
Which roles are critical, what each must hold and prove, how competence is assessed before a person is authorised to work on the critical path, and the three-level screening applied before anyone holds a credential.

This policy governs the competence and integrity of every person who works at the KOM Oman AI Factory. It covers the 104 FTE core organization set out in PRM-ORG-2026-001, and it applies in the same terms to contractors and managed-service personnel who hold an entitlement at the site.
Two principles run through it. First, a credential is not a competence — a certificate proves examined knowledge, an authorisation to work proves demonstrated capability on this plant, and the second is what governs who may touch the critical path. Second, screening precedes credentialing — no access entitlement is provisioned until the screening level for the role has been completed and recorded.
A role is designated critical if it meets any one of the following. The designation drives both the certification requirement and the screening level.
| Related documents | PRM-ORG-2026-001 Organizational Structure · PRM-SEC-2026-001 Physical Security & Access Control · PRM-IRP-2026-001 Incident Response Plan · PC-ECP-001 Export Compliance Policy · PRM-GOV-2026-001 Corporate Governance Charter |
|---|---|
| Owner | The HR Manager owns the programme and the records. The CISO owns screening standards and the vetting decision. The COO owns authorisation to work on the critical path. |
| Review cycle | Annually, and on any change to the organization, the layered access model or applicable Omani employment and data-protection law. |
| Status and distribution | Controlled internal document. Released to customers, partners and lenders where the engagement protocol requires it. Figures are indicative until the organization is staffed. |

Every role in the core organization, its headcount at full build-out, whether it is designated critical under section 1.1, and the screening level that follows. Phase 1 staffs 88 of these; Phase 2 adds the remaining 16.
| Role | FTE | Critical test met | Authorisation held | Screening |
|---|---|---|---|---|
| Executive — 5 FTE | ||||
| CEO · COO · CTO · CCO · CFOExecutive management | 5 | Tests 2, 3 | Site-wide entitlement; no unsupervised critical-path work | Level 3 |
| Operations — COO · 52 FTE | ||||
| Operations ManagerDays | 1 | Tests 1, 2 | Approves hall work; escalation authority | Level 3 |
| Shift LeadShifts A–D | 4 | Tests 1, 2 | Shift command; authorises smart hands | Level 3 |
| DC EngineerSix per shift | 24 | Test 2 | Rack work, hardware replacement, escort | Level 3 |
| Facilities Manager | 1 | Tests 1, 2 | Approves all MEP work and switching | Level 3 |
| Electrical Engineer | 4 | Test 1 | LV and MV switching, authorised person | Level 3 |
| Mechanical Engineer | 3 | Test 1 | Cooling plant isolation and return to service | Level 3 |
| HVAC Engineer | 3 | Test 1 | Air-side plant, CRAH, refrigerant work | Level 3 |
| UPS / Generator Specialist | 1 | Test 1 | UPS, battery and generator operations | Level 3 |
| BMS Engineer | 1 | Tests 1, 3 | BMS administration and setpoint change | Level 3 |
| NOC Manager | 1 | Tests 1, 3 | Incident command to P2; monitoring platform | Level 3 |
| Senior NOC Engineer | 4 | Test 3 | Escalation, availability declaration | Level 3 |
| NOC Engineer | 5 | Test 3 | Monitoring and first-line response | Level 2 |
| Technology — CTO · 33 FTE | ||||
| Engineering Manager · Infrastructure Architect | 2 | Tests 1, 3 | Platform change approval; standards | Level 3 |
| Linux Platform Engineer | 5 | Test 1 | Fleet administration, privileged access | Level 3 |
| GPU Engineer | 4 | Tests 1, 2 | GPU systems, firmware, power capping | Level 3 |
| Kubernetes / Slurm Engineer | 4 | Test 1 | Scheduling platform administration | Level 3 |
| Storage Engineer | 3 | Test 1 | Storage tier, customer namespaces | Level 3 |
| Automation Engineer | 3 | Test 1 | Pipeline and configuration authority | Level 3 |
| Network Manager · Network Engineer | 6 | Test 1 | Fabric configuration and routing | Level 3 |
| CISO | 1 | Tests 2, 3 | All control systems; vetting decision | Level 3 |
| Security Engineer · Analysts · IAM · Compliance | 5 | Test 3 | Control-system administration and audit | Level 3 |
| Commercial and Corporate — 14 FTE | ||||
| Solutions Architect | 2 | Test 2 | Escorted hall access for customer work | Level 2 |
| Commercial · Finance · Procurement · HR · LegalNon-critical corporate roles | 12 | — | Interior zone entitlement; escorted beyond | Level 1 |
| Core organization | 104 | 92 FTE meet at least one critical test · 12 FTE meet none | — | |

Mandatory means the role may not be filled, or an incumbent may not work unsupervised, without it. Target means it is required within the stated period from appointment and funded by Prima. Renewal follows the awarding body's cycle unless a shorter one is stated.
| Role | Certification | Status | Renewal |
|---|---|---|---|
| Operations Manager | EPI CDFOM or Uptime Institute Accredited Operations Professional · ITIL 4 Foundation · Permit-to-work authoriser | Mandatory | 3 years |
| Shift Lead | Uptime AOP or CNet CDCTP · Incident command (internal, assessed) · First aid at work | Mandatory | 3 years |
| DC Engineer | CNet CDCTP or equivalent data-centre technician programme | Target · 12 mo | 3 years |
| DC Engineer | Structured cabling and fibre handling · ESD discipline · Rack and PDU safety | Mandatory | 2 years |
| All hall personnel | Liquid-cooling handling: CDU operation, leak response, coolant discipline | Mandatory | Annual |
| Role | Certification | Status | Renewal |
|---|---|---|---|
| Facilities Manager | EPI CDFOM or equivalent · Permit-to-work authoriser · Senior authorised person, electrical | Mandatory | 3 years |
| Electrical Engineer | Omani electrical trade licence at the level of the work · Authorised person, LV and MV switching · Arc-flash and electrical safety to NFPA 70E | Mandatory | Annual |
| Mechanical Engineer | Chilled-water systems · Pressure systems awareness · Chiller OEM programme for installed plant | Mandatory | 2 years |
| HVAC Engineer | Refrigerant handling to the applicable Omani and F-Gas equivalent standard · CRAH and air-side OEM programme | Mandatory | 2 years |
| UPS / Generator Specialist | UPS OEM certification · Generator OEM certification · Battery handling and spill response · Fuel systems | Mandatory | 2 years |
| BMS Engineer | BMS platform vendor certification for the installed system · EPMS familiarisation · OT security awareness | Mandatory | 2 years |
| All Facilities | Water-system hygiene and Legionella awareness · Confined space where applicable · Working at height where applicable | Mandatory | Annual |
| Role | Certification | Status | Renewal |
|---|---|---|---|
| NOC Manager | ITIL 4 Foundation · Incident command, assessed to P2 · Monitoring platform administration | Mandatory | 3 years |
| Senior NOC Engineer | ITIL 4 Foundation · Availability measurement and declaration, assessed internally against PRM-SLA-2026-001 | Mandatory | Annual |
| NOC Engineer | Monitoring platform operation · Escalation procedure, assessed · ITIL 4 Foundation | Target · 9 mo | 3 years |

| Role | Certification | Status | Renewal |
|---|---|---|---|
| Engineering Manager Infrastructure Architect | Senior certification in at least one platform discipline below · Change-authority assessment, internal | Mandatory | 3 years |
| Linux Platform Engineer | RHCSA minimum, RHCE target · Privileged-access discipline, assessed | Mandatory | 3 years |
| GPU Engineer | NVIDIA Certified Professional — AI Infrastructure or equivalent DGX programme · Firmware and power-capping procedure, assessed | Mandatory | 2 years |
| Kubernetes / Slurm Engineer | Certified Kubernetes Administrator · Slurm operation · CKS target for those with cluster-security duties | Mandatory | 3 years |
| Storage Engineer | Vendor certification for the installed storage tier · Customer namespace isolation, assessed | Mandatory | 2 years |
| Automation Engineer | Infrastructure-as-code certification, Terraform Associate or equivalent · Change-pipeline discipline, assessed | Target · 12 mo | 2 years |
| Role | Certification | Status | Renewal |
|---|---|---|---|
| Network Manager | Professional-level routing and switching certification · Change-authority assessment, internal | Mandatory | 3 years |
| Network Engineer | NVIDIA Certified Professional — InfiniBand or equivalent fabric certification · Professional-level Ethernet certification · Optical and DWDM vendor programme | Mandatory | 2 years |
| Role | Certification | Status | Renewal |
|---|---|---|---|
| CISO | CISSP or CISM · ISO/IEC 27001 Lead Implementer · Vetting-decision authority, assessed internally | Mandatory | 3 years |
| Security Engineer | Security engineering certification · GICSP or equivalent for OT-facing duties | Mandatory | 3 years |
| Security Analyst | Security operations certification · Log and evidence handling, assessed | Target · 12 mo | 3 years |
| IAM Specialist | Identity platform certification · Access-recertification procedure per PRM-SEC-2026-001, assessed | Mandatory | 2 years |
| Compliance Specialist | ISO/IEC 27001 Lead Auditor · Export-control administration per PC-ECP-001, assessed | Mandatory | 3 years |
Required of every employee and of every contractor holding an entitlement, regardless of role or division. Completion is a precondition of first entry, not a task to be caught up.
| Requirement | Content | Renewal |
|---|---|---|
| Site safety induction | Hazards, emergency routes, assembly points, reporting duty, prohibited acts | Annual |
| Fire safety and evacuation | Detection and suppression behaviour, evacuation drill participation | Annual |
| Physical security and access | Layered model, tailgating, challenge duty, escort obligations per PRM-SEC-2026-001 | Annual |
| Information security awareness | Phishing, credential hygiene, data handling, media discipline, reporting | Annual |
| Incident reporting | Classification, first response, escalation path per PRM-IRP-2026-001 | Annual |
| Export-control awareness | Controlled technology, prohibited destinations and end uses, escalation per PC-ECP-001 | Annual |
| Code of conduct and anti-bribery | Conflicts, gifts, facilitation payments, whistleblowing channel | Annual |

A certificate proves examined knowledge. Authorisation to work proves demonstrated capability on this plant, on these procedures, witnessed by someone already authorised. The two are separate and the second is what governs the critical path.
| Stage | Typical period | What happens | May the person work alone? |
|---|---|---|---|
| Induction | Week 1 | Universal requirements of section 05 completed. Screening already closed before day one. | No access beyond escorted |
| Familiarisation | Weeks 2–8 | Plant walk-downs, MOP and SOP reading with sign-off, shadowing an authorised person. | No — supervised only |
| Assessed practice | Months 2–6 | Performs procedures under witness. Each procedure signed off individually, not in bulk. | Only signed-off procedures |
| Authorised | From month 6 | Named on the authorisation register for a defined scope of work, approved by the discipline manager and the COO. | Yes, within scope |
A single register records, for each named person, the exact scope they may perform unsupervised — which switching operations, which isolations, which platform changes. It is the document a shift lead consults before assigning work, and it is the document an auditor samples.
| Exercise | Frequency | Who participates · what it evidences |
|---|---|---|
| Emergency operating procedure walkthrough | Quarterly | Each shift in turn · that the on-duty team can execute an EOP without reading it cold |
| Incident response exercise | Quarterly | NOC, Operations, Facilities, InfoSec · command handover and escalation timing per PRM-IRP-2026-001 |
| Evacuation drill | Semi-annual | All site personnel and contractors on site · muster discipline and roll call |
| Tabletop — loss of a critical system | Semi-annual | Executive and discipline managers · decision-making under degraded conditions |
| Cyber incident tabletop | Annual | InfoSec, Technology, Executive, Legal · containment and notification decisions |

Screening is completed and recorded before an access entitlement is provisioned. There is no provisional or conditional credential. The level is set by the role, per the register in section 02, and the vetting decision rests with the CISO — not with the hiring manager, whose interest is in filling the post.
| Screening element | Level 1 · Standard | Level 2 · Enhanced | Level 3 · Critical |
|---|---|---|---|
| Identity and right to workPassport, residency, work permit | Required | Required | Required |
| Criminal record clearanceRoyal Oman Police, plus country of residence | Required | Required | Required |
| Employment history verified | 5 years | 10 years | 10 years, no gaps |
| References taken | 2 | 2, one a manager | 3, two managers |
| Education and professional qualification | Highest claimed | All claimed | All, verified at source |
| Sanctions and PEP screeningPer PC-ECP-001 | Required | Required | Required |
| Adverse media search | — | Required | Required |
| Financial probityCredit and insolvency check | — | — | Required |
| Security interviewConducted by the CISO or delegate | — | — | Required |
| Declaration of interests and side employment | Required | Required | Required, annual |
| Re-screening cycle | 3 years | 2 years | Annual |
| Lawful basis | Screening is conducted on the basis of the employment relationship and Prima's legitimate interest in the security of critical infrastructure, with the candidate's informed written consent obtained before any search is run. |
|---|---|
| Minimisation | Only the outcome of each element is retained — cleared, cleared with conditions, or not cleared — together with the date and the deciding officer. Underlying source documents are destroyed once the outcome is recorded, save where law requires retention. |
| Retention | Screening outcomes for the duration of the engagement plus two years. Training and certification records for the duration plus five years, to allow historical competence to be evidenced in an incident review. |
| Access | Screening records are held by HR under CISO control, separate from the general personnel file. Line managers see the level and the outcome, never the underlying detail. |

The outsourced services listed in PRM-ORG-2026-001 — physical security officers, cleaning, HVAC and generator OEM maintenance, fire protection — are not in the 104 FTE, but their personnel stand inside the same perimeter. They are screened and trained to the level of the access they hold, not the level of their employer's own policy.
| Screening standard | The provider screens to the Prima level for the entitlement held and attests to it in writing per person. Prima audits a sample of at least 10% of attestations annually, and every attestation for Level 3 entitlements. |
|---|---|
| Universal training | Section 05 requirements are delivered by Prima, not by the provider, and are a precondition of first entry. A contractor without them is a visitor and is escorted. |
| Authorisation to work | OEM technicians work on the critical path under a Prima-authorised supervisor and a permit to work. An OEM certificate does not confer authorisation on our plant. |
| Provider change | A change of provider personnel is notified before first entry. Entitlements are person-specific; there is no shared or pooled credential. |
| Event | Action | Timing |
|---|---|---|
| Role change | Re-screen to the receiving level; entitlements of the leaving role revoked as the new ones are granted, never left in place "for handover" | Before effective date |
| Resignation or end of contract | All entitlements revoked; credentials, keys and devices recovered; authorisation register entry closed | By end of last shift |
| Summary termination | Entitlements revoked before notification; escorted from site; access log reviewed for the preceding 30 days | Immediate |
| Extended absence over 3 months | Entitlements suspended; authorisation reassessed before reinstatement | On the 90th day |
Per person: screening level and outcome, certifications with expiry, procedures signed off, authorised scope, exercise participation.
Per person: the enumerated scope of unsupervised work, approving manager, date, and reassessment due date.
Automated alerting at 90, 60 and 30 days before any certification or authorisation lapses, to the holder and the discipline manager.
| Monthly report | To the COO: certification compliance by discipline, authorisations granted and withdrawn, expiries inside 90 days, exercise completion. |
|---|---|
| Quarterly report | To the Executive Leadership Team: screening throughput, adverse findings and their disposition, contractor attestation audit results, open remediation. |
| Annual report | To the Audit & Risk Committee per PRM-GOV-2026-001: full compliance position, matrix changes, and the effectiveness of the programme against incidents in the period. |
| External audit | Records are available to ISO/IEC 27001 and SOC 2 auditors, to certification bodies, and to customers exercising audit rights under the Master Services Agreement. |
For questions on this policy, the certification matrix, or the screening standard applied to a specific role or contract.