Insights
What ISO 55001 actually asks of you
The standard is short, unglamorous and frequently misread as a documentation exercise. Read against a live data center, its requirements are specific and largely about decisions, not paperwork.
ReliDC · 9 min read
It asks you to write down how you decide
The requirement that causes most difficulty is not the asset register. It is Clause 6: asset-management objectives, and the plans to achieve them, established with defined decision-making criteria. Most facilities can produce an asset list. Very few can produce the written rule by which a switchgear replacement was ranked against a cooling upgrade.
That rule is the point. Without it, capital allocation defaults to whichever manager argued most recently, and the organisation cannot demonstrate to a customer, an insurer or a regulator why the residual risk it carries is the risk it chose to carry.
It asks for line of sight, and tests it in reverse
An auditor will take a task off a schedule and walk upward: which asset-management plan requires this, which objective does that plan serve, which organisational objective does that support? Three links is usually enough to find the break.
In practice the break appears at the same place: a task library inherited from an OEM manual or a previous contractor, with no failure mode attached. It is not that the tasks are wrong. It is that nobody can say what would be lost by stopping them.
It treats information as an asset with requirements
Clause 7.5 asks what information is needed, by whom, for which decisions, and how its quality is assured. This is the clause that makes an unreliable CMMS a conformity issue rather than an IT annoyance.
The practical implication is that data requirements should be derived from decisions. If you intend to compare failure rates between two sites, then both must code failure modes to a common taxonomy — ISO 14224 is the obvious choice — and both must record detection method and repair time separately.
It expects change to be managed as risk
Clause 8.2 covers management of change. In a data center this is the clause with the sharpest operational edge, because so much risk is introduced deliberately: a maintenance window, a firmware update, a temporary configuration, a vendor working on a live board.
A conforming organisation can show, for each significant change, what the intended state was, what the fallback was, who was authorised to abort, and what verification confirmed the restoration.
What it does not ask
It does not require certification, a specific software platform, a particular maintenance strategy, or a documented procedure for everything. ISO 55002 is explicit that the system should be proportionate to the organisation's scale and risk.
The organisations that struggle are usually those that built a system to pass an audit rather than to allocate money. The paperwork is then real and the practice is not — which the first serious incident exposes.
Discuss scope
Tell us the facility, the systems that concern you, and the decision you are trying to make. We will tell you which engagement fits.