The Electricity at Work Regulations 1989 don't ban live working. They set a high bar for when it's permitted, and data centre environments make that bar harder to clear than most industrial sites, because the operational pressure to avoid interrupting live IT load cuts directly against the regulation's starting assumption that work should be done dead wherever reasonably practicable. That tension sits underneath most of what gets called data centre electrical compliance, and it's where a lot of the existing guidance on BS 7671 testing and UPS validation stops short.
When live working is actually permitted
Regulation 14 of the Electricity at Work Regulations is specific about this, not permissive. Live work is only justified where it is unreasonable in all the circumstances for the conductor to be dead, where it is reasonable for the person to be at work on or near it while live, and where suitable precautions (including, where necessary, suitable protective equipment) are taken to prevent injury. All three conditions have to be met, not just one.
In a data centre, "unreasonable to isolate" gets argued on uptime grounds more than it would on a typical industrial asset. Dual-feed redundancy, UPS topology and the contractual weight of an SLA all feed into that judgement. None of that changes what the regulation actually requires: a documented, case-specific justification, not a general policy that live diagnostic work on switchgear is acceptable because the facility runs N+1. Where we've seen this handled well, the justification sits in the risk assessment behind the permit, not as a blanket statement in a procedure manual.
What a certificate of isolation needs to show
Once isolation is the chosen route, rather than live working, the certificate of isolation is the record that the isolation was actually achieved and verified, not just instructed. In practice that means it should identify the specific isolation point (not just the circuit or panel), the method used to prove dead, who applied the lock or tag, who tested for dead before work started, and who accepted the isolation as suitable for the task described on the permit.
That last point matters more in data centres than the compliance literature usually acknowledges. A single isolation point on a busbar or PDU can sit behind several live permits at once, covering structured cabling work, mechanical cooling intervention and electrical testing in the same zone. The certificate needs to show not just that isolation happened, but that it's still valid for every piece of work currently relying on it.
Where testing and the permit process diverge
Most of what's published on data centre electrical compliance covers the hardware side: periodic inspection against BS 7671, UPS battery and load testing, switchgear maintenance regimes, thermal imaging. That work is necessary and it's well covered elsewhere. What it doesn't touch is the control-of-work layer that governs who is allowed to approach that switchgear on a given day, under what isolation, with what competency, and how that gets recorded.
A compliance certificate from an electrical contractor tells you the installation met a standard on the date it was tested. It doesn't tell you whether the isolation applied for last Tuesday's rack replacement is still logged as live, or whether two contractors working in the same electrical room this week know about each other. That's a permit-to-work and isolation management question, and it sits right next to the testing question without being the same one.
Connecting isolation to the audit trail
Where isolation certificates are held on paper or in a separate spreadsheet from the permit system, the link between "this circuit is isolated" and "this permit depends on that isolation" has to be maintained manually. On a site with a small electrical footprint that's manageable. On a data centre campus with multiple halls, redundant distribution paths and several contractors on site concurrently, it becomes harder to keep current, and harder still to reconstruct after the fact if someone asks what state an isolation was in on a particular date.
A control isolation that's linked directly to the permit register, rather than tracked in parallel, means a permit can't be issued or kept live against an isolation point that's been removed, and an isolation can't be released while a dependent permit is still open. We've written before about why isolation is often the weak point in permit to work, and the same failure mode shows up on data centre electrical infrastructure as readily as it does on a process plant, even though the hazard and the regulatory hook are different.
What to check in your own process
If you're assessing how well your current process holds up, a few things are worth testing directly rather than taking on trust. Ask whether you can pull the complete history of a specific isolation certificate, including every permit that was ever linked to it, not just the most recent one. Try to find out what would actually stop someone removing an isolation while a second, unrelated permit still depends on it. Check whether your live working justifications are recorded against the specific task and date, or whether they default to a generic statement that gets reused. And look at how visible concurrent electrical work is across contractors working in the same switchroom or distribution zone, particularly where an isolation point is shared.
None of these are testing questions. They're control-of-work questions, and they're the ones that tend to get missed when compliance is framed purely around BS 7671 and statutory testing intervals.
We've written in more detail about how HV/LV Authorised Persons are structured into data centre electrical compliance, and separately about when live working is actually permitted under the Electricity at Work Regulations. If your current process keeps isolation certificates and permits in separate systems, or if reconstructing a past isolation state takes more than a few minutes, that's usually the first place worth looking. We can walk through how a digital control-of-work workflow would handle shared isolation points and concurrent electrical permits on your site, using your own asset hierarchy rather than a generic example.