The Defence Investment Plan commits £298 billion over four years, and £22.7 billion of it goes to Defence Infrastructure and Estate. That makes the estate the fourth largest chapter in the plan, ahead of both the Land and Maritime domains. What the plan buys, and why the asset data model may not survive it, is covered in What the Defence Investment Plan Really Buys.

This piece is about a narrower question with harder dates attached. The department does not maintain most of that estate. Contractors do. And the asset record moves between them, on dates the plan itself publishes.

The supply chain is where the estate data actually lives

This is not a hypothetical exposure, and the last two years have made that plain twice.

In May 2024 the Ministry of Defence disclosed to Parliament that a payroll system operated by a third-party shared services provider had been compromised. Names, bank details and in some cases home addresses of up to 272,000 serving personnel and veterans were exposed. No formal attribution was made.

In September 2025 a maintenance and construction contractor working across the defence estate was breached. Around a thousand documents relating to eight Royal Air Force and Royal Navy sites were subsequently published, two of them hosting United States Visiting Forces. Reported material included visitor records, vehicle registrations, contact details and internal security guidance. The Ministry confirmed it was investigating.

The composition of that list is worth pausing on. Six of the eight sites are in Cornwall and Devon, and only the two Suffolk stations sit outside the south west. What the eight have in common is not their importance to Defence. It is that one contractor held their files. The most consequential base on the list was exposed for exactly the same reason as the least.

Neither breach came through the Ministry's own systems. Both came through a supplier holding Ministry data, and in the second case a supplier whose function was maintaining the estate. That is the part worth sitting with. The organisations holding the most detailed working knowledge of a defence estate, who holds access, which systems sit where, what condition they are in, are frequently not the department. They are the contractors. And that knowledge moves between organisations at every recompete.

Neither incident says anything about whether the records those suppliers held were accurate. What they settle is where the record lives, and what the response to them protects. Those are different questions, and only one of them has a deadline attached.

The plan itself puts dates on exactly that. It sets out PFI expiries falling inside the investment period: the water and wastewater contracts in 2028 and 2030, the Defence Academy at Shrivenham in 2028, Main Building in 2030, and Northwood Headquarters in 2031. Each one is a handover of the asset record from an outgoing provider to an incoming one, on a known date, for a site whose criticality is not in question.

That exposure is being addressed, and seriously. The Ministry of Defence has asked all industry partners to achieve Defence Cyber Certification Level 0 by 31 December 2026, assessed through an approved certification body, with higher levels scheduled where they are required lower in the supply chain. It replaces per-contract self-attestation with organisation-wide certification, and it will close a real gap.

It would also be wrong to suggest nobody has thought about what happens when a contract ends. The Model Services Contract, which shapes a great deal of major public sector contracting, devotes an entire schedule to exit management. An exit plan must exist within three months of the contract starting and be updated annually. The supplier must maintain a register of the assets required to deliver the service. Both sides appoint an exit manager. Subcontracts can be novated to the authority or to a replacement supplier. The supplier must provide full support for the transition, with months of notice. Under G-Cloud terms the supplier must return the buyer's data and then destroy its remaining copies, confirming in writing that it has done so, and where the buyer asks for it the returned version must be complete and uncorrupted.

That is a serious body of work, and none of it is the problem.

Look at what all of it actually tests. Exit management asks whether the record moved. Certification asks whether it was protected while the supplier held it. The contractual language asks whether the copy that arrives is complete and uncorrupted, which is a question about fidelity to what the supplier had, not about whether what the supplier had was right.

The distinctions matter here. The asset register in an exit schedule is a register of the things needed to deliver the service, which exists so the parties can work out what transfers and who owns it. It is not the client's record of its own estate. And Defence Standard 05-138, which does require an accurate inventory of data and control of government information across its lifecycle, applies those controls at its higher levels. Level 0, the only level with a deadline attached, does not reach them.

So the sequence that should worry a department is entirely compliant. A certified supplier holds an estate record that has drifted for years. At exit it produces the register the schedule requires, returns a complete and uncorrupted copy of exactly what it held, destroys its own copies on schedule and confirms in writing that it has done so. Every obligation is discharged. The successor still cannot reconcile what it has been given, because nothing in the process ever asked whether the record was true.

That is the gap. Not an absence of process, which would be easy to point at, but a body of process that is thorough about moving the record and silent about whether it was ever right.

Nor is the pattern confined to Defence. It ran in the opposite direction in 2025, when a cyber attack on a UK vehicle manufacturer halted production for five weeks. The Cyber Monitoring Centre classified it as a Category 3 systemic event and modelled the loss at £1.9 billion, affecting more than 5,000 UK organisations, most of them firms whose own systems were never attacked. In Defence a supplier's weakness reached the department. In manufacturing the manufacturer's outage reached the suppliers. Either way the dependency was real, material and unmapped until an event forced somebody to map it.

Governed asset data is usually argued for on efficiency grounds. In this sector it is also a security control, and the accuracy of the record is the one part of the supply chain problem with no scheme and no deadline attached to it. You cannot apply proportionate protection to a record you have not classified, held by an organisation whose handling of it you have not assured. And you cannot assure a handover you cannot describe.

The pattern that is already on the record

In April 2022 the arrangements for maintaining service family housing were restructured. A single prime arrangement was replaced, under the Future Defence Infrastructure Services programme, with one national management contract and four regional maintenance contracts. What happened next is a matter of public record rather than opinion, and Parliament has examined it in detail.

The Defence Committee reported that the senior Ministry of Defence official accountable for the estate told it, "it is fair to say we lost control for a number of months in the first year of FDIS". The Ministry attributed the failure to an IT failure between the three contractors and to insufficient staffing in the national call centre and the trades. One contractor accepted that an eight-month mobilisation period had been too "ambitious". The Families Federations had raised the inherited backlog as a concern before the contracts went live.

The structural cause is the one that matters here. There was no contractual interface between the national management contract and the regional maintenance contracts. One of the contractors told the Committee this meant "no one contractor had responsibility for the mobilisation and transition of service". The Committee reached the same conclusion in its own words, holding the department accountable for the gap and finding that it "contributed substantially to the problems with the rollout of the new accommodation service".

The consequences landed on service families across the winter of 2022 to 2023. Slow responses, missed appointments, and long delays resolving total loss of heating, hot water and cooking facilities. Contractors funded £2.15 million in compensation payments to service personnel between April 2022 and October 2023. Satisfaction with maintenance and repair of Service Family Accommodation fell to 19 per cent in 2023. Twenty-nine per cent of service personnel cited accommodation as a factor in their intention to leave. The Committee also found that poor customer service was compounded by "an information system which does not hold sufficient information".

That is the lesson, and it is not a technology lesson. The contracts were awarded. The systems went live. What did not transfer cleanly was the record: the inherited backlog, the property data, the job history, and the interfaces between parties who now had to share all three. Mobilising several contractors onto one estate is a data problem wearing a commercial suit. When the data does not hold, the people who feel it are families waiting on a boiler in January.

The same point arrives from the other direction whenever delivery is compressed. An eight-month mobilisation was accepted, in hindsight, as too ambitious. That is the common pattern rather than the exception. A technical implementation can succeed on its own terms, hit its dates and pass its acceptance tests, and still create significant problems downstream, because the schedule left no room to close the data out. Technology readiness and data readiness are not the same thing, and when a programme comes under time pressure only one of them is usually protected. A platform can go live and still sit on data that no model should be allowed to reason over.

That distinction is the whole argument. The Defence Investment Plan buys technology readiness at scale. It does not, by itself, buy data readiness. The two have to be closed separately, and the second one has to come first.

What this means for the strategy-to-procurement window

For programme leaders across the Ministry of Defence, in the other government departments, NHS bodies and local authorities running comparable estates, and in the industry primes delivering the work in all of them, the practical question is not whether to adopt AI and autonomy. The plan has answered that. The question is what condition the underlying asset and configuration data is in before the autonomy layer is placed on top of it.

The Defence Investment Plan is the document with the numbers attached, which is why it is the worked example here. The pattern it exposes is not confined to Defence. Any organisation that has outsourced the delivery of its estate, retained the accountability for it, and is now being sold autonomy has the same exposure, whichever department or sector it sits in.

Three programmes already in flight make that concrete, and none of them is an AI programme.

The first is the consolidation of defence equipment engineering and asset management onto a single platform. The Defence Equipment Engineering Asset Management Systems programme was contracted in October 2025 at £320 million, and replaces seventeen fragmented, siloed and outdated applications with one system serving more than 65,000 users across over 130 major military platforms and assets. The capability case is strong, the benefits claim is over £1 billion, and the platform is explicitly intended to use AI. What the announcement does not address is the state of the seventeen records being merged. Consolidation does not produce a single version of the truth. It produces a single place where seventeen versions of the truth now have to be reconciled, and the reconciliation is the work. It is also the part that tends to be scoped last and funded least.

The second is the ingestion of expiring private finance contracts. As each one reaches its end date, the asset record built and maintained by the outgoing provider has to be taken on by the department or by whoever replaces them. The plan publishes those dates. Ingestion is the moment the condition of that record stops being the provider's problem and becomes the department's, and it usually arrives when there is least time left to do anything about it.

The third is the water estate, and it is the largest of them. The Aquatrine contracts cover around 2,600 sites, roughly 85 per cent of the Great Britain defence estate, and expire in 2028 and 2030. Whatever commercial model is chosen, the asset record for the water and wastewater infrastructure across most of the estate changes hands inside this investment period. Networks, pumping stations, treatment works and connections, described by data assembled under one contractual regime and about to be relied on under another.

None of these three buys an AI capability. All three determine what an AI capability would have to reason over when it arrives.

The checks worth running now, while the procurement pipeline is still forming:

Whole-life cost is only as reliable as the asset records it is calculated from. If the configuration baseline is contested, so is every downstream figure.

Asset criticality has to be governed, not assumed. An autonomous system prioritising by criticality will act on whatever criticality data exists, correct or not.

Through-Life Management depends on continuity of data across handovers between contractors. Contractor dependency is a stated fear in this sector for good reason, and data continuity is where it usually bites. The PFI expiries in this plan give that a date rather than a worry.

None of this argues against the plan. It argues for getting the sequence right. The organisations that will capture the autonomy dividend are not the ones that move first. They are the ones whose asset data can be trusted when the autonomy arrives.

ISO 55000 was designed for exactly this class of problem, and it remains a defensible, applicable discipline for governing long-life asset data in regulated environments. The UK-sovereign, security-cleared, practitioner route into this work matters in Defence in a way it does not in most sectors.

Data governance as a service exists to close this specific gap. That is a factual description of the work, not a pitch. The pitch, if there is one, is simpler than any product. Look at what the Defence Investment Plan really buys, and ask what the autonomy will be reasoning over on day one.

Foundations before automation.

Sources and further reading