THE PFI RECKONING · ARTICLE 6 OF 12
The Hidden Risk at PFI Expiry: Missing Asset Data, Lost Records, and 25 Years of CAFM Migration
The SPV is contractually required to hand over a complete set of asset data, maintenance records, and compliance documentation at expiry. In practice, 25 years of records spanning paper archives, multiple CAFM systems, multiple FM subcontractors, and staff who left decades ago means the data set is almost always incomplete. This article examines what data should transfer, why it rarely does in full, and what authorities need to do about it before handback.
Why data is the hidden risk at PFI expiry
Every other article in this series depends on data. The lifecycle fund reconciliation requires a complete record of what was replaced and when. The condition survey requires an accurate asset register to define its scope. The handback deduction calculation requires evidence of what the contractual standard is and whether it has been met. The insource versus reprocure decision requires an understanding of what the authority is inheriting and what it will cost to operate. TUPE planning requires workforce data including roles, terms, pensions, and qualifications.
If the data is incomplete, every one of these processes is compromised. The authority cannot verify what the SPV claims. The SPV cannot evidence what it says it delivered. The negotiation becomes a contest of assertions rather than a process grounded in evidence. The party with better records wins.
In most PFI handbacks, the party with better records is the party that controlled the data for 25 years. That is the SPV. The authority is relying on the other party to hand over the evidence that will be used to hold the other party accountable. That structural conflict is the core of the data problem.
The authority is relying on the SPV to hand over the evidence that will be used to hold the SPV accountable. That structural conflict is the core of the data problem at PFI expiry.
Why data is the hidden risk at PFI expiry
The project agreement typically requires the SPV to deliver a comprehensive data package at or before expiry. The exact requirements vary by contract, but a complete handover data set should include the following:
Asset register
A complete register of every maintainable asset on the estate. Location, type, manufacturer, model, serial number, date of installation, expected life, condition at last assessment, and the SFG20 or other maintenance schedule applied to it. This register should reconcile with the physical estate. In practice, it rarely does.
Maintenance records
A complete history of every planned preventive maintenance task, every reactive maintenance intervention, every statutory inspection, and every compliance certificate for every asset over the life of the contract. This includes what was done, when, by whom, what was found, and what remedial actions were taken.
Lifecycle replacement records
A complete record of every capital replacement carried out under the lifecycle programme. What was replaced, when, at what cost, to what specification, and who carried out the work. This record should reconcile with the lifecycle fund accounts.
Operating and maintenance manuals
Current O&M manuals for every major building system. These should reflect the as-built condition including any modifications, replacements, or upgrades carried out during the contract. Original O&M manuals from 2001 that do not reflect 25 years of changes are not adequate.
Compliance and statutory documentation
All current certificates, inspection reports, risk assessments, asbestos registers, fire safety records, Legionella management records, electrical installation certificates, gas safety certificates, and any other statutory compliance documentation. These should be current, not historic.
Under the Building Safety Act 2022, higher risk buildings require a Golden Thread of information: a complete, accurate, and accessible record of safety related data maintained throughout the building’s life. If the SPV cannot evidence fire stopping history, compartmentation integrity, or structural safety interventions because the records were lost during a CAFM migration or a subcontractor change, the building may be deemed non compliant with current safety law. The cost of recreating that Golden Thread from scratch falls on the authority after handback.
Warranties and guarantees
Any active warranties or guarantees on recently replaced or installed equipment. These transfer with the asset and have real commercial value to the authority.
Workforce data
For TUPE purposes: a complete list of employees in scope, their terms and conditions, pension arrangements, qualifications, training records, and any relevant HR documentation. This data triggers legal obligations for the authority and must be accurate and timely.
Why the data is almost always incomplete
25 years of system migrations
Most PFI contracts have been through at least two and sometimes three or four CAFM system changes over their life. The original system from 2001 may have been a paper based or early digital system. It was migrated to a second platform around 2008 to 2012. It may have been migrated again to a cloud based system in the late 2010s. Each migration carries risk of data loss, corruption, field mapping errors, and incomplete transfer. Records that existed in the original system may not exist in the current one.
85% of FM organisations do not have a fully accurate asset register. SFG20 State of FM Report 2026. On a 25 year PFI estate the figure is likely worse.
Multiple subcontractors over 25 years
The FM provider at year 25 is often not the FM provider at year 1. Hard FM subcontractors for specialist systems such as lifts, fire protection, BMS controls, and medical gas may have changed multiple times. Each subcontractor brought its own data formats, its own reporting systems, and its own records. When the subcontractor changed, the handover of maintenance history was frequently incomplete. The maintenance record for a lift that has been maintained by three different companies over 25 years may exist in three different formats across three different systems, one of which no longer exists.
Departed staff and undocumented knowledge
The people who maintained the building in the early years have left. The engineer who knew that a specific valve was replaced informally in 2009 and never logged in the system is not available to explain the gap in the records. The contract manager who agreed a variation to the maintenance schedule in 2014 and documented it in an email rather than a formal contract change is not available to locate that email. Undocumented knowledge is lost knowledge. On a 25 year contract with multiple staff turnovers, the volume of lost knowledge is significant.
Paper records and physical archives
The first decade of most PFI contracts predates widespread digital record keeping for FM operations. Statutory inspection certificates, O&M manuals, commissioning records, and early maintenance logs may exist only on paper. Those paper records may be stored in filing cabinets on site, in offsite archives, or they may have been lost during office moves, reorganisations, or simple neglect. Reconstructing a complete compliance history from paper records accumulated over 25 years is a substantial exercise.
Data as competitive leverage
There is a further dynamic that authorities rarely consider. If the incumbent FM provider holds the only comprehensive digital record of the estate’s operational history, that information becomes competitive leverage. In a reprocurement, the incumbent knows the building’s quirks, its failure patterns, its access constraints, and its real maintenance costs. No other bidder has access to that information. The authority that does not hold its own independent data set is not just exposed at handback. It is locked into a reprocurement process where the incumbent has a structural information advantage over every other bidder.
The maintenance record for a lift maintained by three different companies over 25 years may exist in three different formats across three different systems, one of which no longer exists. That is the data the authority is expected to inherit.
The consequences of incomplete data
Condition surveys cannot be scoped properly
The condition survey depends on an accurate asset register to define its scope. If the register is incomplete or inaccurate, the survey will miss assets, survey the wrong assets, or apply the wrong handback standard. Article 3 of this series examines the condition survey problem in detail. The data problem is upstream of the survey problem.
Lifecycle fund reconciliation is contested
Without a complete record of what was replaced and when, the lifecycle fund reconciliation becomes a negotiation rather than an audit. The SPV claims it completed the works. The authority cannot verify. Article 2 examines the lifecycle fund gap. Incomplete data makes that gap harder to quantify and harder to contest.
Handback deductions cannot be evidenced
If the authority cannot demonstrate that a specific asset was not maintained to the contractual standard, the deduction mechanism fails. The burden of evidence in handback deductions is typically on the party asserting the deduction. If the data does not support the claim, the deduction is not applied. Poor data protects the SPV.
Post PFI operating costs are unknown
The authority cannot model the cost of operating the estate after handback without reliable asset data. What systems exist. What condition they are in. What maintenance regime they require. What skills the workforce needs. What capital investment is required in the first five years. Without data, the insource versus reprocure business case is built on assumptions rather than evidence.
Poor data does not create a neutral problem. It creates an asymmetric advantage for the party that controlled the data for 25 years. The SPV knows what it did. The authority has to prove what was not done. Without evidence, the authority loses.
What authorities should do about the data problem
The data handover problem cannot be solved in the final year. It must be addressed early, systematically, and independently of the SPV. NISTA’s PFI Contract Management Document Stocktake guidance (March 2026) formalises this as a structured exercise covering the project agreement, schedules, variations, performance reports, and operational records. The NISTA PFI Contract Review guidance adds a Gaps and Ambiguities Log for capturing unclear, missing, or conflicting provisions. These work alongside the NISTA Contract Management Plan for structured operational reporting on the contract through to expiry, the NISTA Obligations Tracking guidance for monitoring contractual commitments approaching expiry across both sides of the agreement, and the NISTA Contract Calendar for managing key dates including survey windows, deduction deadlines, and TUPE consultation milestones. All of these should be owned by the Senior Responsible Owner (SRO) for expiry and initiated at the seven year mark. NISTA explicitly identifies completeness of associated data as a primary expiry objective alongside asset condition and continuity of public services.
Audit the data five years out
Request the full data set from the SPV at year five before expiry, not at year one. Use this early request to identify what exists, what is missing, what is inconsistent, and what needs to be reconstructed. The earlier the gaps are identified, the more time remains to fill them while the SPV still has a contractual obligation and a commercial incentive to cooperate.
When requesting the data, specify the format. Do not accept unindexed PDF archives or unstructured file dumps. Require data in a structured, interoperable format such as COBie (Construction Operations Building information exchange) that can be imported directly into the authority’s own CAFM or asset management system. The format of the data determines whether it is usable or whether it is simply a compliance gesture by the SPV.
Verify the asset register on site
Do not accept the SPV’s asset register at face value. Commission an independent physical verification of the asset register against the actual estate. Walk the estate. Count the assets. Record their condition. Compare what exists with what the register says should exist. The SFG20 State of FM Report 2026 found that 85% of FM organisations do not have a fully accurate asset register. Assume yours is in that 85% and verify independently.
Reconstruct critical compliance records
Where statutory compliance records are missing, commission an independent assessment of current compliance status. For fire safety, Legionella, asbestos, electrical installation, gas safety, and any other statutory requirements, the authority needs to know the current position regardless of what the historic records show. A gap in the record is a gap in the evidence. Fill it before handback, not after.
Build a parallel data set
For NHS estates, cross reference the SPV’s data against ERIC submissions for the same estate. ERIC data is independently reported by the trust and provides a cross check on condition, backlog maintenance, and critical infrastructure risk that does not depend on the SPV’s records.
Preserve what exists
Before any system migration or contract change in the final years, ensure a complete data extract is taken and stored independently by the authority. Data lost during a final years CAFM migration is data lost permanently. The authority should hold its own copy of the complete data set from the current system before any transition occurs.
What undocumented variations look like in practice
To make the data-as-leverage argument concrete, consider an anonymised composite drawn from a recurring pattern across street lighting PFI engagements. The contract was a 25-year street lighting PFI covering approximately 75,000 columns, lanterns, and associated control gear across a county footprint. The authority’s expiry team commissioned a Document Stocktake at year 19 against the eight-document NISTA contract management framework. The exercise found the formal contract bible was complete and well-organised. The asset register was 92% accurate against a sample physical audit. The compliance documentation for inspection regimes was current. So far, so good. The Contract Review (gaps and ambiguities log) was where the issues emerged. Over 25 years, a series of operational practices had become business-as-usual without ever being formalised: a tacit agreement on overnight isolation procedures during major works that varied from the project agreement; an informal access protocol for connecting authority-owned festive lighting to PFI columns; tolerated non-compliance on a documented LED retrofit pilot that had never been signed off as a formal variation; and side-letter agreements on inspection frequency for amenity lighting in three town centres that never made it into the contract bible. None of these were defects in the asset. All of them were exposures at handback because the SPV could argue (and did) that the variations were the contract, while the authority’s position was that the project agreement was the contract and the variations were unauthorised. The Contract Review identified seventy-three such items across the contract, ranging from trivial to material. Capturing them while the people involved were still available and contactable was the work of months. Six months after the audit, three of the four key SPV staff with operational memory of the variations had moved on. The authority’s window to convert tacit operational practice into documented contractual position was narrower than the calendar suggested.
Change control fatigue and the undocumented-variation problem
The street lighting example is structural, not unusual. Twenty-five years of operational practice creates informal variations that were never formally documented. The NISTA Contract Review guide explicitly recommends capturing these and provides a structured template. The variations cluster into recognisable patterns: undocumented changes to maintenance regimes that responded to changes in the operational environment but were never written into the contract; informal access and isolation protocols agreed between site teams to make the asset workable; tolerated non-compliances where the SPV proposed a workaround the authority quietly accepted; and side-letter agreements that captured a deal between particular individuals at a particular time and never made it into the contract bible after those individuals moved on. Each of these is a potential dispute at handback. Authorities approaching expiry should run the Gaps and Ambiguities Log exercise before the operational memory leaves. The cost of capture is small. The cost of failing to capture is the difference between a documented contractual position and a contested oral history of operational practice. Documented variations are also a precondition for the dual-benchmark assessment of asset condition; see Article 7 for how undocumented variations interact with sector-specific compliance standards.
The data problem at PFI expiry is not a technology problem. It is a governance problem. The authority that treats data as the SPV’s responsibility until handback will discover that the data it receives is the data the SPV chose to keep. The authority that builds its own evidence base from year five will negotiate from a position where the data supports its claims rather than undermining them.
Buildings can be repaired. Missing evidence, lost compliance history, and broken asset intelligence are far harder and far more expensive to recover. At handback, data is not administration. It is leverage.
Independent analysis for contracting authorities, SPVs, FM providers, and investors approaching PFI expiry.
Full series: baachurain.com/pfi-reckoning
PFI Reckoning Reports
This article represents Baachu Works Limited’s independent analysis based on publicly available information, NAO and NISTA reports, BAILII case law, and Baachu’s commercial experience. It is not legal or financial advice. Baachu Works Limited has no commercial relationship with any SPV, investor, FM provider, or PFI advisory firm referenced in this series.