Compliance evidence is the first automation
Statutory certificates and their expiry dates are a bounded, high-consequence document problem, which makes them the clearest early target in an estate.
Facility management looks like a services business and behaves like a compliance one. A building has statutory obligations with legal dates attached — fire, lifts, water hygiene, electrical — and the question a regulator or an insurer asks is not whether you meant to comply but whether you can produce the certificate. That is a document and evidence problem, which is exactly what this specialisation is built around.
The estate is a portfolio of buildings, a book of service contracts and a legal obligation register. Part 1 maps all three and names the people holding them together.
Six stages from portfolio to occupant. Select one.
The estate, leases, space allocation, occupancy and the cost of holding it.
Service specifications, contractor selection, SLA structures and mobilisation.
Hard and soft services, planned and reactive maintenance, helpdesk and dispatch.
Consumption, plant efficiency, controls strategy, carbon reporting and retrofit.
Statutory inspections, certificates, permits, risk assessments and remedial actions.
Workplace services, requests, environmental comfort and occupant experience.
One of these people is personally accountable if a statutory certificate has expired. Select one to light the stages they own.
A services industry whose data finally exists, and whose obligations were always legal.
Statutory certificates and their expiry dates are a bounded, high-consequence document problem, which makes them the clearest early target in an estate.
Modern controls and metering expose enough data that plant behaviour can be compared against the documented strategy rather than assumed to follow it.
Unplanned work costs materially more than the same work planned, so shifting the mix is where operating savings in maintenance actually come from.
Utilisation can now be measured rather than surveyed, which turns portfolio decisions from floor-area arithmetic into evidence.
Emissions reporting has moved from voluntary to expected, and assembling it by hand each period does not scale with the number of buildings.
The same data that measures utilisation can identify individuals, so aggregation and purpose limitation are design decisions rather than policy footnotes.
Two things make this architecture distinctive: building systems are operational technology with a real safety boundary, and the compliance obligations are held in certificates issued by third parties. Neither is a database you can simply query.
Six families. The certificate corpus is the one that carries legal consequence.
Buildings, floors, spaces, plant and equipment records.
CAFM / IWMS, space systemsHVAC, lighting, controls, setpoints and plant telemetry.
BMS / BAS, meteringPlanned and reactive jobs, tickets, dispatch and completion.
CAFM, helpdesk platformsStatutory inspections, certificates, risk assessments and remedials.
Contractor portals, document storesLease terms, service specifications, SLAs and variations.
Lease systems, contract storesAccess events, sensor occupancy, bookings and occupant requests.
Access control, sensors, booking systemsA facilities agent that cannot tell an obligation from a certificate will report a building as compliant because a document exists, or as non-compliant because one is missing from a portal. These are the domains, the graph and the definitions that make the difference.
Six subject areas, each with the entities it holds, its critical data elements and the function accountable for it.
The buildings and the space inside them.
The plant and equipment that has to keep working.
What the law requires, and what proves it was done.
What was asked for, who did it and whether it closed.
What the estate consumed and what it emitted.
Who used the space, aggregated so that nobody is identifiable.
The entities and the typed relationships between them — what the agent traverses instead of guessing joins. Select any entity.
A structure in the estate.
An area within a building.
Plant or equipment installed in the building.
The classification that determines duties.
A statutory duty attaching to an asset class.
The performance of a statutory check.
The evidence an inspection was passed.
Work an inspection finding requires.
A job raised against an asset.
The party performing the work.
A consumption measurement point.
The agreement governing a contractor.
The classification hierarchies that make records comparable across systems.
Campus North → Block B → Chilled water → Chiller 2
Fire safety → Emergency lighting test → Monthly
Reactive → P1 → Loss of heating in occupied space
The definitions an agent must use rather than invent. Most wrong answers in this industry are a term used loosely.
The layers a deployment needs, what each one holds, and what the engineer owns there.
Seven layers, with the statutory obligation register treated as a governed entity.
The asset and space register, building systems, work orders and the certificate corpus.
Nothing. This is the upstream edge.
Asset-resolved telemetry, extracted certificates with expiry dates, and aggregated occupancy.
The facilities system of record: assets, locations, planned maintenance, work orders and space. Everything else has to resolve back to its asset identifiers.
HVAC, lighting and plant controls with their setpoints and schedules. Operational technology, read across a controlled path and never written to.
Electricity, gas, water and heat consumption at building and sometimes circuit level. The basis of every energy and carbon number.
Statutory inspection certificates, risk assessments and remedial actions — frequently held in contractor portals rather than by the client who is legally accountable.
Service specifications, SLAs, variations and the lease obligations that sit under the estate.
Badge events, sensor occupancy and room bookings. Personal data at fine resolution, which is why aggregation is applied before anything else reads it.
Getting certificates out of contractor portals and into the client’s own evidence base.
Reporting a compliance gap that is really a missing document. The certificate usually exists and sits in a contractor portal, and a system that cannot tell the two apart destroys its own credibility on the first report.
Telemetry and work-order ingestion aligned to the asset hierarchy, plus certificate extraction.
Read-mostly access paths, change feeds and document streams from the systems of record.
Replayable, resolved, quality-checked records with their lineage back to the source row.
Reads the source’s own change log rather than polling it, so the platform sees every state a record passed through instead of only where it ended up.
Every extract kept as it arrived, immutable and timestamped. The thing you replay from when a downstream definition turns out to have been wrong.
Layout-aware extraction over the unstructured half of the estate: sectioning, tables, signatures, and the page reference every later citation depends on.
Decides that two records are the same real-world thing, with a survivorship rule and a confidence, so downstream joins are a decision rather than an assumption.
Schema, freshness and volume expectations asserted at the boundary, so a bad load fails loudly here rather than quietly two layers later.
Pulls asset, inspection type, date and expiry out of certificates issued in whatever format each contractor happens to use.
Resolving a BMS point and a work order to the same physical asset.
Treating an unreadable scan as an absent certificate. The obligation may well have been met; what failed was your extraction, and reporting it as a compliance gap is worse than silence.
The graph joining building, asset, obligation, certificate, contract and responsible party.
Replayable, resolved records with lineage from ingestion.
Typed, classified, defined data an agent can be grounded on without inferring meaning.
One agreed definition per term, owned by a named person, so the number an agent quotes means what the business means by it.
The typed entities and relationships the domain actually has, so an agent can traverse "which customers are exposed to this" rather than guess from adjacent text.
Metrics defined once, in one place, with their filters and grain. Removes the class of error where the agent computed something plausible and wrong.
Sensitivity labels and the purpose each classification permits, applied at the field level and inherited by everything downstream.
Where a value came from and what it touched on the way. The layer that makes an answer defensible rather than merely correct.
States which assets carry which legal duty, at what frequency and under whose ownership. Compliance coverage has no meaning without it.
One register stating which assets carry which statutory obligation, and who owns each.
Measuring compliance against the certificates you happen to hold rather than against the obligations that exist. That produces a reassuring number and no information.
Retrieval over regulations, standards, service contracts, O&M manuals and risk assessments.
Typed, classified, defined data from the governance layer.
Ranked, permission-trimmed, citable evidence scoped to the caller and the moment.
Vector and lexical retrieval together, because exact identifiers, codes and clause numbers are the thing semantic search is worst at.
Splits on the document’s own structure and carries effective dates, version and source into every chunk, so a retrieved passage knows when it was true.
Applies the caller’s permissions inside the query rather than filtering results afterwards, so the model never sees what the user may not.
Traverses the knowledge graph for questions that are joins rather than similarity — exposure, genealogy, ownership, causation.
Reorders candidates on relevance and returns the passage identifier behind every sentence, so the answer can be checked rather than trusted.
Answering an obligation question with the regulation and the contract clause cited.
Filtering results after retrieval instead of constraining the query. The model has already seen the rows you removed, and it will use them.
Agents for compliance gap detection, ticket triage, anomaly review and contract evidencing.
Ranked, permission-trimmed, citable evidence from retrieval.
Actions taken or proposed, each with the evidence, the identity and the trace behind it.
Plans, calls tools and holds the loop. Where the step budget, the timeout and the stopping condition are enforced rather than hoped for.
Typed, permissioned tools with declared schemas. An agent’s real capability surface is this list, which is why the list is a security artefact.
Durable task state with checkpoints, so a run that dies mid-way resumes instead of restarting and re-doing side effects.
Approval steps on the actions that need one, carrying enough context for the approver to actually decide rather than rubber-stamp.
Writes back into the systems people already work in, under a service identity with its own audit trail.
Keeping the agent advisory on anything that touches building control.
An agent that acts under a service account rather than on behalf of the user. It will eventually do something the requesting user had no right to do, and the log will not show it.
The building-controls boundary, occupant privacy, aggregation thresholds and audit.
Proposed actions and drafted responses from the agent layer.
Permitted, grounded, logged output — or a refusal with a stated reason.
The rules that decide whether an action is permitted at all, evaluated before the action and independently of the model that proposed it.
Injection detection on the way in, and on the way out the checks for leakage, unsupported claims and content the domain forbids.
Verifies each assertion resolves to retrieved evidence, and fails the response rather than shipping the sentence that does not.
Model inventory, intended use, validation evidence and the sign-off that lets a model be used for a purpose. Not optional in a regulated estate.
Immutable record of what was asked, retrieved, decided and done — the artefact a reviewer reads when they do not take your word for it.
Enforces the minimum aggregation below which utilisation output is not returned, because at fine resolution it identifies individuals.
Proving occupancy analysis cannot identify an individual, and control cannot be actuated.
Utilisation reporting at desk-and-hour resolution. It is personal data about named staff, whatever the dashboard is called.
Compliance coverage, prediction precision, anomaly accuracy and cost per building.
Permitted, grounded, logged output from the guardrail layer.
Measured quality, cost and latency — and the evidence to change any of the three.
Held-out sets and graded runs on every change, so a prompt edit is a measured change rather than a hopeful one.
Blocks a release when quality drops, in CI, on the same evidence for everyone. The difference between a system and a demo.
End-to-end spans across retrieval, model and tool calls, so a bad answer can be opened and read rather than argued about.
Cost per task and per tenant, against throughput and quota. The number that decides whether the pilot can become the rollout.
Watches quality against production traffic rather than the test set, and routes real corrections back into the eval suite.
Proving compliance coverage improved, which is the only number an auditor cares about.
Evaluating once, before launch. Quality moves with the data, the model and the traffic, and a system with no live measurement has no idea which of the three moved.
Fire, lifts, water hygiene and electrical inspections have legal dates. No efficiency gain justifies a gap, and the evidence is the certificate rather than the intention.
The agent reads the BMS and never writes to it. Comfort and safety strategies are engineered artefacts with their own change control.
At fine enough resolution, utilisation data is personal data. Aggregation thresholds have to be architectural, not a reporting convention.
Certificates are often held by whoever performed the inspection. Any compliance system that assumes the client already has the documents will report a gap that is really a retrieval failure.
The compliance use cases come first here, not because they are the most interesting but because everything else is optional and they are not.
Filter by stage or by earned autonomy. Selecting a use case jumps the value chain and the architecture to the stage and layer it depends on.
No use cases match that combination.
How a facilities deployment actually runs.
Establish which assets carry which statutory obligation and who owns each. Without this the compliance work has nothing to measure coverage against.
Retrieve certificates from contractor portals into the client’s own evidence base. Reporting a gap that is really a missing document destroys trust immediately.
Certificate extraction and gap detection carry legal consequence and no controls risk. They also build the asset resolution the energy work will depend on.
Only once BMS points and work orders resolve to the same assets can anomaly detection and prediction mean anything.
Prove occupancy analysis cannot identify an individual and that no control path exists, then hand over runbook, obligation register and coverage evidence.
8 modules, 80 taught hours, 40 hands-on labs and 8 assessments — every lab provisioned and graded by the SCIKIQ Agentic AI Playground. Open a module to see its labs.
End-to-end agent design, development, deployment and testing, 10 hours each. Reviewed by a Senior SCDAI Engineer against a published rubric.
Build an agent that extracts certificates across contractor formats, resolves each to an asset in the obligation register, and reports every asset without a valid in-date certificate — distinguishing a missing document from a missing inspection, and audited specifically for assets wrongly reported as compliant.
Build an agent that detects departures from a building’s own weather- and occupancy-adjusted consumption pattern, cites the documented control strategy the plant appears to be departing from, and demonstrably has no write path to the BMS.
Every lab in this program follows the shape below. This is lab 05 in full — the brief you are given, the environment that is provisioned for you, the code you start from and the assertions that decide whether you passed.
Report every asset without valid statutory cover, and never confuse that with a missing file.
You are given an obligation register for 4,200 assets, certificates from six contractors in six different formats, and a labelled key. Some assets genuinely have no valid inspection. Others have one, evidenced by a certificate that is badly scanned or sitting in a portal you did not read. Report the first group. Reporting the second as non-compliant is the failure this lab is built to catch.
def compliance_gaps(register, certificates):
"""Return [(asset, obligation, status, evidence)].
status is one of: 'compliant', 'gap', 'unverified'.
'unverified' is not a soft 'gap' -- it means the extraction failed and
a human must look, which is a different action entirely.
"""
# 1. an obligation is satisfied by an IN-DATE certificate for that asset
# 2. an unreadable certificate is unverified, never a gap
# 3. carry the evidence so a compliance officer can check any verdict
raise NotImplementedError
Every module ends with a timed, randomised assessment delivered through the SCIKIQ Agentic AI Playground. The certificate requires a pass on all of them plus two reviewed capstones.
What each test covers, how long it runs, and how many items are currently in the versioned bank behind it.
| # | Assessment & coverage | Items | Time | In bank |
|---|---|---|---|---|
| 01 | Operating model & obligationsDelivery mandateStatutory obligationsValue sizingThin slicing | 25 | 35 min | 3 |
| 02 | Facilities data landscapeRegistersBMS dataCertificatesOccupancy and privacy | 25 | 35 min | 2 |
| 03 | Context engineeringAsset resolutionDates and expiryUnitsStructured outputs | 25 | 35 min | 2 |
| 04 | Retrieval & groundingRegulation retrievalContract clausesGraph traversalRetrieval metrics | 25 | 40 min | 2 |
| 05 | Agent design for compliance & operationsGap detectionMissing vs absentTriageAdvisory limits | 25 | 40 min | 2 |
| 06 | Systems integrationMCP designBMS read pathsWrite-back safetyIdentity | 25 | 35 min | 2 |
| 07 | Safety, privacy & securityControls boundaryOccupant privacyAggregationLLM security | 30 | 45 min | 2 |
| 08 | Production & coverageEval gatingCoverageFalse-clean riskEconomics | 30 | 45 min | 2 |
Real items, drawn from 17 in this program's bank — weighted toward the scenario and diagnosis types, because those are the ones that predict field performance. Instant feedback, nothing saved.
Four sample items — one attempt each, then the reasoning is shown.
Q1An FM provider asks for AI to reduce cost. Where should the first engagement land?
Compliance is the obligation that outranks efficiency, is a bounded document problem, and produces the asset resolution the energy work later depends on.
Q2An asset has an obligation and no certificate in your store. What is the correct status?
A missing document and a missing inspection require different actions. Reporting them identically destroys the credibility of the whole report on the first run.
Q3Where does the authoritative statement of a statutory duty come from?
The contract allocates the work; the law creates the duty. A compliance system grounded only in the contract will miss duties nobody contracted for.
Q4Which error matters most in compliance gap detection?
A false gap wastes time; a false clean means an unsafe asset sits unexamined with a report saying otherwise. Only one of those has legal consequence.
The same ladder whichever specialisation you enter through — what changes is the domain you go deep in. Below: how the program is delivered, the skills it moves, the roles it leads to, and the specialisations closest to this one.
The same labs, assessments and capstones, delivered to an enterprise cohort or to individual professionals.
Cohorts of 20 to 2,000+ on your own tenancy, with your data patterns and your cloud. Skill-gap baselining up front, per-team mastery reporting throughout, and capstones scoped against your real backlog so the output is deployable work.
The same labs, assessments and capstones for individual engineers and analysts, run on shared infrastructure with a fixed cohort calendar. You leave with a graded portfolio, not a certificate of attendance.
Find your row and aim one column right. The Playground scores you against this after every module.
| Skill | Beginner | Intermediate | Advanced |
|---|---|---|---|
| Facilities domain fluency | Knows hard and soft services. | Maps obligations to assets and owners. | Sizes reactive, energy and compliance value credibly. |
| Obligation engineering | Reads a certificate. | Maintains an obligation register with coverage measured. | Audits for false-clean results, not just for gaps. |
| Building data | Reads BMS telemetry. | Resolves points and work orders to one asset model. | Designs a read-only path with privacy thresholds enforced. |
| Context engineering | Writes clear prompts. | Structures retrieval, tools and state deliberately. | Designs context strategy for reliability and cost at scale. |
| Retrieval & grounding | Builds basic vector search. | Tunes chunking, hybrid search and reranking. | Designs graph + vector grounding with measured recall. |
| Agent orchestration | Runs a single tool-calling agent. | Builds supervised multi-step and multi-agent flows. | Designs autonomy boundaries and failure containment. |
| Tool & system integration | Calls a documented API. | Writes an MCP server over a system of record. | Designs a least-privilege tool estate across systems. |
| Evaluation | Eyeballs outputs. | Builds labelled eval sets and regression gates. | Runs online evals with drift and judge calibration. |
| Observability & cost | Reads logs. | Traces runs, tracks tokens and latency. | Owns cost per task and capacity planning in production. |
| Security & guardrails | Adds output filters. | Mitigates the OWASP LLM Top 10 in a build. | Threat-models an agent estate and proves controls. |
| Client delivery | Takes notes in a workshop. | Runs discovery and scopes a thin slice. | Owns the account technically, from scope to handover. |
The SCDAI ladder is the same whichever specialisation you enter through — what changes is the domain you go deep in.
Skill a team, or join a cohort
B2B cohorts run on your tenancy with capstones scoped to your backlog. B2C cohorts run on a fixed calendar.
Stated plainly enough to rule yourself in or out without a sales call: the prerequisites, how the program runs, exactly what the credential is worth, and the questions everyone asks.
Stated plainly so you can rule yourself in or out without a sales call. Nothing here is a formal qualification — it is what the first lab assumes you can already do.
You should already be able to do these
What we assume, and what we teach
What the program asks of your week
Cohort dates and pricing are confirmed on enquiry rather than printed here, because both move with the intake.
The credential is awarded per specialisation, so it names the domain or stack you were assessed in rather than claiming general competence. On this program the badge reads SCDAI — Facility Management.
A certificate that cannot be checked is decoration. Every award resolves to a record showing the specialisation, the award date and the assessments passed.
This is the credential the program awards, shown exactly as it is issued — with the specialisation named, the assessment record attached and a verification link anyone can check without an account.
This is to certify that
Your name
has been assessed and certified as
SCIKIQ Certified Data and AI Engineer
Facility Management
Not “Data and AI Engineer” but the domain or stack you were actually assessed in. A general claim would be a weaker one.
Modules passed, labs graded and both capstones reviewed — so the credential states what was measured rather than that you attended.
The credential ID resolves to a public record showing the specialisation, the award date and the assessments passed.
Add it to your LinkedIn profile in one step. The link pre-fills the certification fields from the credential record, so the entry on your profile matches the record a reader can check.
Add to LinkedIn profile The button is live on your real certificate; here it opens LinkedIn pre-filled with this specialisation so you can see exactly what the profile entry will say.A certificate that cannot be checked is decoration. Every award resolves to a record showing the specialisation, the award date and the assessments passed.
The objections that come up in every conversation about this program, answered without the brochure voice.
Both, and the second is the point. Eight timed assessments and two reviewed capstones stand between you and the credential, so a pass means someone measured the skill rather than recorded your attendance.
Every lab is provisioned, graded and unblocked by the Playground rather than by an instructor. That is what lets a cohort of 2,000 cost the same faculty time as a cohort of 20 — and why you are never waiting on someone to mark your work.
Two retakes are included per assessment, each drawing a fresh item set from the bank, so a retake is a genuinely new paper rather than the same questions again.
For the domain specialisations, no — labs run in provisioned sandboxes. For the four tech-stack programs you will want access to that platform, since deploying into a real subscription is much of the point.
Yes. B2B cohorts run on your own tenancy with your data patterns, a skills baseline before kick-off, per-team mastery reporting, and capstones scoped against your actual backlog so the output is deployable work rather than an exercise.
Take the domain you deploy into. If you move across industries, take a tech-stack program instead and pick up domain context on the engagement. The chooser on the programs page will narrow it.
The trends, platform capabilities and regulatory positions are reviewed each quarter, and every external claim on these pages links to its source so you can check the date yourself.
A graded portfolio: forty machine-graded labs, two reviewed end-to-end agent builds with measured evaluation and cost per task, and a verifiable credential naming your specialisation.
Still deciding?
Tell us the systems you deploy into and we will say plainly whether this specialisation is the right one — or which of the 21 is.