |
| Procurement Committee | F | Chair CFO · tenders, awards 100k–1M, vendor register | ⇢ endorses larger awards to Investment Cttee |

Solid reporting lines, secondary (functional) lines, and the standing forums each role attends.
| Role | Reports to | Secondary line | Standing forums |
|---|---|---|---|
| Chief Executive Officer | Board | — | Board · ExCo (chair) · Investment Cttee · CMT (chair) |
| Chief Operating Officer | CEO | — | ExCo · Operational Risk (chair) · H&S (chair) · Investment |
| Chief Technology Officer | CEO | — | ExCo · Technology (chair) · Cybersecurity · Investment |
| Chief Commercial Officer | CEO | — | ExCo · Investment · Technology (customer requirements) |
| Chief Financial Officer | CEO | Audit & Risk Cttee (reporting) | ExCo · Investment (chair) · Procurement (chair) |
| General Counsel & Corporate Secretary | CEO | Chair & A&R Cttee — unqualified access | Board (secretary) · ExCo · Procurement · CMT |
| Head of HR & Administration | CEO | — | ExCo (standing attendee) · H&S |
| CISO | CTO | CEO & A&R Cttee — direct escalation | Cybersecurity (chair) · Operational Risk · Technology · CAB |
| Operations Manager | COO | — | Operational Risk · H&S · CAB · daily ops review |
| Facilities Manager | COO | — | Operational Risk · H&S (deputy chair) · CAB |
| NOC Manager | COO | — | Operational Risk · Cybersecurity · CAB · daily ops report |
| Engineering Manager, Infrastructure | CTO | — | Technology · CAB (chair) · Operational Risk |
| Network Manager | CTO | — | Technology · CAB |
| Commercial Director | CCO | — | Weekly pipeline review · Investment (deal papers) |
| Financial Controller · Procurement Manager | CFO | — | Procurement (secretary) · Investment (papers) · month-end close |
| Security provider site manager (MSP) | COO (operational) | Audited by Information Security | H&S · CMT (physical events) · vendor reviews |

Accountability by domain across the Executive Leadership Team. One A per domain; the CISO acts within the CTO column for security domains with the independence safeguards at Section 8.7.
| Domain | CEO | COO | CTO | CCO | CFO | GC | HR |
|---|---|---|---|---|---|---|---|
| Strategy, financing & investor relations | A | C | C | C | R | C | — |
| Facility availability & Tier III operations | I | A | C | I | — | — | — |
| Compute platform, network & roadmap | I | C | A | C | I | — | — |
| Cybersecurity & ISMS (via CISO) | I | C | A | I | — | C | — |
| Physical security oversight | I | A | R | — | C | — | — |
| Revenue, pricing & customer contracts | C | — | C | A | C | C | — |
| SLA performance & customer reporting | I | R | R | A | — | — | — |
| Financial control, treasury & lender reporting | I | — | — | — | A | C | — |
| Procurement & vendor management | I | C | C | — | A | C | — |
| Legal, ethics, export control & sanctions | I | C | C | C | C | A | C |
| People, Omanisation & training records | A | C | C | C | C | — | R |
| Business continuity & crisis management | R | A | R | R | C | C | C |
| Health & safety | I | A | C | — | — | C | R |
| ESG measurement & reporting | A | R | C | — | R | — | R |

Escalation paths by scenario. The clock starts at detection; a step that cannot reach its escalation contact within the stated window escalates past them. Severity definitions at Section 13.2.
| Scenario | First response | Escalation path | Decision authority | Notification clock |
|---|---|---|---|---|
| Facility incident — SEV-1 | Shift Lead + EOPs | NOC → Shift Lead → Ops Manager → COO → CEO | COO (incident command); CEO if crisis declared | CEO immediate · Board ≤ 24 h · customers per SLA |
| Security incident — confirmed or suspected breach | NOC / Security Analyst + IR plan | Analyst → CISO → CTO · GC → CEO | CISO — isolation without prior approval; GC — notification decisions | CEO ≤ 2 h · A&R chair ≤ 24 h · statutory clocks per PDPL/contract |
| Safety incident — injury or dangerous occurrence | Any person — stop work; Shift Lead | Shift Lead → Facilities Mgr → COO · HR | COO; site remains stopped until H&S clearance | CEO same day · Board — any lost-time incident · regulator per law |
| Customer executive escalation | Customer Success | CS → Commercial Director → CCO → CEO | CCO; commercial remedies within DoA | CCO ≤ 4 h · CEO ≤ 24 h for strategic accounts |
| Financial — covenant risk or material variance | Financial Controller | Controller → CFO → CEO → Board / lenders | CFO; Board for waiver requests | CEO ≤ 24 h of identification · Board before any lender notice |
| Legal / regulatory — contact, claim or investigation | Recipient — refer, do not respond | Any staff → GC → CEO → Chair | GC; Board for material litigation (4.5) | GC same day · Board ≤ 24 h if material |
| Critical vendor failure — security MSP, OEM, utility, carrier | Supervising function | Function head → COO/CTO → Procurement Cttee | Accountable executive; exit/substitution per contingency plan | ExCo next sitting · immediately if service risk |
| Ethics — whistleblower report or suspected fraud | External channel / GC | Channel → GC → A&R chair (bypasses management if implicated) | GC; A&R Committee for executive matters | Triage ≤ 5 days · quarterly summary to A&R |

Annual rhythm of governance events. Standing cadences: ExCo weekly · CAB weekly · management committees monthly (Procurement fortnightly) · monthly management pack and Board flash.
| Body / event | Q1 | Q2 | Q3 | Q4 |
|---|---|---|---|---|
| Board of Directors | Q meeting · FY results & audited statements | Q meeting · Charter re-approval · AGM matters | Q meeting · insurance renewal · capacity roadmap | Q meeting + strategy session · budget & capital plan approval |
| Audit & Risk Committee | External audit close-out · control findings | Risk register deep-dive · governance review report | Internal audit plan · cyber posture review | External audit planning · compliance attestations |
| Remuneration & Nomination | Prior-year scorecards · incentive outcomes | — | Succession review | Objectives & packages for next year |
| Certification & assurance | SOC 2 period opens · statutory filings | ISO 27001 surveillance audit | Penetration test · ISO 22301 exercise evidence | SOC 2 Type II report issued · vendor audits complete |
| Continuity & crisis readiness | DR restore test · BIA refresh | DR restore test · security IR exercise | DR restore test · CMT full exercise (unannounced) | DR restore test · security IR exercise · plan updates |
| Policy & framework reviews | Charter review evidence gathering (17.1) | Charter & DoA re-approved · Code of Conduct attestation | Security policy suite review · vendor tiering refresh | Risk appetite review with budget · ESG report |

| ABC | Anti-bribery & corruption |
|---|---|
| AML | Anti-money laundering |
| A&R | Audit & Risk Committee of the Board |
| BCMS | Business continuity management system |
| BCP / DRP | Business continuity / disaster recovery plan |
| BIA | Business impact analysis |
| BMS | Building management system |
| CAB | Change Advisory Board |
| CMT | Crisis Management Team |
| CRAH | Computer-room air handler |
| CSAT | Customer satisfaction score |
| DCIM | Data centre infrastructure management |
| DoA | Delegation of Authority |
| DSCR | Debt service coverage ratio |
| DWDM | Dense wavelength-division multiplexing |
| EAR | US Export Administration Regulations |
| ELT | Executive Leadership Team |
| EOP / MOP / SOP | Emergency / method / standard operating procedure |
| EPC | Engineering, procurement & construction |
| ExCo | Executive Committee |
| FCPA | US Foreign Corrupt Practices Act |
| FTE | Full-time equivalent |
| GC | General Counsel & Corporate Secretary |
| IAM | Identity & access management |
| ISMS | Information security management system |
|---|---|
| KPI | Key performance indicator |
| KYC | Know your customer |
| M&O | Uptime Institute Management & Operations |
| MEP | Mechanical, electrical & plumbing |
| MSP / MSA | Managed service provider / agreement |
| NOC | Network Operations Center |
| OEM | Original equipment manufacturer |
| OT | Operational technology |
| PDPL | Oman Personal Data Protection Law (RD 6/2022) |
| PEP | Politically exposed person |
| PIR | Post-incident review |
| PM | Preventive maintenance |
| PUE / WUE | Power / water usage effectiveness |
| RACI | Responsible · Accountable · Consulted · Informed |
| RFO | Reason for outage |
| RFS | Ready for service — start of commercial operations |
| RTO / RPO | Recovery time / point objective |
| SEV | Incident severity level (Section 13.2) |
| SLA | Service level agreement |
| SOC 2 | AICPA Trust Services attestation |
| TCDD / TCCF | Uptime Tier Certification of Design Documents / Constructed Facility |
| TCV | Total contract value |
| TRIR | Total recordable incident rate |
For questions on this Charter, the delegation of authority or the governance document register. Issued in draft (v0.1) — substantive revision anticipated before Board adoption.