Where Risk Management Adds Value in Data Centre Projects

In this article:
AI is driving a historic expansion of data centre infrastructure. According to the International Energy Agency, global electricity consumption from data centres is expected to more than double by 2030, reaching around 945 TWh. At the same time, growing demand for computing capacity, grid constraints and the increasing role of data centres in critical digital services are reshaping how facilities are designed, built and operated.
For owners, developers, and operators, this changes the operating reality. Data centres are physical assets underpinning services that businesses, public functions, and end users increasingly expect to be continuously available. Downtime can disrupt operations far beyond the facility itself.
A structured approach to risk management helps owners and project teams translate these challenges into practical decisions throughout the project lifecycle, from concept and commissioning to operation.
Redundancy is Necessary, But Availability Depends on More
Data centres are designed for high availability. Redundant power supply, UPS systems, generators, cooling capacity, fire detection and protection, and security arrangements are examples of essential measures. Their value, however, depends on how they are configured, tested, operated and fit together when the facility is under stress.
This is especially important during transitions and degraded operation: switching from normal to backup power, restoring cooling after a disturbance, performing maintenance with reduced redundancy, or expanding capacity while the facility remains in operation. These are the moments when the design, operating procedures and emergency response arrangements must work in practice, not only on paper.
Data centres are also shaped by constraints beyond the site boundary. Grid capacity, water availability, fuel logistics, permitting requirements, and the surrounding security environment can affect both project delivery and operational reliability.
The practical question is whether the project can establish, demonstrate and sustain the required level of availability from early site selection and concept development through design, commissioning and operation.
Where Risks Typically Emerge
A structured risk assessment helps translate availability requirements into practical discussions and concept selections. The objective is not only to confirm that systems are redundant or safe, but to examine how failures, dependencies and operating responses could affect the required level of availability. The examples below are not a complete checklist for risk assessments, but illustrate typical areas to be discussed.
Risk area | Examples of discussion points |
Power and electrical systems | Are grid connection, protection coordination, UPS performance, generator start reliability, switching sequences, fuel logistics and backup-power testing robust under realistic operating conditions? |
Cooling and thermal management | Can cooling be maintained, restored and controlled following disturbances, especially at higher AI-related workload densities where the electrical and mechanical systems interact closely? |
Fire and life safety | Do detection, suppression, compartmentation, isolation and emergency response arrangements protect people, assets and service availability across electrical rooms, battery systems, cable routes and fuel infrastructure? |
Physical security systems and building control systems | Which assets are critical, which threats are credible, and are prevention, detection, delay, response, segmentation, alarm handling and manual override procedures proportionate? |
Interfaces and handover | Are responsibilities, procedures, documentation and management of change tested across contractors, utilities, IT, operations and emergency services? |
Table 1. Typical risk areas affecting data centre availability.
Publicly reported incidents show how failures in cooling, power, fire protection and operational response can combine in practice. During the July 2022 UK heatwave, a Google Cloud data centre in London experienced a simultaneous failure of multiple redundant cooling systems. The service impact was then extended by operational routing changes made during the response. The case highlights that operator response under stress can be as important as the initiating technical failure.
In October 2022, a fire at the SK C&C data centre in Pangyo disrupted services for Kakao and Naver. Subsequent reporting highlighted concerns relating to battery and UPS arrangements, fire detection, isolation and emergency response. The case illustrates how layout and response decisions can influence whether a localised event develops into a wider service disruption.
The recurring pattern is that availability risks rarely sit neatly inside one discipline. They emerge from the interaction between physical infrastructure, design choices, backup architecture and operational response.
HSE and Risk Roadmap
To support timely project decisions, availability requirements must be translated into actions across the project lifecycle. Owners and project teams need to identify which HSE and risk studies should inform each phase, what decisions those studies must support, and which regulatory, standards and assurance requirements must be addressed early enough to influence design, procurement, commissioning and operation.
Figure 1 provides an indicative EU/EEA roadmap for medium-to-large data centre projects. The exact requirements will depend on project size, location, operating model and customer or tenant mix.

Figure 1. Indicative HSE and risk roadmap for data centre projects, including key project phases and regulatory/assurance touchpoints for medium-to-large EU/EEA facilities.
Figure 1 should be read from left to right. Early project phases are where site constraints, availability expectations and major risk contributors should be identified. Design and engineering then translate these requirements into technical safeguards, maintainability provisions and testing requirements. During construction and commissioning, the focus shifts to interface management, integrated testing and evidence for handover. In operation, the priority is to keep the risk picture current through management of change, periodic reassessment, emergency drills and incident learning.
Several of the methods referenced in the roadmap (HAZID, HAZOP, E-HAZOP, FMECA, RAM analysis, electrical and fire risk assessments, and physical/cyber security reviews) are covered in dedicated ORS insights, providing further detail for readers who want to explore the methodology behind the project-phase view.
The regulatory context should be treated as project-specific rather than generic. In the EU/EEA, relevant considerations may include national permitting, environmental impact assessment, energy reporting under the Energy Efficiency Directive, NIS2 cybersecurity obligations, potential designation under the CER Directive, applicable fire and electrical codes, and recognised standards or frameworks such as EN 50600, ISO/IEC 22237, ISO 27001 and the Uptime Institute Tier Standard. For facilities serving financial-sector clients, DORA may also influence contractual requirements, assurance expectations and third-party ICT risk controls through the clients’ own regulatory obligations.
By linking each project phase to the studies, decisions and evidence it is expected to produce, risk management becomes a practical project tool. It helps owners and project teams move from a general ambition of high availability to a documented basis for design, commissioning, operation and regulatory assurance.
Availability as a Commercial Requirement
Downtime can trigger contractual penalties, reputational damage, regulatory attention and insurance consequences. For facilities supporting public functions or critical digital services, the impact may extend beyond the operator’s own business.
Projects must balance availability against constraints such as cost, schedule, land, grid capacity and supply-chain limitations. The objective is not to eliminate every risk, but to give owners, project managers and engineering teams a sufficiently clear view of the risk profile to make informed, proportionate decisions and maintain confidence in the facility’s ability to deliver the required level of service.
This is where structured risk management adds value. It helps identify dependencies before they become late surprises, test whether availability requirements can be met in practice, and connect design decisions with commissioning evidence and operational readiness.
As digital demand accelerates, the strongest data centre projects will be those in which critical dependencies are identified early, availability assumptions are tested under realistic conditions, and risks are managed across the full lifecycle. Because digital services depend on physical infrastructure, disciplined risk management is becoming a defining requirement for reliable and resilient data centre development.
Sources
International Energy Agency, Energy and AI - Energy demand from AI: iea.org/reports/energy-and-ai/energy-demand-from-ai
Uptime Institute, Global Data Centre Survey Results 2025: uptimeinstitute.com/resources/research-and-reports/uptime-institute-global-data-center-survey-results-2025
Google Cloud Service Health, europe-west2 cooling incident, July 2022: status.cloud.google.com/incidents
Data Center Dynamics, Google London data centre outage during heatwave caused by simultaneous failure of multiple redundant cooling systems: datacenterdynamics.com
Reuters, Fire knocks out services at South Korea tech giants Kakao, Naver, October 2022: reuters.com
Data Center Dynamics, Korea ICT ministry emergency response system reporting after Kakao, SK and Naver incident: datacenterdynamics.com
CEN-CENELEC, EN 50600 series - Information technology - Data centre facilities and infrastructures: cencenelec.eu
EUR-Lex, Directive (EU) 2022/2555 (NIS2) on measures for a high common level of cybersecurity across the Union: eur-lex.europa.eu
EUR-Lex, Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA): eur-lex.europa.eu
EUR-Lex, Directive (EU) 2022/2557 on the resilience of critical entities (CER): eur-lex.europa.eu
EUR-Lex, Directive (EU) 2023/1791 on energy efficiency (recast), including Article 12 on data centre reporting: eur-lex.europa.eu



