All insights

DCFR Insight 29 / Data Center Design + Risk Management

Factory Mutual (FM) + Property Loss Prevention

Factory Mutual Data Center Design Beyond Building-Code Compliance

A practical guide to Factory Mutual (FM) data center design: site hazards, envelope, fire protection, batteries, power, cooling, water, resilience, insurability, and what building-code compliance alone does not address.

Factory Mutual Data Center Design Beyond Building-Code Compliance

What Factory Mutual (FM) Means in Data Center Design

Factory Mutual (FM), historically widely known as FM Global and now branded as FM, is a commercial property insurer and engineering-based property-loss-prevention organization. Its role includes commercial property insurance, property-loss-prevention engineering, research and loss experience, Property Loss Prevention Data Sheets, risk evaluation, and product and assembly certification through FM Approvals. FM Approvals is distinct from the broader Factory Mutual loss-prevention guidance: it evaluates and certifies products and systems for defined performance criteria. Factory Mutual is neither a government agency nor a building-code organization. For a mission-critical facility, obtaining a permit answers one essential question: “Can the project legally be built under the adopted requirements?” It does not, by itself, establish how vulnerable the asset is to catastrophic loss, how quickly a fire can be controlled, whether one equipment failure can propagate, or whether water intrusion can disable multiple redundant systems. Nor does the permit alone determine whether a battery event can spread into adjacent critical infrastructure; whether flood, windstorm, roof failure, or utility interruption can create a campus-wide outage; how rapidly the owner can recover; or whether the insurer will accept the proposed risk. Those are different, complementary questions. Building code largely establishes minimum regulatory requirements for health, safety, fire protection, structural safety, accessibility, and related legal obligations. Factory Mutual evaluates risk through a property lens: preventing loss, limiting fire spread, reducing the severity of equipment failure, avoiding common-mode failure, protecting continuity, improving recovery, and reducing business interruption. A legal solution is not necessarily the lowest-risk solution. A solution that protects occupants is not automatically sufficient to protect a billion-dollar mission-critical operation from prolonged outage. This does not diminish building code; it recognizes that regulatory review and loss prevention have different objectives. Factory Mutual thinking therefore belongs in site selection and concept design—not as a late insurance check after layouts, assemblies, and systems are fixed.

BUILDING-CODE COMPLIANCE AND PROPERTY-LOSS PREVENTION ARE NOT THE SAME DESIGN QUESTION.

Three coordinated review lenses for building-code compliance, Factory Mutual loss prevention, and owner or insurer criteria.
Building-code review, Factory Mutual (FM) loss prevention, and owner or insurer criteria address overlapping but different questions. Strong data center design coordinates all three.

Code Compliance vs Factory Mutual (FM) vs Owner / Insurer Criteria

Four layers must remain explicit: adopted building and fire code with Authority Having Jurisdiction (AHJ) review; Factory Mutual engineering-based property-loss-prevention guidance; project-specific owner and insurer criteria; and the final requirements established by the actual project team. Factory Mutual recommendations are not automatically universal mandates. Applicability, priorities, and acceptance must be confirmed for the project.

CODE-COMPLIANT DOES NOT AUTOMATICALLY MEAN LOSS-PREVENTION OPTIMIZED.

Code Compliance vs Factory Mutual (FM) vs Owner / Insurer Criteria

Review LensPrimary ObjectiveTypical QuestionsTypical Outcome
Building Code / Authority Having Jurisdiction (AHJ)Regulatory compliance; occupant safety; means of egressDoes the design meet adopted fire protection, structural, accessibility, and other legal requirements?Permit / approval subject to the applicable review process
Factory Mutual (FM)Property-loss prevention; resilience; equipment protectionHow are hazards controlled, fire spread limited, business interruption reduced, and recovery improved?Engineering recommendations and risk-improvement priorities for project-specific evaluation
Owner / Insurer CriteriaUptime; service availability; redundancy; recovery objectivesDoes the proposal align with capital strategy, risk tolerance, operating model, and underwriting requirements?Project-specific basis of design, risk decisions, and acceptance conditions

These lenses overlap but are not interchangeable. The actual project team must reconcile them and document final design requirements.

Start With the Site, Not the Sprinkler System

Loss-prevention thinking begins before a building exists. Screen flood exposure, elevation, drainage, wind, hail, seismic and geotechnical conditions, wildfire and smoke where relevant, emergency-response access, utility resilience, water availability, surrounding property exposures, and vulnerable adjacent uses. A site with cheaper land can become the more expensive site when mitigation consumes land, capital, redundancy, schedule, or operating flexibility. Flood planning must use current project-specific hazard data and applicable guidance. Do not assume a universal elevation or freeboard. Coordinate flood elevation, freeboard, surface and roof drainage, critical-equipment placement, below-grade vulnerability, access during an event, and recovery. Keep critical electrical and continuity infrastructure out of vulnerable locations where feasible; exact criteria require project-specific confirmation.

Data center site hazard screening for natural hazards, access, drainage, utilities, and adjacent exposures.
Factory Mutual (FM) screening should begin during site selection. Natural hazards, access, drainage, utility resilience, and surrounding exposures can change the viability of a data center before detailed design starts.

The Building Envelope Is a Loss-Prevention System

The envelope is not aesthetic wrapping. For the roof, coordinate membrane, insulation, deck, attachment, wind uplift, hail exposure, drainage, ponding, equipment curbs, penetrations, safe access, and maintainability. For walls, examine combustibility, insulation, cladding, moisture durability, impact resistance, fire resistance, and interfaces with doors and louvers. For penetrations, coordinate electrical, mechanical, plumbing, fire-protection, cable, structural, and future work. Risk often sits at a transition: roof-to-wall, wall-to-foundation, panel joint, door opening, louver, cable or pipe penetration, equipment curb, or expansion joint. Details must preserve weather, fire-resistance, thermal, air, and water-control continuity. Confirm that specified products are suitable within the tested or approved assembly; a listed component does not automatically make an unreviewed combination acceptable. Roof replacement, inspection, drain cleaning, curb access, and equipment removal must remain practical throughout facility life.

  1. 1

    Roof

    Verify the complete assembly, attachment, drainage paths, exposed equipment interfaces, penetrations, access, and repair strategy against project criteria.

  2. 2

    Walls

    Resolve material combustibility and durability, then detail cladding, insulation, openings, joints, and fire-resistance continuity as one system.

  3. 3

    Penetrations

    Create owned details and change control for every service, future opening, curb, louver, joint, and interface.

Coordinated review of data center products, assemblies, penetrations, roofing, equipment, and access.
Factory Mutual (FM) review reaches into products, assemblies, penetrations, roofing, electrical equipment, cooling equipment, and maintenance access—not just fire protection.

Fire Detection: Find the Event Before It Becomes the Event

Data centers combine high asset concentration, continuous electrical load, strong airflow, concealed cable pathways, raised-floor or overhead distribution, and multiple potential ignition sources. Very Early Warning Fire Detection (VEWFD) uses high-sensitivity detection that can provide earlier warning than conventional arrangements, depending on the design. It is not a universal answer. Detection design must follow actual airflow: hot-aisle and cold-aisle containment, sampling locations, ceiling configuration, return-air paths, and underfloor or overhead conditions can all affect transport of smoke. Commissioning should include representative smoke testing, verified sampling and alarm thresholds, documented alarm-response sequences, interfaces with suppression and air systems, and recurring inspection. The project fire protection engineer, insurer, manufacturer, and Authority Having Jurisdiction must confirm the appropriate technology and sequence.

Why Water-Based Fire Protection Still Matters

“Water and servers do not mix, therefore data centers should avoid sprinklers” is incomplete. Localized water damage must be compared with uncontrolled fire, heat, smoke, corrosive combustion products, cascading failures, and total room loss. The goal is not to put water everywhere; it is to provide a reliable, engineered way to control a local fire before it becomes a catastrophic facility event. Wet and preaction systems involve different operating, detection, accidental-discharge, and maintenance considerations. Coordinate zoning, isolation, drainage, protected-area boundaries, testing, and impairment management so protection remains available without creating uncontrolled secondary exposure. Clean-agent systems can play an important role, but they do not universally replace water-based protection. Agent selection, enclosure integrity, occupant safety, fire scenario, reignition potential, and water-based backup belong to one integrated fire strategy. Final system choice requires project-specific confirmation.

Integrated data center fire strategy balancing early detection, water-based control, drainage, and equipment protection.
Protecting electronic equipment is not only about avoiding water. It is also about controlling fire quickly enough to prevent much larger property loss and business interruption.

Uninterruptible Power Supply (UPS), Batteries, and Energy Storage

The Uninterruptible Power Supply (UPS) strategy is architectural as well as electrical. Review redundancy topology, physical segregation, room location, fault isolation, maintenance bypass, ventilation, fire strategy, equipment movement, and replacement access. A bypass that crosses the same vulnerable space as the primary path may preserve a diagram but not real resilience. Lithium-ion batteries introduce thermal-event, propagation, gas and off-gas, detection, ventilation, separation, emergency-response, maintenance, and access questions. Chemistry, cell and module construction, rack configuration, enclosure, controls, tested performance, and system scale all matter. Battery Energy Storage System (BESS) installations located outdoors or centrally can create different spatial, exposure, drainage, security, and fire-protection questions than rack-level or UPS batteries. Battery-fire strategy is chemistry-, configuration-, enclosure-, testing-, and project-specific. It requires fire protection engineering and review of applicable Factory Mutual guidance, National Fire Protection Association (NFPA) standards, manufacturer information, insurer criteria, and Authority Having Jurisdiction requirements. Do not assume water is always prohibited or always sufficient. Separation, ventilation, suppression, drainage, emergency access, and response tactics require project-specific confirmation rather than an invented threshold.

Battery architecture planning for separation, ventilation, fire protection, access, and continuity.
Battery architecture changes the fire, ventilation, separation, maintenance, and continuity strategy. Battery location is therefore a building-planning decision, not merely an electrical specification.

Cooling, Water, and Leak Management

High-density computing changes the property-loss profile. Heating, Ventilation, and Air Conditioning (HVAC) design must address cooling redundancy, airflow, equipment zoning, control dependencies, and failure isolation—not efficiency alone. For liquid cooling, coordinate direct-to-chip circuits, each Coolant Distribution Unit (CDU), distribution piping, couplings, valves, leak detection, containment, drainage, and serviceability. Water systems need reliable sources, appropriate quality and treatment, management of scaling, corrosion, and biological growth where relevant, plus leak isolation, overflow control, and drainage. Heat rejection brings its own dependencies: cooling towers, dry coolers, chillers, pumps, heat exchangers, structural support, weather exposure, and replacement access. A leak, pump failure, control fault, or maintenance event should not disable a disproportionate amount of Information Technology (IT) capacity. Map what each valve isolates, where leaked fluid travels, which alarm acts first, how drainage behaves, what equipment sits below pipes, and whether service can occur without crossing live critical zones. Coordinate controls and physical containment so a single fault does not become a shared failure.

Data center cooling and liquid distribution with leak detection, isolation, drainage, and redundant equipment.
Cooling strategy is also a loss-prevention strategy. High-density and liquid-cooled facilities require deliberate leak detection, isolation, drainage, redundancy, and maintenance access.

Electrical Rooms, Generators, and Common-Mode Failure

Coordinate utility service, transformers, switchgear, electrical-room separation, busway, UPS equipment, batteries, emergency generators, fuel systems, maintenance, and equipment replacement as connected risk systems. Redundancy is not useful when supposedly independent systems share the same vulnerable room, flood zone, overhead pipe exposure, fire compartment, control dependency, or maintenance pathway. Concrete examples include two redundant electrical paths through one vulnerable room; two cooling systems dependent on one water header; redundant generators served by one vulnerable fuel-transfer arrangement; and independent IT halls served through a shared, unprotected electrical or mechanical bottleneck. Architects should overlay routes, rooms, fire compartments, water paths, access zones, controls, and replacement routes—not merely compare separate discipline diagrams. Ask what single event can defeat both sides and who owns the corrective action.

Factory Mutual (FM) Data Center Risk-Control Layers

Use these eleven layers as a concise multidisciplinary agenda. Each layer needs an owner, evidence, unresolved-risk statement, and project-specific acceptance path.

  1. 1

    Site and flood exposure

    Screen natural and surrounding hazards, access, elevation, drainage, and recovery.

  2. 2

    Roof and building envelope

    Coordinate complete assemblies, attachment, weather resistance, and maintainability.

  3. 3

    Penetrations and combustible materials

    Control interfaces, continuity, substitutions, and future change.

  4. 4

    Very Early Warning Fire Detection (VEWFD)

    Match detection and response to actual airflow and fire scenarios.

  5. 5

    Water-based fire suppression

    Integrate reliable control with zoning, isolation, drainage, and impairment planning.

  6. 6

    Data hall and aisle containment

    Coordinate airflow boundaries with detection, suppression, egress, and access.

  7. 7

    Uninterruptible Power Supply (UPS) and lithium-ion batteries

    Resolve chemistry, configuration, separation, protection, ventilation, and replacement.

  8. 8

    Electrical rooms and utility resilience

    Separate paths and remove shared spatial, environmental, and control vulnerabilities.

  9. 9

    Generators and fuel systems

    Test fuel delivery, transfer, containment, weather, access, and maintenance dependencies.

  10. 10

    Heating, Ventilation, and Air Conditioning (HVAC), cooling, and water

    Plan leak control, isolation, drainage, redundancy, treatment, and heat rejection.

  11. 11

    Inspection, testing, and business continuity

    Keep protection functional through turnover, impairment, change, and recovery.

Eleven data center risk-control layers from site exposure through operations and continuity.
Factory Mutual (FM) risk review spans the entire facility—from site elevation and roof assemblies through fire protection, power, batteries, cooling, and business continuity.

The Architect's Factory Mutual (FM) Review Checklist

Six clearly owned checklist groups keep risk decisions visible across planning, detailing, coordination, commissioning, and operations.

  1. 1

    A. Site and hazards

    Flood exposure; wind; hail; seismic and geotechnical risk; wildfire and smoke where relevant; emergency access; adjacent property exposure.

  2. 2

    B. Building envelope and roof

    Roof assembly and attachment; drainage; exterior walls; insulation; penetrations; louvers; doors; weather continuity; fire-resistance continuity.

  3. 3

    C. Fire protection

    Detection; Very Early Warning Fire Detection (VEWFD) where appropriate; sprinkler or preaction strategy; clean agent; compartmentation; fire pump; water supply; impairment strategy.

  4. 4

    D. Electrical and batteries

    Utility redundancy; transformers; switchgear; Uninterruptible Power Supply (UPS); batteries; generators; fuel; separation; replacement access.

  5. 5

    E. Cooling and water

    Heating, Ventilation, and Air Conditioning (HVAC); liquid cooling; Coolant Distribution Unit (CDU); leak detection; drainage; treatment; heat rejection; maintenance access.

  6. 6

    F. Operations and continuity

    Inspection; testing; maintenance; alarm response; impairment procedures; emergency response; training; recovery; change management.

Architect review checklist spanning site, envelope, fire protection, electrical systems, cooling, and operations.
The architect's Factory Mutual (FM) review should start during planning and continue through detailing, coordination, commissioning, and operations.

When Factory Mutual (FM) Should Enter the Project

Bring loss-prevention criteria into every decision gate. The workflow is iterative: later testing can reveal a planning assumption that must be corrected, and operational changes must return to the same risk logic.

  1. Step 1

    Site screening

    Evaluate hazards before acquisition.

  2. Step 2

    Concept design

    Identify owner, insurer, and Factory Mutual criteria before the layout is frozen.

  3. Step 3

    Envelope + fire strategy

    Coordinate materials, compartmentation, detection, suppression, drainage, and access.

  4. Step 4

    Power + battery + cooling coordination

    Test whether supposedly redundant systems are genuinely independent.

  5. Step 5

    Detailed risk review + insurer alignment

    Resolve identified loss-prevention issues before construction.

  6. Step 6

    Testing + operations + continuity

    Verify that protection systems remain functional after turnover.

Six-step property-loss-prevention workflow from site screening through operations and continuity.
Factory Mutual (FM) should be used as an early design lens, not introduced after major planning, procurement, and coordination decisions have already been made.

A Practical Design Review Matrix

The matrix below identifies typical coordination roles, not universal assignments. The project responsibility matrix, contracts, applicable law, insurer engagement, and Authority Having Jurisdiction process establish who actually decides, designs, reviews, and accepts each item.

Factory Mutual (FM) Review Zones for Data Centers

Review ZoneWhat Can Go WrongArchitectural / Planning ResponseWho Must Confirm
Site / floodInundation, inaccessible site, disabled utilitiesSet planning elevations, drainage, access, and critical-equipment locations from project hazard dataTypically owner, insurer, architect, civil engineer, structural engineer, and Authority Having Jurisdiction (AHJ)
Envelope / roofWind, hail, water entry, combustible or incompatible assemblyCoordinate approved or accepted assemblies, attachment, drainage, interfaces, and accessTypically owner, insurer, architect, structural engineer, and manufacturers
PenetrationsFire, smoke, air, or water bypasses intended barrierSchedule openings, tested details, inspection, and change controlTypically architect, relevant engineers, fire protection engineer, manufacturers, and Authority Having Jurisdiction
Fire detectionSmoke is not detected early or alarms do not trigger useful responseModel actual airflow; coordinate sampling, testing, alarms, and response sequenceTypically owner, insurer, fire protection engineer, equipment manufacturer, and Authority Having Jurisdiction
Water-based fire suppressionFire grows, discharge affects excessive area, or impaired system is unavailableCoordinate system type, zoning, isolation, drainage, maintenance, and impairment controlsTypically owner, insurer, fire protection engineer, civil and mechanical engineers, and Authority Having Jurisdiction
Battery systemsThermal event propagates or affects adjacent critical infrastructurePlan chemistry and configuration, separation, detection, ventilation, protection, access, and drainageTypically owner, insurer, architect, electrical and fire protection engineers, manufacturer, and Authority Having Jurisdiction
Electrical systemsFault or room event defeats redundant pathsMap segregation, compartments, overhead exposure, bypass, controls, access, and replacementTypically owner, insurer, architect, electrical engineer, utility, and manufacturers
Generator / fuel systemsShared transfer fault, fire, spill, weather, or inaccessible equipmentSeparate dependencies; coordinate containment, delivery, ventilation, access, and replacementTypically owner, insurer, architect, civil, structural, mechanical, electrical, and fire protection engineers
Cooling / liquid systemsLeak, pump, control, or header failure removes disproportionate capacityZone equipment; provide detection, isolation, containment, drainage, and service routesTypically owner, insurer, architect, mechanical and electrical engineers, and manufacturers
Water / drainageSource loss, overflow, corrosion, contamination, or water reaches critical roomsMap sources and destinations; isolate branches; coordinate treatment, overflow, and drainsTypically owner, insurer, architect, civil and mechanical engineers, and utility
Operations / continuityProtection is impaired, untested, inaccessible, or altered after turnoverDefine inspection, testing, impairment, training, change control, spares, and recovery plansTypically owner and insurer with design professionals, manufacturers, and authorities as project-specific needs require

Role combinations are typical coordination participants only; project-specific confirmation required.

What Developers Should Ask Before Design Freeze

Turn unresolved risk into direct questions with named owners and dates. Answers should cite current project evidence rather than a prior project's assumptions.

  1. 1

    Criteria

    Is the insurer known? Is Factory Mutual criteria applicable? Has the team received current project-specific insurer requirements? Who owns final insurer coordination?

  2. 2

    Site and envelope

    Have natural hazards and flood exposure been reviewed? Is the roof assembly compatible with loss-prevention criteria? Are wall and insulation combustibility decisions resolved?

  3. 3

    Fire and batteries

    Is the fire strategy integrated with aisle containment and airflow? Are battery chemistry and configuration known? What still requires Authority Having Jurisdiction confirmation?

  4. 4

    Power and cooling

    Are critical electrical systems protected from common-mode failure? Is liquid cooling included? Where can leaked water or coolant go?

  5. 5

    Independence and recovery

    Can major equipment be replaced without taking unrelated systems offline? Can redundant systems actually fail independently?

Common Design Mistakes

These mistakes usually arise when one discipline's apparently complete answer is not tested against the whole-facility loss scenario.

  1. 1

    Mistake 1

    Treating Factory Mutual (FM) as a late-stage specification check.

  2. 2

    Mistake 2

    Assuming code compliance equals insurer acceptance.

  3. 3

    Mistake 3

    Selecting roofing and wall assemblies without understanding loss-prevention criteria.

  4. 4

    Mistake 4

    Treating clean-agent suppression as a universal replacement for water-based fire protection.

  5. 5

    Mistake 5

    Adding battery systems after room geometry and ventilation strategy are fixed.

  6. 6

    Mistake 6

    Designing liquid cooling without leak containment and failure isolation.

  7. 7

    Mistake 7

    Calling a system redundant when both paths share a common vulnerability.

  8. 8

    Mistake 8

    Ignoring maintainability and equipment replacement.

  9. 9

    Mistake 9

    Failing to carry Factory Mutual lessons into repeatable reference designs.

DCFR Design Principle

Factory Mutual (FM) should be treated as an early feasibility and design-control lens. DCFR would flag a concept that appears code-compliant but retains unresolved property-loss exposure involving flood, roof, envelope, combustible assemblies, penetrations, fire protection, batteries, electrical systems, generator and fuel systems, cooling, water, common-mode failure, or operational continuity.

CODE COMPLIANCE ALONE DOES NOT AUTOMATICALLY MAKE A DATA CENTER LOSS-PREVENTION OPTIMIZED, RESILIENT, OR INSURABILITY-READY.

Current Technical Basis — August 2026

FM

Property Loss Prevention Data Sheets

Use the current project-applicable data sheets and insurer guidance; access and applicability require project-specific confirmation.

FM Approvals

FM Approvals

Product and system certification is distinct from broader property-loss-prevention guidance.

National Fire Protection Association (NFPA)

Codes and Standards

The adopted editions and project-applicable standards require confirmation.

American Society of Heating, Refrigerating and Air-Conditioning Engineers (ASHRAE)

Data Center Resources and Datacom Series

Apply current project-relevant thermal guidance with qualified engineering review.

Technical basis reviewed August 2026. Cooling technology, equipment capability, vendor qualification, and industry guidance continue to evolve; project decisions should use the latest applicable manufacturer data and professional engineering analysis.

Capacity-delivery review checklist

What to verify before the next release gate.

  • Confirm adopted code, Authority Having Jurisdiction (AHJ) process, owner criteria, insurer, and applicability of Factory Mutual (FM) guidance.
  • Screen natural hazards, surrounding exposures, access, utilities, water, and recovery constraints before acquisition.
  • Coordinate complete roof, wall, opening, joint, and penetration assemblies—not isolated products.
  • Integrate airflow, detection, suppression, drainage, compartmentation, alarm response, and impairment management.
  • Resolve Uninterruptible Power Supply (UPS), battery chemistry and configuration, ventilation, separation, protection, access, and replacement.
  • Map every electrical, fuel, cooling, water, control, spatial, and maintenance dependency that can defeat redundant capacity.
  • Commission protection and response sequences, then carry inspection, testing, training, change control, and recovery into operations.

What DCFR would flag

Delivery risks that should be visible early.

DCFR would flag a code-compliant concept when unresolved property-loss exposure remains in its site, envelope, fire protection, battery, power, fuel, cooling, water, common-mode-failure, maintainability, or continuity strategy.

Professional confirmation required

Items requiring project-specific validation.

This article is planning-grade educational guidance. Factory Mutual (FM) recommendations, insurer requirements, applicable codes, product approvals, fire protection criteria, battery requirements, natural-hazard criteria, electrical design, cooling design, structural design, and Authority Having Jurisdiction (AHJ) interpretations are project-specific and require confirmation by the owner, insurer, qualified design professionals, applicable authorities, and relevant manufacturers.

Final takeaway

CODE COMPLIANCE ALONE DOES NOT AUTOMATICALLY MAKE A DATA CENTER LOSS-PREVENTION OPTIMIZED, RESILIENT, OR INSURABILITY-READY.

Surface site, code, utility, and delivery risk before it becomes expensive.

DCFR converts early assumptions into planning-grade flags, confirmation registers, and decision-ready feasibility outputs.