AISB Intelligence Report · 2026-07-06

The AI-HVAC Retrofit Decision: A Feasibility and M&V Framework for Class-A Office Towers

Occupancy, utilization & tenant experience

📄 Formatted PDF editions (English · 繁體中文) are free for subscribers — subscribe to get them →

Analysis Report v2 — Class-A Office Tower AI-HVAC Retrofit: Feasibility & M&V Analysis

run: cre-ts-class-a-office-tower-ai-hvac-retrofit-fe-20260707-aa6a · squad: CRE-TS · client: aisb · finalized: 2026-07-07 · audience: building owner / asset manager

This v2 is the single coherent report: the ARCHITECTURE (framing, logic, decision gates) and DETAIL (tables, formulas, thresholds, ledger) lanes of v1 are integrated under one section-numbering scheme, the independent correction plan is applied, and a brief-fidelity gate has been run against the original request.

Grounding pass 2026-07-07: 11 values resolved via web-verified sources (see §8), 5 caveated as single-source/partial, and 13 items remain [UNVERIFIED] — deliberately, no citable source found. All resolved values are source-attributed and tiered per Harper's grounding dossier; no unsourced number was introduced, and no caveat was upgraded.


Correction-plan disposition (applied at the top, per protocol)

BLOCKING — all 6 applied:

# Item Disposition
B-1 PART A/B subsection-numbering collisions vs cross-references APPLIED — merged into one report; PART A retitled to the scheme every cross-reference already used (attribution → §3.3, gate tree → §3.4, operator readiness → §3.5, governance → §5.4, risk logic → §6.4). "Why feasibility precedes economics" is now the §3 unnumbered preamble so §3.1/§3.2 stay reserved for BMS-readiness / point-coverage content. DETAIL tables now sit under their matching unified section.
B-2 GATE-1 "aggregate readiness score" contradicts "gates in series" + orphan weight column APPLIED — tree node now reads "series evaluation — verdict = worst dimension (min across §3.1/§3.2/§3.3/§3.5)"; the empty "Weight" column is removed from the §3.4 sub-gate table and its note rewritten to the min/series rule; §7 GATE 1 references the series rule.
B-3 Invented thresholds (point-coverage %, critical-check bands, ≥6-month fault history, ~$1M Monte Carlo trigger) un-tagged and absent from the ledger, falsifying the ledger's reconciliation claim APPLIED — each tagged [ILLUSTRATIVE DEFAULT — not a sourced/validated threshold; owner may recalibrate] in place; ledger rows 29–32 added; §8 internal-consistency note softened to a now-true statement.
B-4 Denominator "inflation guard" states the inflation direction backwards; DETAIL restatement is a broken sentence APPLIED — both passages rewritten (§4.1): a given absolute saving is a large % of the small HVAC-energy-OpEx denominator and a small % of total OpEx; the dishonesty to guard against is quoting the large HVAC-basis % while implying the total-cost basis, or 1/CapRate value conversion. Rule printed: every savings % must name its denominator inline.
B-5 Declared blocking check B1 (life-safety / licensed-PE statement) never discharged in the body APPLIED — explicit write-scope-exclusion + licensed-PE statement added at §6.4 and echoed at every write-touching gate in §7.
B-6 §6.3 "Mandatory Financial Triggers" is US-only, violating the dual-jurisdiction rail APPLIED — APAC-bracket rows added (Kigali-Amendment HFC controls as adopted in the named APAC jurisdiction; APAC minimum-efficiency / energy-code capital-action trigger), both [UNVERIFIED]; ledger rows 24a/25a added.

ADVISORY — 7 dispositions (all applied):

# Item Disposition
A-7 IPMVP decision rule non-exhaustive, no terminal ELSE APPLIED — terminal ELSE branch added (route to §3.2 remediation / escalate to referee); precedence C > B > D > A made explicit with a one-line justification; Option-D caveat added (calibration needs some measured baseline). Strengthens R1.
A-8 Plan-internal refs ("§0.5", "§0.6", "§0.1") + undefined R/B codes leak into the deliverable APPLIED — refs fixed/inlined; a glossary (§0.3) now defines every R-rail and B-check so the blocking-checks section is legible without the plan.
A-9 Internal jargon ("v119", bull_bear_setpoint_gate.py, "Comfort-Bear", "fin-commander") in an owner-facing doc APPLIED — generalized to role language throughout; the internal governance tags are preserved once, as a footnote, for traceability (not deleted, per the report's own audit-trail value).
A-10 GATE 2 "fault-corrected savings alone sufficient?" not operable — no fault-burden monetization method APPLIED — Phase-2 checklist line added specifying per-fault engineering savings vs Guideline 36 correct-sequence operation (or a short post-RCx measurement period), producing a $ figure with its own uncertainty caveat.
A-11 Bracket-selection overclaims ("worst-and-best case for the verdict") — argued only on the economizer axis; tariff axis unbracketed APPLIED — claim downgraded at the claim site (§2.2) to "brackets the climate-mechanism axis only; the tariff axis is NOT yet bracketed and the R6 widening rule applies to it with full force."
A-12 EFLH promised in the architecture, never delivered in DETAIL/Register/ledger APPLIED — EFLH row added to §2.A and the ledger ([UNVERIFIED]), with its §4.2(b) mechanism-sizing role noted (kept rather than deleted because it is a real load-driver).
A-13 §2.3 wording ("presented as a benchmarking band") vs two empty [UNVERIFIED] cells; §4 presents 4.2 before 4.1/4.3, merged heading APPLIED — §2.3 wording aligned ("…once sourced; in this version both cells are deliberately [UNVERIFIED]"); §4 reordered 4.1 → 4.2 → 4.3 with separate headings, absorbed by the structural integration.

Rejections: none. All 7 advisories were low-cost and improved either operability, honesty, or audience-fit; none conflicted with a rail.

Honesty rails preserved: every load-bearing number retains a source or an [UNVERIFIED] tag; no vendor endorsement or comparative product ranking anywhere; dual-jurisdiction (US + APAC) values are presented as brackets with the jurisdiction named; every financial exhibit carries the illustrative-not-advice disclaimer; the human-in-the-loop gate on every control write is restated at each write-touching gate.


0. Controlling Frame, Rails & Glossary

0.1 The archetype-not-asset constraint (binds every section)

This is not a building audit. It is a decision-gate framework for a representative asset. The single most important structural consequence, which shapes every section below:

  • The subject is a representative ~100,000 sq ft Class-A office tower with an asserted BACnet BAS, chiller plant, and VAV AHUs. No surveyed data, meter reads, trend logs, or utility bills exist.
  • Therefore every quantitative statement about this building is authored as one of two things — an industry range with a cited source, or a decision criterion / gate threshold the owner applies when real data arrives — and never as a finding about the archetype's actual performance. Any number written as if it were this building's measured value is a violation; [UNVERIFIED — requires site data] stands in its place.

0.2 The binding rails (R-rails)

Five rails and one uncertainty discipline bind downstream and are named so the reasoning is legible:

  • Honesty rails — every load-bearing number carries a source or [UNVERIFIED]; no vendor endorsements (categories, never comparative product rankings); savings basis is HVAC/energy OpEx only (never total-OpEx, never 1/CapRate value-inflation presented as forecast); CapEx/NPV/payback are illustrative, not investment advice; auto-BMS-write requires a human gate.
  • Dual-jurisdiction (US + APAC) discipline — region-sensitive values (grid emission factor, tariff, degree-days, code trigger, refrigerant schedule) are presented as a range bracketing both, jurisdiction named beside each number. A two-point bracket is a modeling assumption, not a coverage guarantee: if the verdict can flip within a jurisdiction's own climate/tariff range, the single-bracket presentation is inadequate and must be widened (see §2.2, R6).
  • Engineering-anchor floor — every substantive technical claim cites a standard/guideline or is tagged [UNVERIFIED].
  • Number-source resolution — canonical values (equipment lifetimes, EFLH, degree-days, CV(RMSE)/FSU thresholds, GWP figures, chiller efficiency) are resolved to named authoritative sources, not emitted from memory.
  • Stakeholder set (three lenses). The financial decision-maker is the owner / asset manager, but two further stakeholders are first-class value and persistence axes, not mere constraints: the occupant / tenant (comfort degradation is a downside on the value case via tenant-churn / lease-retention risk on NOI, R2) and the facilities / operations staff (operator trust and override behavior determine whether savings persist or decay, R3).

0.3 Glossary of the rail codes (R-rails) and blocking checks (B-checks)

These codes are load-bearing to §9 and are defined here so the report is legible without any external plan:

Code Meaning as used in this report
R1 The IPMVP option is derived from point-coverage data (§3.2), never presumed as a "primary" default.
R2 Occupant comfort degradation is a value-case downside (tenant churn / lease-retention risk on NOI), not merely a control bound — a comfort failure can void an otherwise-favorable case.
R3 Savings persistence is a first-class risk: realized savings decay if operators distrust/override the optimizer; monitored as an ongoing measured quantity.
R4 The savings estimate leads with the conservative, mechanism-anchored range; the marketing "up-to" genre is a demoted caveat, not the organizing frame.
R5 FDD-vs-AI credit is a measured attribution (fault-recurrence rate), not a clean assumed split.
R6 Two-point jurisdiction bracket is adequate only if the verdict does not flip within a jurisdiction's range; otherwise it must be widened.
R7 M&V independence is a required, verifiable property, not a presumed party; supplier/referee overlap is a disclosed, mitigated conflict of interest.
B1 No life-safety-adjacent control modification without a human-gate + licensed-PE (or jurisdictional equivalent) statement.
B3 No M&V claim without a baseline-model citation.
B4 No live >$100K decision without the owner's financial-analysis function supplying the discount rate (see footnote †).
B5 No savings claim without a CV(RMSE)/FSU uncertainty bound.

In BEAST's internal governance these map to specific mechanisms — the human-in-the-loop / occupant-comfort-veto doctrine (internal ref "v119" / bull_bear_setpoint_gate.py / "Comfort-Bear veto") and the internal financial-analysis cross-call ("fin-commander"). They are retained here once, as an internal traceability footnote only; the report body uses role language throughout.


1. Executive Summary & Decision Frame

No new numbers originate here — every figure referenced is established and sourced in §§2–6.

1.1 The central conditional

An AI-HVAC retrofit for a building like this is justified IF, AND ONLY IF, all of the following hold together — it is a conjunction of gates, not a savings headline:

Justified IF the technical + operator-readiness feasibility gates (§3) return GO or a remediable CONDITIONAL, AND the conservative, mechanism-anchored savings range (§4) clears the owner's hurdle rate under their specific tariff and climate (§2 brackets), AND the comfort and savings-persistence guardrails hold (§3.5, §6.4, §7 GATE 3/4) — verified via the IPMVP option that §5 derives from the point-coverage data (§3.2), with savings accepted only when they exceed the M&V uncertainty band.

The verdict is conditional and gated by construction. There is no unconditional "yes." A building that fails the readiness gate, or whose savings sit inside the measurement noise, or whose energy savings come at the cost of comfort complaints or operator reversion, does not clear the frame even if the raw savings percentage looks attractive.

1.2 Bottom line up front

  • This is a methodology + decision-gate framework for a representative asset, not an audit of a specific building. No proceed / do-not-proceed recommendation is made on the archetype, because there is no asset to decide on. The deliverable is the gate sequence the owner runs against their real building (§7).
  • Feasibility is a technical and operational qualifier that precedes economics (§3). The control substrate must be readable at sufficient resolution, safely writable under a human gate, backed by a trustworthy fault baseline, and run by an operator prepared to trust and sustain the optimizer. Any of these failing yields CONDITIONAL (with a named remediation path) or NO-GO before any financial case is entertained.
  • Expected savings are stated conservatively, mechanism by mechanism, on the HVAC/energy-OpEx denominator (§4) — with the honest caveat that the realized value is [UNVERIFIED] until M&V (§5) confirms it exceeds measurement uncertainty. Marketing "up-to" figures are not used as the estimate (R4).
  • Savings are only credible when auditable. The IPMVP option (A/B/C/D) is an output of the point-coverage analysis (§5), not a presumed default (R1), and every savings claim is accepted or rejected against explicit CV(RMSE) / NMBE / FSU thresholds resolved to ASHRAE Guideline 14-2023 (§5.3, B5). A saving smaller than its own uncertainty band is rejected as unverifiable, not reported as a soft win.
  • (R2) Comfort degradation is a downside axis on the value case, not merely a control bound. A retrofit that saves energy while generating comfort complaints can be net-negative on NOI through tenant churn and lease-retention risk. The verdict is therefore conditioned on comfort and persistence, never on savings alone — an energy-positive pilot that fails the comfort/tenant-satisfaction band (§7 GATE 3) does not pass.
  • (R3) Savings persistence is a first-class risk. Realized savings decay if in-house operators distrust and override the optimizer; operator readiness (§3.5) and reversion-monitoring in continuous M&V (§7 GATE 4) are the structural defenses.
  • Every financial exhibit is illustrative, not investment advice, and any control-write recommendation states the human-in-the-loop and occupant-comfort veto explicitly.

1.3 Brief-fidelity statement (does this report answer the question asked?)

The brief requires six coverage items; each is addressed, and there are no unaddressed parts:

# Brief coverage item Where addressed Status
1 Technical feasibility gates (BMS readiness, data/point coverage, FDD baseline) §3.1–§3.5 (+ operator readiness elevated to a fourth gate) ✅ Addressed
2 Expected savings range with honest uncertainty, on HVAC/energy-OpEx basis (no total-OpEx inflation) §4.1–§4.4 ✅ Addressed — mechanism ranges now grounded to named DOE/LBNL sources where resolvable; remaining cells [UNVERIFIED] (see limitation §8/§10)
3 IPMVP option selection (A/B/C/D) + M&V plan + CV(RMSE) acceptance criteria §5.1–§5.4 ✅ Addressed — option derived, not presumed; numeric CV(RMSE)/NMBE/FSU thresholds now resolved to ASHRAE Guideline 14 (§5.3)
4 CapEx envelope + payback/NPV framing (illustrative, not advice) §6.1–§6.3 ✅ Addressed — structural framing + sensitivity; dollar values [UNVERIFIED] (archetype has no quotes)
5 Risks incl. vendor lock-in, cybersecurity, occupant-comfort guardrails (auto-write human gate) §6.4 ✅ Addressed — plus life-safety write-scope exclusion (B1) and persistence risk (R3)
6 Implementation playbook with decision gates §7.1–§7.2 ✅ Addressed — 4-phase gated sequence with halt/rollback per gate

Honest limitation on fidelity (stated, not hidden): because the subject is an archetype with no site data, the report answers the brief at the methodology/decision-gate level, not with building-specific numbers. Coverage items 2, 3, and 4 are answered as ranges, criteria, and rules the owner applies to their real building — the building-specific numeric cells are deliberately [UNVERIFIED] pending site data, not fabricated, even where an industry-range citation now backs the mechanism. This is the correct and only honest way to answer "is a retrofit justified" for a representative asset with no meter data; the deliverable is the framework, and the framework is complete.

1.4 How to read this report

The owner runs the gates in §7 against their real building. §§2–6 supply the reasoning, ranges, and thresholds those gates reference; §8 consolidates every assumption and [UNVERIFIED] tag into one auditable ledger; §9 is the cross-section coherence and blocking-check summary; §10 is the limitations statement. Pointer: the decision gates that operationalize this summary are in §7.


2. Subject Definition, Baseline Context & Analytical Assumptions

2.1 The archetype as a shared analytical object

All downstream sections reason about one archetype, pinned here as an analytical envelope — explicitly a set of modeling assumptions subject to replacement by a real site survey (the §3 readiness gate):

  • Envelope: ~100,000 sq ft, Class-A office.
  • Occupancy profile: a nominal single-/multi-tenant assumption with nominal occupied hours (see §2.A). (R2) The occupant / tenant is named here as a stakeholder in the occupancy-profile assumption, not only the owner — because the occupancy pattern is simultaneously (a) a driver of the baseline energy model and (b) the population whose comfort is the value-case downside axis. The same occupied-hours assumption that shapes the savings estimate also defines who bears any comfort degradation.
  • Systems (asserted, not surveyed): chiller plant + VAV AHUs on a BACnet BAS. Firmware age, controller vendor, point-naming hygiene, and trend-log retention are UNKNOWN and are gates in §3, not givens.
  • Climate stance: the analysis carries both a representative US and a representative APAC climate zone as explicit brackets (§2.A), because degree-days, code triggers, and grid factors diverge materially across them.

2.2 Bracket-selection logic (R6) — why two points, and when two is not enough

The reasoning that justifies the jurisdiction brackets is load-bearing:

  • The brackets are chosen to be decision-conservative on the climate-mechanism axis. US and APAC each span enormous internal divergence — a tropical cooling-dominated zone (e.g., ASHRAE Zone 1A/2A) behaves nothing like a temperate mixed zone (e.g., Zone 5); tariff regimes range from wholesale-market (e.g., PJM) to state-regulated to APAC feed-in / tiered structures. Choosing "a representative" middle case would understate the spread the verdict must survive. The brackets are therefore selected to bracket the climate-mechanism worst-and-best case (high-economizer-value vs near-zero-economizer-value); the Assumption Register (§2.A) states which zones were chosen and why.
  • (A-11) Honest limit on the claim — the tariff axis is NOT yet bracketed. The "decision-conservative / worst-and-best case" claim is demonstrated only on the economizer/climate-mechanism axis. The tariff axis (§2.A items 8–9) is [UNVERIFIED] with jurisdictions unnamed — it is not bracketed. The R6 widening rule applies to it with full force: once real jurisdictions are named, if the verdict flips across their tariff sub-ranges the bracket must be widened before any conclusion is drawn.
  • The adequacy caveat is structural, not cosmetic. A two-point bracket is a modeling assumption about coverage. If the verdict swings within a single jurisdiction's climate or tariff range — "justified" at one end of the US bracket and "not justified" at the other — the two-point presentation is inadequate and must be widened to expose that internal flip. This prevents a false "US: yes / APAC: no" simplification from hiding a "US-warm: yes / US-cold: no" reality.

2.3 Baseline benchmarking stance

The Class-A office EUI figure is presented as a benchmarking band once sourced (US and APAC brackets), explicitly not this building's EUI — the archetype has no measured EUI. (A-13) In this grounding pass both benchmark cells now carry a single-source industry band with a visible caveat (§2.B), pending primary-table confirmation. The framing rule: a benchmark band informs where the archetype plausibly sits; it never becomes a finding about actual consumption.

(Out of scope here: the site-survey data-collection procedure itself, which is the §3 readiness gate rather than a data set.)

2.A Assumption Register

# Parameter Assumed value / range Source or tag Sensitivity flag (does verdict swing on it?)
1 Gross floor area ~100,000 sq ft (single archetype, per brief) Brief (stipulated) LOW — scales $/kWh terms linearly, does not change % savings or gate logic
2 Building class / use Class-A multi-tenant office Brief (stipulated) LOW
3 Occupancy profile Multi-tenant assumed; nominal occupied hours ~50–60 hrs/week (weekday business hours + partial weekend) [UNVERIFIED — requires site data] (industry-typical office schedule, no cited source for THIS archetype) MEDIUM — affects EFLH and schedule-based savings mechanisms (§4.2b)
4 HVAC system config Central chiller plant + VAV AHUs with terminal reheat/VAV boxes Brief (stipulated) HIGH — precondition for AHU static-pressure reset, chilled-water reset, economizer optimization (§4.2b)
5 BAS/BMS protocol BACnet (protocol asserted; IP vs MS/TP unspecified) Brief (stipulated); IP/MS-TP split [UNVERIFIED] HIGH — gates §3.1 integration path and cost
6 US climate-zone bracket ASHRAE Climate Zone 4A (Mixed-Humid); representative city Baltimore, MD (DOE/OpenEI Zone-4A designation, T2) ANSI/ASHRAE Standard 169 climatic-zone definitions — current edition year [UNVERIFIED — 2013/2020/2021 conflicting; no authoritative 2026-current confirmation]; station-level design-day values [UNVERIFIED — requires named station] HIGH (R6)
7 APAC climate-zone bracket ASHRAE Climate Zone 1A/2A equivalent (Tropical/Hot-Humid, e.g., Singapore/SE Asia office stock); Singapore-Changi confirmed present in the ASHRAE 169 station DB, but the specific zone-letter (0A vs 1A) assignment is [UNVERIFIED — no primary source stated the letter] ASHRAE Standard 169 zone definitions; station design-day values [UNVERIFIED — requires named station] HIGH (R6)
8 Tariff stance (US) Commercial time-of-use or flat commercial rate; jurisdiction not named [UNVERIFIED] HIGH — directly scales §4 $ conversion and §6 payback; NOT yet bracketed (see §2.2, A-11)
9 Tariff stance (APAC) Commercial/industrial tariff, possible time-of-use peak-shaving incentive structure; jurisdiction not named [UNVERIFIED] HIGH — NOT yet bracketed (see §2.2, A-11)
10 Baseline energy intensity band (US) See §2.B EUI table ENERGY STAR Portfolio Manager / CBECS — see §2.B MEDIUM
11 Baseline energy intensity band (APAC) See §2.B EUI table See §2.B (BCA 2023, T2 single-source) MEDIUM
12 Baseline year concept No fixed calendar baseline year; "most recent 12 consecutive months of stable operation prior to ECM installation" per IPMVP convention IPMVP baseline-period convention (industry-practice consensus, T3); exact IPMVP Core Concepts 2022 section number [UNVERIFIED — primary text login-gated, not resolved] HIGH — feeds §5.2
13 Chiller plant nominal lifetime ~20–25 years (central chiller; sources disagree 20/25/31 yr by chiller sub-type) [T2 single-source range — primary-table confirmation pending] (ASHRAE Service Life and Maintenance Cost Database via hvac-eng.com) ASHRAE equipment-service-life data — specific table/edition [UNVERIFIED] LOW–MEDIUM — relevant to §6.3 "do nothing" baseline
14 AHU/VAV box nominal lifetime 20–25 years (AHU), 15–20 years (VAV box/terminal unit) [UNVERIFIED — no ASHRAE-specific median-year figure resolvable; AHU directional-only, VAV box NOT FOUND (searched 2026-07-07)] ASHRAE equipment-service-life data — specific table/edition [UNVERIFIED] LOW
15 BAS controller nominal lifetime 10–15 years (DDC controller hardware refresh cycle, shorter than mechanical equipment) [UNVERIFIED — no citable ASHRAE table resolvable; DDC controller life NOT FOUND (searched 2026-07-07)] MEDIUM — feeds §3.1 firmware-currency gate
16 EFLH (equivalent full-load hours) — cooling (A-12) [UNVERIFIED — requires climate-zone-specific EFLH source] (diverges sharply between the Zone 4A and Zone 1A/2A brackets) Named climate-zone EFLH source (e.g., ASHRAE climatic data / regional load study) — NOT FOUND (searched 2026-07-07: only generic EFLH methodology sources, no numeric comparison table) MEDIUM — sizes the §4.2b supervisory-optimization mechanisms and the annual $ savings magnitude

Bracket-selection justification (R6): The US bracket (ASHRAE Zone 4A, mixed-humid; representative city Baltimore, MD) and APAC bracket (ASHRAE Zone 1A/2A, tropical/hot-humid) are chosen because they represent materially different HVAC load profiles: Zone 4A carries a balanced heating+cooling load with meaningful economizer/free-cooling opportunity (favoring supervisory mechanisms in §4.2b that trade on outside-air enthalpy), whereas Zone 1A/2A is cooling-dominated with near-zero economizer hours (favoring chilled-water/condenser-water reset and demand-side/tariff mechanisms in §4.2c). This brackets a high-economizer-value case against a near-zero-economizer-value case — the two mechanisms that diverge most by climate. It is not a guarantee that all US or all APAC assets fall inside this bracket (a Zone 1A/2A US property, e.g., South Florida, or a temperate/high-altitude APAC property would sit outside it), and it does not bracket the tariff axis at all (A-11). Sensitivity note (required by R6): if the savings-mechanism ranking in §4.2 or the IPMVP option in §5.1 would flip for an asset within either named zone's tariff/climate sub-range (e.g., a Zone 4A asset with an unusually high electric-peak-demand tariff behaving like a demand-charge-dominated rather than an economizer-dominated case), the two-point bracket is inadequate and must be widened to a third or fourth climate/tariff point before the owner applies this framework's conclusions.

2.B Baseline EUI benchmark bands (industry benchmarking bands — NOT this archetype's measured EUI)

Region Building type EUI band (site) Source Notes
US Office (CBECS national median context) ~78 kBtu/sq ft/yr median site EUI [T2 single-source — primary-table confirmation pending] CBECS 2018 (EIA) via envigilance.com EUI Guide 2026 Attributed to EIA's 2018 CBECS by a secondary source; two attempts to verify against the EIA/ENERGY STAR primary tables failed (PDF-parse errors, not a content mismatch), and quick web summaries showed a noisier 65–80 kBtu/sqft range by exact metric definition — hence the caveat
APAC Office (representative — Singapore large-office stock) ~186 kWh/m²/yr average EUI (large offices; top-10% 216; medium offices 122) [T2 single-source — primary PDF not directly readable] BCA Building Energy Benchmarking Report 2023 (Singapore) Search-synthesized from the 2023 BCA report; direct PDF fetch returned 404 (stale path). Internally consistent with the reported historical trend (2014 median 218 → 2023 average 186 kWh/m²/yr). NABERS (Australia) not separately resolved

Explicit note: Both cells now carry a single-source industry band with a visible caveat, not a primary-confirmed number. The US figure is one T2 citation attributing CBECS 2018 (not independently confirmed against the EIA primary table); the APAC figure is search-synthesized from the BCA 2023 report (primary PDF not directly readable). Neither is upgraded to a settled benchmark — the caveat tags are the report discharging its evidentiary duty.


3. Technical Feasibility Gates

Why feasibility precedes economics (unnumbered preamble — §3.1/§3.2 are reserved for the readiness and point-coverage content the framework's prose references):

AI-HVAC optimization is a supervisory layer on top of an existing control substrate. Its value is conditional on the substrate, so the substrate is qualified first. This section decides GO / CONDITIONAL / NO-GO on technical and operational-readiness grounds before any economics, because a favorable savings estimate on an unreadable, un-writable, or operator-distrusted plant is a fiction. The four qualifying dimensions: (a) the substrate can be read at sufficient resolution (§3.1–3.2), (b) it can be written to safely under a human gate (§3.1, §6.4), (c) it has a trustworthy fault baseline (§3.3), and (d) it is run by an operator prepared to trust and sustain it (§3.5).

The architecture-relevant hinge in §3.2: sub-metering adequacy is the hinge to §5, and it is what derives the IPMVP option (R1) — it does not presume one. The point-coverage result flows forward and selects the M&V method; it is not a formality.

3.1 BMS/BAS Readiness Checklist

Readiness benchmarks: ASHRAE Guideline 13-2015 (Specifying Direct Digital Control Systems / BAS specification practice) and ASHRAE Guideline 36-2021 (High-Performance Sequences of Operation for HVAC Systems) — the reference standards against which sequence correctness and BAS specification adequacy are benchmarked.

Check Pass threshold This archetype's status
BACnet interoperability — object types exposed (AI/AO/BI/BO/AV/BV/Schedule/Trend-log) All required object types readable via BACnet/IP or BACnet MS/TP gateway [UNVERIFIED — requires site data]
Read/write permission model Supervisory layer has documented read access to all required points (§3.2) and gated write access to setpoint objects only, with a human-approval workflow [UNVERIFIED — requires site data]
Integration path BACnet/IP preferred (native IP-routable); BACnet MS/TP requires a router/gateway device — added integration-cost line in §6.1 [UNVERIFIED] — brief asserts "BACnet" without specifying IP vs MS/TP
Controller firmware currency Firmware within vendor-supported version window; no end-of-life controllers on critical points [UNVERIFIED — requires site data]
Spare CPU/network headroom Sufficient headroom for an additional BACnet client (the optimization layer) to poll without degrading existing BAS performance [UNVERIFIED — requires site data]
Trend-log capacity & retention ≥ the minimum historical window required by §3.2, retained on-controller or exported to a historian [UNVERIFIED — requires site data]
Point-naming hygiene / semantic-tagging readiness Points named/tagged such that they map to Brick or Haystack schema without a full manual re-tagging project [UNVERIFIED — requires site data]
Default posture Haystack + Brick export capability required as a condition of vendor selection (owner retains a normalized, exportable point database; vendor access is read-only against the owner's data layer) Policy statement, not a site finding

3.2 Required-Point Matrix

Point category Example points Tier Rationale
Central plant — chilled water Supply/return CHW temp, CHW flow, CHW ΔT, chiller kW, condenser-water supply/return temp Critical Chilled-water reset optimization (§4.2b) and Option B/C M&V
AHU supply-air Supply-air temp, supply-air static pressure, fan VFD speed/kW, mixed-air temp, OA damper position Critical AHU static-pressure reset and economizer optimization (§4.2b)
VAV terminal units Zone airflow (CFM), damper position, reheat valve position, zone temp setpoint vs actual Critical Zone-level comfort verification (§7 GATE 3) and load-based optimization
Outside-air conditions OA dry-bulb temp, OA relative humidity/enthalpy Critical Economizer logic and weather-normalized baseline model (§5.2)
Zone environmental Zone temp, zone CO₂ (if DCV present) Critical (temp); Desirable (CO₂) Comfort-band verification (ASHRAE 55-2023), demand-controlled-ventilation optimization
Electrical submeters Whole-building kW, HVAC-only kW (chiller plant + AHU fans + pumps split from lighting/plug loads) Critical for Option B; Desirable for Option C Sub-metering adequacy is the direct hinge to the IPMVP option decision (§5.1) — see note below
Schedule/override log BAS schedule objects, manual-override event log Desirable Feeds §3.5 operator-reversion monitoring and §7 GATE 4
Fault/alarm log BAS alarm history, economizer-fault flags, simultaneous-heat-cool flags Critical Feeds §3.3 fault-baseline establishment
Refrigerant/leak monitoring Refrigerant leak sensor status (if present) Optional Relevant only if chiller refrigerant transition (§6.3) is in scope

Sampling-rate / trend-history requirement (a criterion, not a finding): a defensible regression baseline under IPMVP Option C, or a defensible calibrated-simulation baseline under Option D, typically requires at minimum 12 months of interval data at 15-minute-or-finer resolution for the independent variables (energy, degree-days/OA conditions) to capture seasonal variation and weekday/weekend/holiday schedule effects. This 12-month / 15-minute figure is the criterion the owner should apply, not a verified property of this archetype. Actual availability of trend history here is [UNVERIFIED — requires site data].

Sub-metering adequacy note (hinge to §5, per R1): whether HVAC-only kW is separately sub-metered from whole-building kW is the single largest determinant of which IPMVP option is viable (§5.1's decision rule). This is a gate, not a resolved value — the option is derived in §5.1 from whichever sub-metering condition the site presents; at the archetype level with no site data it remains [UNVERIFIED].

3.3 AI-FDD Attribution Protocol (R5) — a measured attribution, not a clean split

The genuinely ambiguous question — how much credit does the AI layer get for fault correction versus one-time commissioning? — is resolved as a measurable protocol, not by fiat. Asserting "a fault fixed by commissioning is never an AI win" would under-count the AI; asserting the AI captures all fault savings would over-count it (the marketing failure mode). The protocol is symmetric:

  • One-time commissioning corrections — a fault found and fixed once (a stuck damper repaired, a schedule override cleared) → attributed to the non-AI baseline. This is value the building would capture from a competent retro-commissioning pass with or without an optimizer.
  • Sustained fault prevention / re-drift avoidance over the M&V period — the continuous AI-FDD layer keeping a fault from recurring where a manual pass would let it silently drift back → attributable to the continuous AI-FDD layer, and measured by fault-recurrence rate (baseline fault burden vs sustained post-deployment recurrence), never assumed.

The load-bearing requirement this places on §5: the M&V plan must make this attribution measurable — capturing baseline fault burden and tracking sustained post-deployment fault-recurrence, so the AI-FDD persistence credit is an observed quantity. The current fault burden is the first value source (economizer faults, simultaneous heat/cool, stuck dampers, sensor drift, schedule overrides), with ASHRAE Guideline 36-2021 sequences as the correctness reference.

FDD baseline — fault categories and attribution-measurement design:

Fault category Detection basis Attribution bucket (per protocol above) Measurement metric
Economizer faults (damper stuck, sensor fault, control-sequence fault) ASHRAE Guideline 36-2021 sequence-of-operation deviation One-time fix → non-AI baseline; sustained non-recurrence → AI-FDD Fault-recurrence rate (faults/month, pre- vs post-deployment, over the M&V period)
Simultaneous heating/cooling Guideline 36-2021 sequence check (heating and cooling valves open concurrently) Same split Same metric
Stuck/failed dampers or valves Position-feedback vs command deviation Same split Same metric
Sensor drift Cross-check against redundant/adjacent sensors or expected physical relationship (e.g., supply temp tracks setpoint within tolerance) Same split Same metric
Schedule overrides left in manual/permanent-override state BAS schedule-object audit vs intended operating schedule Same split; sustained AI-FDD credit only if the tool detects AND prevents recurrence, not merely a one-time cleanup Same metric; also feeds §3.5 operator-reversion signal

Typical fault prevalence (qualitative — precise figures deliberately not pinned): LBNL field-study research documents that HVAC faults are both common and persistent — economizer, airflow, thermostat, and sensor faults are each present in a substantial minority-to-majority of surveyed AHUs, and many fault types persist for a large fraction of the observed period (LBNL fault-detection-&-diagnostics research corpus, T2). The specific percentage figures are not pinned to a single study here because the available secondary synthesis carries a conflation risk across two distinct datasets (per the grounding dossier's own recommendation); a completed report that needs an exact prevalence figure must cite the named study by title/year directly. Where any such figure is needed elsewhere it is tagged [UNVERIFIED] or cited qualitatively as above.

3.4 Gate Decision Tree

The feasibility logic resolves to a three-way verdict with an explicit remediation path on the middle branch. (B-2) The verdict is a series-gate evaluation — the aggregate is the worst dimension, not a weighted average:

┌─────────────────────────────────────────────┐ │ §3.1 BMS/BAS readiness (read + write safe) │ │ §3.2 Point / data coverage (resolution) │ │ §3.3 FDD baseline trustworthy │ │ §3.5 Operator readiness (trust + sustain) │ └───────────────────────┬─────────────────────┘ │ series evaluation — verdict = WORST dimension (min across §3.1 / §3.2 / §3.3 / §3.5; no weighting) │ ┌───────────────────────────────────┼───────────────────────────────────┐ ▼ ▼ ▼ ┌──────┐ ┌──────────────┐ ┌───────┐ │ GO │ │ CONDITIONAL │ │ NO-GO │ └──┬───┘ └──────┬───────┘ └───┬───┘ │ │ │ proceed to §4/§5 named remediation prerequisites halt; remediation-only economics + M&V design MUST clear before optimization: path (e.g., controls • point coverage fails → refresh) — re-enter gate install submeters / only after remediation. extend trend logs • operator distrust/untrained → training + change-management • FDD baseline unestablished → retro-commissioning first

The decision rule: any single dimension failing hard forces at most CONDITIONAL (with its specific remediation named), and a dimension that cannot be remediated within the project envelope forces NO-GO. The tree is not a weighted average that lets a strong point-coverage score paper over a distrustful operator — each dimension is a gate in series (min rule).

Sub-gate thresholds (series/min rule, no weighting scheme):

Sub-gate GO threshold CONDITIONAL threshold NO-GO threshold
§3.1 BMS/BAS readiness All critical checks pass 1–2 critical checks fail with a defined remediation (e.g., firmware upgrade, gateway install) [ILLUSTRATIVE DEFAULT — not a sourced/validated threshold; owner may recalibrate] ≥3 critical checks fail or no BACnet write-access path exists at all [ILLUSTRATIVE DEFAULT]
§3.2 Point coverage ≥90% of Critical-tier points present and trending at required resolution [ILLUSTRATIVE DEFAULT] 60–89% of Critical-tier points present; remediation = submeter/sensor gap-fill (feeds §6.1) [ILLUSTRATIVE DEFAULT] <60% of Critical-tier points present [ILLUSTRATIVE DEFAULT]
§3.3 FDD baseline Fault log/history exists and is queryable ≥6 months [ILLUSTRATIVE DEFAULT] Fault log exists but <6 months or incomplete [ILLUSTRATIVE DEFAULT] No fault/alarm logging capability at all
§3.5 Operator readiness Facilities/ops team engaged, trained, and change-management plan in place Team identified but untrained/no plan — remediation = training program No identified in-house operator or explicit refusal to engage with automated writes

(B-2/B-3) Note on combination: the four sub-gates combine by the min/series rule — the overall verdict is the worst of the four, never a weighted or averaged score. No numeric weighting scheme exists or is needed; there is no orphan weight column. The GO/CONDITIONAL/NO-GO percentages and count-bands above are [ILLUSTRATIVE DEFAULT] values the owner recalibrates against their optimization vendor's actual point-list and their own risk tolerance — they are ledger rows 29–30 (§8.A), not sourced/validated thresholds.

3.5 Operator / Change-Management Readiness (R3) — feasibility and persistence

Operator readiness is a first-class gate dimension, not a soft consideration: the human-gate doctrine requires a capable human-in-the-loop, so the feasibility question is not merely "can the plant be optimized?" but "does the capable, prepared human the doctrine mandates actually exist?" An un-trained or distrustful operator is a CONDITIONAL flag (remediation = training + trust-calibration + change-management), never an assumed-adequate given. The persistence dimension — a reversion-monitoring check carried into continuous M&V (are operators overriding/reverting the optimizer and silently erasing savings?) — connects a feasibility test to the realized-savings risk in §4 and §6.4. Operator capability is [UNVERIFIED] and tested by this sub-gate; reversion/persistence-decay figures are sourced or [UNVERIFIED].

Operator / change-management readiness checklist:

Item Pass criterion Status
Named facilities/operations owner for the BAS An identified individual/team with BAS access and accountability [UNVERIFIED — requires site data]
Training plan for the optimization layer Documented onboarding covering what the tool changes, why, and how to review/approve/override recommendations [UNVERIFIED]
Trust-calibration approach A defined initial period (e.g., recommend-only/advisory mode before any autonomous write) to build operator confidence Structural recommendation, not a site finding
Reversion-monitoring capability BAS or supervisory-layer logging captures manual overrides/reversions of optimizer-set setpoints, distinguishable from the optimizer's own changes [UNVERIFIED — requires site data]; direct input to §7 GATE 4

(Out of scope: vendor-specific integration walkthroughs; procurement of the FDD tool — that is the §7 playbook.)


4. Expected Savings Range — Denominator & Uncertainty Framing (R4)

4.1 Denominator discipline — every savings % must name its denominator inline

The most common way an HVAC-savings headline becomes dishonest is a denominator switch. This section fixes the denominator as HVAC / energy OpEx and states the conversion chain explicitly:

site kWh → HVAC share of kWh → $ at the jurisdiction's tariff.

A saving is a percentage of the HVAC energy cost that flows through that chain — never a percentage of total building OpEx, and never converted to asset value via 1/CapRate as if it were a forecast.

(B-4) The inflation guard, stated correctly. A given absolute $ saving is a large percentage of the small HVAC-energy-OpEx denominator and a small percentage of the much larger total-OpEx denominator. The dishonesty to guard against is therefore not "quoting against total OpEx inflates the number" (that shrinks it); the real denominator-switch inflation modes are the reverse:

  1. Basis-implication switch — a percentage correctly measured on the small HVAC-only energy base, then presented so the reader applies it to the total energy bill or total-OpEx $ base. The percentage looks the same but the implied dollars are inflated several-fold.
  2. Value-conversion switch — a 1/CapRate conversion of an OpEx saving into "asset value created," presented as a forecast rather than an illustrative arithmetic identity.

Rule to print: every savings percentage must name its denominator inline (e.g., "N% of HVAC energy OpEx," never a bare "N% savings"). A single neutral guard names this so the reader can detect a switch. The section is deliberately not organized around any specific marketing figure (R4).

Denominator conversion chain (formula):

``` Site total kWh (annual, metered or estimated) × HVAC share of site kWh [US office end-use, CBECS 2018 (EIA): space heating ~30% + ventilation ~20% are directly reported; the cooling % line is NOT separately broken out in the fetched EIA office profile, so a single combined "HVAC share" figure is UNVERIFIED — the heating+ventilation ≥50% floor UNDERSTATES total HVAC share] = HVAC-attributable kWh (annual)

HVAC-attributable kWh (annual) × claimed savings % (from §4.2 decomposition, per mechanism) = HVAC energy savings (kWh/yr)

HVAC energy savings (kWh/yr) × applicable tariff rate ($/kWh, named jurisdiction — §2.A items 8–9) = HVAC energy savings ($/yr) ```

(B-4) Illustrative inflation-guard structure (symbolic, no fabricated inputs, written grammatically): let HVAC be a fraction h of total building energy (h must be sourced, not assumed — the CBECS 2018 office breakdown confirms space-heating ~30% + ventilation ~20%, T1, but not a complete HVAC-inclusive-of-cooling total). A saving of S dollars is correctly expressed as S / (HVAC energy OpEx) — a large percentage because the denominator is small. If the same S dollars is instead expressed as S / (total OpEx), the percentage is smaller by roughly the factor h. The misleading move is to compute the large HVAC-basis percentage and then let the reader multiply it against the total energy or OpEx dollar base — inflating the implied dollars by roughly 1/h. → the fix is the inline-denominator rule above; the two bases are never mixed. (The HVAC-share source is CBECS 2018 for the US partial breakdown; the equivalent APAC end-use split and the tariff-band $ conversion remain jurisdiction-named or [UNVERIFIED].)

4.2 Savings-stacking logic and decomposition

Savings must be attributed by source, not summed blindly, or independent mechanisms get double-counted. Three sources whose interaction and jurisdiction-sensitivity differ:

  • (a) FDD / commissioning corrections — split per the §3.3 attribution protocol: one-time correction → non-AI baseline; sustained recurrence-avoidance → AI-FDD, each measured, not assumed (R5).
  • (b) Supervisory optimization — setpoint reset, chilled-water / condenser-water reset, AHU static-pressure reset, economizer optimization, load prediction. The core continuous-optimization value.
  • (c) Demand-side / tariff optimization — peak-shaving, load-shifting — jurisdiction-dependent (its value exists only where the tariff rewards it; a flat-tariff APAC feed structure and a wholesale-market US tariff produce very different (c) contributions).

Stacking rule: where mechanisms overlap (e.g., an economizer fix that is both an FDD correction and an optimization action), the overlap is resolved to one source, not counted in both.

Savings-decomposition table:

Mechanism Attribution bucket (per §3.3) Typical % range (of HVAC/energy OpEx) Source Applicability caveat US vs APAC divergence
(a) FDD / commissioning — one-time corrections Non-AI baseline ~16% median whole-building savings for existing-building commissioning (EBCx), ~1.1-yr median simple payback [T2 — LBNL primary PDF not directly readable] Mills (2011), LBNL "Building Commissioning: A Golden Opportunity…" Whole-building EBCx figure, not HVAC-only or AI-specific; one-time, realized once, does not recur as an annual saving unless faults would otherwise re-occur Not climate-dependent per se; magnitude depends on baseline fault burden (site-specific)
(a) Sustained fault-prevention / re-drift avoidance AI-FDD (continuous), via fault-recurrence rate [UNVERIFIED — requires a named source] Candidate: continuous-commissioning / FDD persistence literature Only counted where measured recurrence-avoidance exceeds the pre-deployment baseline recurrence rate (§3.3) Not climate-dependent per se
(b) Supervisory optimization — CHW/condenser-water reset, AHU static-pressure reset, economizer optimization, load prediction Supervisory AI layer Setpoint-adjustment measures ~8%, min-VAV-airflow reduction ~7%, aggregate theoretical maximum across all tuned-controls measures ~29% [T1 — nationwide, ALL commercial building types, NOT office-specific] (PNNL-25985, DOE BTO, 2017). Field-demonstrated MPC upper bound ~40% is a single-site, favorable-condition result — NOT a typical expectation [T1] (LBNL MPC field demo, Northern California, shoulder season) PNNL-25985 (DOE Building Technologies Office, 2017); LBNL MPC field demonstration Economizer value materially reduced or near-zero in a cooling-dominated climate with minimal free-cooling hours; the ~29% and ~40% figures are ceilings, not central estimates US Zone 4A: meaningful economizer-hours value. APAC Zone 1A/2A: economizer value approaches zero; CHW/condenser-water reset remains applicable in both
(c) Demand-side / tariff optimization (peak-shaving, load-shifting) Supervisory AI layer, jurisdiction-dependent [UNVERIFIED — entirely tariff-structure-dependent] Candidate: utility demand-response program literature (jurisdiction-specific) Only applicable where a demand charge, TOU rate, or DR incentive exists; value is zero under a flat-rate tariff with no demand charge Highly jurisdiction-specific in both regions — depends on the named utility/tariff (§2.A items 8–9), not on US-vs-APAC as a category

Grounding note on the (a) and (b) figures: the mechanism ranges now carry named DOE/LBNL sources where resolvable, but every substituted figure is presented with its scope caveat — the Mills 16% is a whole-building EBCx median (not HVAC-only or AI-attributable), and the PNNL 8/7/29% are nationwide, all-building-type potentials (the report explicitly does not break out office). The ~40% MPC result is an upper-bound single-site field demonstration under favorable conditions, not a typical expectation and must never be cited as such (R4). The (a)-sustained and (c) rows remain [UNVERIFIED] — no resolvable named citation. A completed report MUST retain each caveat or replace with an office-specific dated citation.

4.3 Honest range statement (R4) — lead with the mechanism-anchored range

The estimate leads with the conservative, mechanism-decomposed range built from §4.2's independent sources (DOE / LBNL / IEA / peer-reviewed). Only then, as a brief demoted caveat, is the marketing genre addressed: "marketing 'up-to' figures conflate best-case single-mechanism results with whole-system realized savings and are not used as the estimate." The marketing rebuttal is a footnote to guard against, not the organizing frame (R4). The estimate's status is plain: realized savings are [UNVERIFIED] until M&V (§5) confirms them against measurement noise — and note that even the sourced §4.2 mechanism figures are nationwide/whole-building/single-site scopes, not building-specific realized savings.

4.4 The two conditions that make a saving real and net-positive

A favorable savings number must clear two independent tests before it counts:

  1. Real (exceeds noise). A claimed saving is only real if it exceeds the M&V model's uncertainty band (FSU) — see §5.3's CV(RMSE)/FSU criteria. A saving smaller than the measurement uncertainty is unprovable and is not claimed. The check: Claimed savings ($ or kWh) is PROVABLE only if Claimed savings > FSU-derived $ uncertainty band (§5.3).
  2. (R2/R3) Net-positive on the value case. A saving is only net-positive if it does not degrade occupant comfort (tenant-churn / lease-retention risk on NOI) and does persist (survives operator reversion). See §7 GATE 3 (comfort acceptance) and §6.4 / §3.5 (persistence risk).

These two tests are why the executive verdict (§1) is a conjunction: a savings percentage alone, however large, satisfies neither by itself.

(Out of scope: carbon savings — belongs in ESG framing if included, and carbon % must never be conflated with energy %; energy savings performance contract (ESPC / ESCO) structures — §7.)


5. IPMVP Option Selection + M&V Governance

5.1 Option selection reasoning (R1) — the option is derived, never presumed

The four IPMVP options are evaluated on equal footing, in IPMVP-canonical order, with no pre-loaded "primary" example (R1). The output is a decision rule that selects the option from the data, not a settled answer — because the archetype has no data, the option is [UNVERIFIED] until §3.2 resolves the point coverage. (Mechanics anchored to IPMVP Core Concepts 2022; the exact option-selection section number is [UNVERIFIED — NOT FOUND: the 2022 revision is confirmed to include option-selection clarifications, but no source gave the specific section number; primary text login-gated (searched 2026-07-07)].)

Option mechanics (equal-footing, no option presumed):

Option Mechanism Data prerequisite Relative cost Fit trigger
A — Retrofit isolation, key-parameter measurement + stipulated values Measure only the key parameter(s) that change (run-hours, key operating point); stipulate the rest from spec/estimate Lowest — spot or short-term monitoring of 1–2 parameters Lowest Where only key parameters are practically measurable and stipulating the rest is defensible; weakest against un-stipulated interactive effects
B — Retrofit isolation, all-parameter measurement All parameters affecting the ECM's energy use are measured, isolated from the rest of the building Requires ECM-specific sub-metering Medium Where isolated ECM sub-metering exists (e.g., chiller-plant kW submetered separately from whole-building load); tighter attribution
C — Whole-facility, utility-meter regression Whole-building utility data regressed against an independent-variable set (degree-days, occupancy) pre- vs post-retrofit Requires clean whole-building interval utility data over a sufficient baseline + reporting period Low–Medium (uses existing billing/interval data) Where whole-building interval data is clean AND supervisory/systemwide measures dominate scope such that the whole-meter signal is attributable
D — Calibrated simulation An energy model is calibrated to measured baseline data, then used to estimate savings by comparing calibrated-baseline vs post-retrofit simulated performance Requires a building energy model AND calibration data; useful when metered history is sparse Highest Where baseline metered history is too sparse/short for a defensible regression, but enough is known to build and calibrate a model

Decision rule (formal, with the terminal branch added per A-7):

IF whole-building interval data is clean AND supervisory/systemwide measures dominate scope → Option C ELSE IF isolated-ECM sub-metering exists → Option B ELSE IF baseline metered history is too sparse for a defensible regression → Option D ELSE IF only key parameters are practically measurable → Option A ELSE (none of the four hold, or the conditions conflict) → M&V is NOT yet feasible; route back to §3.2 remediation (submetering / trend-log extension) and re-derive; escalate to the M&V referee if remediation is out of the project envelope.

(A-7) Precedence is deliberate — C > B > D > A — because whole-facility regression on clean interval data is the most defensible and lowest-marginal-cost method when supervisory measures dominate (the typical AI-HVAC scope); isolated sub-metering (B) is next-most-rigorous where it exists; calibrated simulation (D) is used only when data is too thin for statistics; key-parameter+stipulation (A) is the fallback of last resort. Option-D caveat: calibration itself requires some measured baseline data — utility bills at minimum — so "sparse" does not mean "none"; if truly no baseline data exists, remediation (metering + a baseline monitoring period) precedes any option.

Applied to this archetype: sub-metering adequacy (§3.2) and baseline-history length (§2.A item 12) are both [UNVERIFIED — requires site data]; therefore no option can be selected today — the option is [UNVERIFIED] pending the §3.2 data gate (R1). No option is presented as the "obvious default."

5.2 Baseline model specification (structural — no fitted coefficients exist) [B3]

B3: an M&V claim without a baseline-model citation is a violation. The baseline model is specified here; the numeric acceptance thresholds are in §5.3 (both B3/B5-blocking).

Model element Specification
Independent variables (candidates) Heating/cooling degree-days (HDD/CDD), occupancy proxy (badge-swipe count or schedule flag), a utilization proxy if applicable (not typically relevant to a pure office archetype)
Regression form (candidates, selected once data exists) Change-point regression (3- or 5-parameter heating/cooling change-point model) vs multi-variable linear regression vs simple single-variable (HDD/CDD-only) degree-day model
Weather normalization method Degree-day method referenced to a named weather station representative of the site — resolved to ASHRAE Climatic Design Database station data; the specific station is [UNVERIFIED — no site named]
Baseline period Minimum 12 consecutive months of stable pre-ECM operation (per IPMVP baseline-period convention, T3 industry-practice consensus; exact IPMVP Core Concepts 2022 section citation [UNVERIFIED — primary text login-gated (searched 2026-07-07); 12-month convention safe to state as practice, not as a pinned IPMVP-2022 cite])
HDD/CDD base temperature To be fit to the building's actual balance-point temperature during calibration (not assumed a priori at 65°F/18°C without site-specific validation)

5.3 Acceptance statistics — threshold table [B5]

B5: a savings claim without a CV(RMSE)/FSU uncertainty bound is a violation. The numeric thresholds below are resolved to ASHRAE Guideline 14 (values consistent across the 2002/2014 editions per multiple independent secondary sources reproducing the G14 calibration-criteria table; whether the 2023 edition revised them was not directly confirmable from a 2023-edition source — see caveat).

Statistic Purpose Threshold Source
CV(RMSE) — Coefficient of Variation of the Root Mean Squared Error How well the baseline model fits historical data (goodness of fit) ≤ 15% for monthly-interval models; ≤ 30% for hourly-interval models (ASHRAE Guideline 14 via OSTI/LBNL "Suitability of ASHRAE Guideline 14 Metrics for Calibration" + reproduced G14 criteria tables, T2) ASHRAE Guideline 14 (2002/2014 values; 2023-edition revision [UNVERIFIED])
NMBE — Normalized Mean Bias Error Systematic over/under-prediction bias of the baseline model |NMBE| ≤ 5% for monthly-interval models; ≤ 10% for hourly-interval models (same G14 calibration-criteria table, T2) ASHRAE Guideline 14 (2002/2014 values; 2023-edition revision [UNVERIFIED])
Goodness-of-fit companion (variance explained) Expectation band [UNVERIFIED — Guideline 14 does not always set a hard R² threshold independent of CV(RMSE)/NMBE; a specific value is not resolvable within this envelope] ASHRAE Guideline 14-2023 (companion diagnostic)
FSU — Fractional Savings Uncertainty Translates model uncertainty into an uncertainty band on the savings estimate itself, at a stated confidence interval Uncertainty in reported annual savings ≤ 50% of the reported savings, at a 68% confidence level (FSU ≤ 0.50 at 1 s.d.) [T2 — search-summarized quote of the primary G14 text, not directly read; FEMP M&V Guidelines v4.0 do NOT independently specify this CI] (ASHRAE Guideline 14 via TAMU thesis + LBNL Granderson uncertainty-methods corroboration) ASHRAE Guideline 14 (2002/2014 basis)

Rejection rule: any savings claim whose achieved CV(RMSE)/NMBE fall outside the resolved Guideline 14 thresholds (CV(RMSE) ≤ 15% monthly / ≤ 30% hourly; |NMBE| ≤ 5% monthly / ≤ 10% hourly), or whose FSU-derived $ uncertainty band exceeds the claimed savings amount (FSU ≤ 0.50 at 68% CI), is rejected as unverifiable and reported as such — not published as a "soft" or "directional" positive.

FSU → $ translation (formula, no fabricated inputs): $ uncertainty band = FSU (as a fraction, at stated CI) × claimed $ savings (from §4 decomposition) This ties directly to §4.4's noise-threshold check: a claimed savings figure is provable only if it exceeds this computed $ uncertainty band.

5.4 M&V governance property (R7) — a required property, not a presumed referee

The governance property required, deliberately without naming who fills the role:

"M&V is computed and audited by a party with no financial stake in the measured savings outcome."

Independence is what makes a savings number trustworthy, and it is a governance attribute that can be required and verified regardless of which party supplies it. Two rails follow:

  • Conflict-of-interest disclosure (R7). "If the M&V party also supplies, integrates, or endorses the optimization layer, that overlap is itself a conflict of interest that must be disclosed and mitigated." A supplier grading its own savings is a structural CoI whether or not the numbers are honest.
  • Referee identity is a positioning matter, not methodology. If any specific party's referee role — including AISB's — is in scope at all, it belongs in a clearly-labeled positioning note, never inside this methodology specification. No specific party (including AISB) is asserted as "independent M&V referee" inside this methodology, and never without the supplier/referee-overlap disclosure (R7).

The governance design carries a requirement back to §3.3: the M&V design must make the AI-FDD attribution measurable — baseline fault burden vs sustained post-deployment fault-recurrence rate — so the persistence credit is audited, not asserted.

Governance property specification:

Governance element Requirement Status
M&V computing/auditing party No financial stake in the measured savings outcome (not paid on a percentage-of-savings basis, and not the same entity that supplied/sold/integrated the optimization layer, unless the overlap is explicitly disclosed and mitigated) Property to require — no specific party (incl. AISB) presumed to fill this role (R7)
Reporting cadence To be specified per project (e.g., monthly interim, annual formal report) — not fixed by this framework [UNVERIFIED — project-specific]
Baseline-adjustment (non-routine events) protocol Documented process for adjusting the baseline model on a non-routine event (tenant fit-out changing occupied area, major equipment replacement outside ECM scope) Structural requirement, not yet instantiated for this archetype
Conflict-of-interest disclosure If the M&V party also supplies/integrates/endorses the optimization layer, that overlap must be disclosed in the M&V plan and mitigated (e.g., independent third-party spot-audit of a sample of reporting periods) Mandatory caveat (R7)

(Out of scope: actual regression output / achieved CV(RMSE) for this building — no data, [UNVERIFIED]; measurement-hardware procurement — §7; any assertion of a specific party's commercial role in the retrofit.)


6. CapEx / NPV Framing & Risk Logic

Illustrative only — NOT investment advice. All figures below are cost-category placeholders, not vendor quotes.

6.1 Financial framing — illustrative, not investment advice

Every financial exhibit carries the inline disclaimer: illustrative on archetype ranges, not investment advice; a live decision re-runs it with real quotes and a real discount rate. The framing logic:

  • Simple payback = CapEx range / annual HVAC-energy savings range (from §4, on the correct HVAC/energy-OpEx denominator — §4.1's denominator discipline flows through so payback cannot be inflated by a denominator switch).
  • NPV / IRR at a stated discount rate — and the discount-rate governance is load-bearing: for a live >$100K decision, the discount rate must come from the owner's financial-analysis function (B4). For this illustrative archetype the rate is a clearly-labeled assumption with a note that a live case triggers that pull. Framing a live >$100K decision without it is a violation (B4).
  • Sensitivity is what makes the uncertainty legible — the sensitivity table swings ≥4 variables (savings %, CapEx, tariff/energy price, discount rate) at ±20% so the reader sees how fragile the case is. Monte Carlo is noted as the recommended tool if a live case exceeds ~$1M [ILLUSTRATIVE DEFAULT — not a sourced/validated threshold; owner may recalibrate] (ledger row 32).

CapEx cost-breakdown structure:

Cost category Component Range US vs APAC divergence
Supervisory software / licensing Optimization-layer software license (subscription or perpetual) [UNVERIFIED — vendor-quote-dependent, no generic industry figure sourced within this envelope] Licensing typically USD-denominated globally; no structural regional divergence beyond FX
Integration & gateway BACnet/IP-to-cloud gateway hardware, MS/TP-to-IP router if needed (per §3.1), integration labor [UNVERIFIED] Integrator labor rates diverge materially by region (US commercial-controls labor rate vs APAC market rate) — direction/magnitude [UNVERIFIED]
Submetering / sensor gap-fill Additional kW submeters, temp/CO₂ sensors, flow meters per §3.2 point-matrix gaps [UNVERIFIED — depends entirely on the §3.2 gap-fill scope] Hardware cost is roughly global-market; installation labor diverges by region
Commissioning / FDD remediation Cost to fix faults identified in §3.3 (one-time commissioning bucket) [UNVERIFIED — depends on fault burden found] Labor-rate divergence as above
M&V setup Baseline model development, meter data acquisition/QA, initial M&V plan authorship (§5) [UNVERIFIED]
Operator training / change-management Facilities/ops training program (§3.5) [UNVERIFIED]
Contingency Standard project contingency line Commonly 10–20% of subtotal in capital-project practice [UNVERIFIED — no specific cited standard within this envelope; presented as common practice, not a sourced figure]

6.2 Financial framing — formulas + sensitivity table

Simple payback: Simple payback (years) = CapEx range (§6.1) / Annual HVAC-energy $ savings (§4, correct denominator)

NPV (illustrative, discount rate as an assumption): NPV = Σ [ (Annual HVAC-energy $ savings_t − O&M delta_t) / (1 + discount_rate)^t ] − CapEx (t=0) Discount rate: for this illustrative archetype, an assumption (e.g., a placeholder in the 6–10% range commonly used in commercial-real-estate capital-project screening) — [UNVERIFIED — no specific rate sourced]. Per B4: a live decision above $100K CapEx must pull the discount rate from the owner's financial-analysis function, not assume one.

Sensitivity table (≥4 variables at ±20%, structural placeholder — no populated dollar values because no baseline CapEx/savings figures exist for this archetype):

Variable −20% Base (illustrative, [UNVERIFIED]) +20% Payback/NPV swing
Savings % (§4) Lower savings → longer payback [UNVERIFIED] Higher savings → shorter payback High sensitivity
CapEx (§6.1) Lower CapEx → shorter payback [UNVERIFIED] Higher CapEx → longer payback High sensitivity
Tariff / energy price (§2.A items 8–9) Lower price → less $ savings → longer payback [UNVERIFIED] Higher price → more $ savings → shorter payback High sensitivity, highly jurisdiction-dependent
Discount rate (assumption above) Lower rate → higher NPV [UNVERIFIED] Higher rate → lower NPV Moderate on NPV; does not affect simple payback

Monte Carlo note: recommended as the analytical tool of choice if a live case's CapEx exceeds approximately ~$1M [ILLUSTRATIVE DEFAULT — not a sourced threshold; owner may recalibrate], given the compounding of the four uncertain variables; a methodological recommendation, not a computed result.

6.3 Mandatory financial triggers (dual-jurisdiction — B6)

(B-6) The refrigerant schedule and code trigger are region-sensitive values bracketed for both jurisdictions, so the honest "do nothing" baseline exists for each:

Trigger Jurisdiction Detail
AIM Act refrigerant phase-down US Applies if the chiller plant uses a refrigerant subject to the AIM Act HFC phase-down schedule. As of 2026 the phasedown sits in the 2024–2028 step, capped at 60% of the established baseline (steps to 30% for 2029–2033, 15% for 2036+) [T1] (US EPA, "Frequent Questions on the Phasedown of HFCs"). The archetype's specific refrigerant identity and its GWP figure remain [UNVERIFIED — requires the actual refrigerant charge to be named on this archetype and resolved to the AIM Act HFC list; not to be emitted from memory]
Kigali-Amendment HFC controls as adopted locally APAC Refrigerant phase-down under the Kigali Amendment as adopted in the named APAC jurisdiction. For Singapore specifically: from Oct 2022, NEA banned new water-cooled chillers (≥1,055 kW) using refrigerants above a GWP threshold of 15; broader proposed rules (new HFC equipment above GWP 150, plus mandatory recovery for GWP >15 at decommissioning) are slated to take effect 1 April 2027 with a one-year transition to 31 March 2028 [T2 — law-firm secondary summaries of NEA circulars, primary PDF not directly read] (Singapore NEA circulars via Lexology / Rajah & Tann). Archetype refrigerant identity + applicable schedule [UNVERIFIED — requires named jurisdiction + refrigerant]
Energy-code minimum-efficiency mandate US ASHRAE 90.1-2022 / adopted local code may force capital action (minimum-efficiency equipment replacement) independent of the AI-HVAC decision, changing the honest "do nothing" baseline. Specific triggering section [UNVERIFIED — requires the named jurisdiction's adopted code edition]
Energy-code minimum-efficiency mandate APAC APAC-bracket minimum-efficiency / energy-code capital-action trigger (e.g., SG SS 553 / BCA Green Mark minimum requirements or the named local code) [UNVERIFIED — requires named jurisdiction's adopted edition]

Refrigerant GWP reference values (AR4 100-yr basis, the basis the AIM Act itself specifies) — a reference table, NOT an assertion about this archetype's charge: R-134a GWP 1,430 · R-410A GWP 2,088 · R-513A GWP 630 · R-1233zd(E) GWP 1 [T2 single-source — R-134a/R-410A are extremely standard AR4 values with high convergence; R-513A/R-1233zd(E) from search-summary only, recommend independent spot-check against an EPA SNAP/GWP table before final publication] (industry technical references; AR4-basis confirmation from the EPA HFC-allowances page, T1). These values apply if and when the archetype's actual refrigerant is named; the archetype's own refrigerant remains [UNVERIFIED] per the table above.

6.4 Risk logic — the risks that can void the case

The risk register is organized around the four risks that can void an otherwise-favorable case:

  • Vendor lock-in (load-bearing). The mitigation is structural, not contractual: open-ontology data ownership — Brick/Haystack export, an owner-held normalized point DB, read-only vendor access. If the owner retains the normalized point database and the vendor only reads it, the optimization layer becomes swappable, which is what breaks lock-in. Ties to the §3.1 readiness requirement (export capability) — lock-in defense is designed in at feasibility time, not bolted on later.
  • Cybersecurity. The OT/BAS attack surface is real; the posture is network segmentation, no direct internet exposure of controllers, disciplined credential management, and a "data never leaves the building" default, anchored to ISA/IEC 62443. For a BAS/OT deployment the most directly applicable parts are IEC 62443-4-2 (technical security requirements for IACS components) and IEC 62443-2-1 (establishing a cybersecurity management program) [T2 — vendor/technical-reference summaries; IEC 62443 itself paywalled; the series is a layered framework, not a single-document standard, so multiple parts apply by layer]. A supervisory layer that reads/writes controls widens the attack surface, so the security posture is a precondition of enabling writes, not an afterthought.
  • Occupant comfort guardrails — the human gate. Auto-BMS-write requires a human gate: the optimizer proposes, and a human/occupant override disposes. Comfort bounds (temperature / humidity / CO₂ per ASHRAE 55-2023 / local) are hard constraints the optimizer cannot violate. Autonomy compresses the operator's workflow; it never removes the operator/occupant override. (R2) Beyond the control bound, comfort degradation is a value-case downside (tenant churn / lease-retention risk on NOI) — so a comfort failure is both a control violation and a financial loss, which is why it can void the case even when energy savings are positive.
  • (R3) Savings persistence / operator reversion. The risk that realized §4 savings decay because operators distrust and override the optimizer — a documented persistence-failure mode. Mitigation: operator training / trust-calibration (§3.5) plus reversion-monitoring in continuous M&V (§7 GATE 4). An optimizer that is silently overridden produces on-paper savings that never reach the meter, so persistence is monitored as an ongoing measured quantity, not assumed at commissioning.

(B-5 / B1) Life-safety write-scope exclusion + licensed-PE statement (discharges declared check B1): The optimizer's write scope categorically excludes fire/life-safety sequences, smoke-control modes, and any point whose modification is life-safety-adjacent. Any proposed change touching such systems requires review and sign-off by a licensed professional engineer (or the jurisdiction's equivalent) in addition to the standing human gate. This scope statement is restated at every write-touching gate in §7.

Risk register:

Risk Likelihood Impact Mitigation
Vendor lock-in Medium (structural in any proprietary supervisory-control deployment) High (switching cost, data-hostage risk) Open-ontology data ownership: Brick/Haystack export required (§3.1 default posture), owner-held normalized point DB, vendor granted read-only access to the owner's data layer
Cybersecurity (OT/BAS attack surface) Medium (BAS/OT is a documented attack-surface category) High (life-safety-adjacent systems; building-wide disruption potential) ISA/IEC 62443 reference framework (esp. -4-2 component technical requirements + -2-1 security program, T2); OT network segmented from IT/corporate; no direct internet exposure of controllers; credential management/rotation; "data never leaves the building" posture (on-prem or controlled, audited data path)
Occupant comfort guardrails Medium Medium–High (tenant churn / lease-retention risk on NOI, per R2) Comfort bounds (temp, humidity, CO₂) set per ASHRAE 55-2023 and local code as hard constraints the optimizer cannot violate; auto-BMS-write requires a human gate — the layer proposes, a human operator approves, and an occupant-comfort veto function can block any setpoint change on comfort grounds; autonomy compresses the workflow, it never removes the human/occupant override
Savings persistence / operator reversion (R3) Medium–High (documented persistence-failure mode in supervisory-control deployments) High (can silently erase all realized §4 savings over time) Operator training / trust-calibration (§3.5) plus reversion-monitoring instrumented into continuous M&V (§7 GATE 4) — tracking the rate at which operators manually override or revert optimizer-set values
Life-safety-adjacent control modification N/A (excluded by scope) Critical if breached Write scope categorically excludes life-safety sequences; any life-safety-adjacent change requires a licensed-PE sign-off in addition to the human gate (B1)

Every financial exhibit in §6 carries this disclaimer inline: figures are illustrative modeling constructs for a representative archetype, not investment advice, not a specific-property projection, and not a guarantee of any realized return.

(Out of scope: actual vendor quotes; a firm go/no-go NPV verdict; detailed cyber-penetration-testing procedure.)


7. Implementation Playbook with Decision Gates

7.1 The gated sequence

The playbook is a staged path where each gate can halt the project before further spend — a fail-fast structure that spends the least capital before the riskiest unknowns are resolved. Each gate has entry criteria, a pass/fail threshold referencing §3/§5 numbers (no new thresholds are invented here), and a defined halt/rollback action on fail.

PHASE 1 PHASE 2 PHASE 3 PHASE 4 Readiness → Baseline + FDD → Pilot / partial → Full deployment assessment (establish §5 deployment + continuous M&V (executes §3 gates, baseline; quantify (bounded scope, incl. §3.5 operator §3.3 fault burden) human-gated writes) readiness) │ │ │ │ ┌──▼──┐ ┌──▼──┐ ┌──▼──┐ ┌──▼──┐ │GATE1│ │GATE2│ │GATE3│ │GATE4│ └──┬──┘ └──┬──┘ └──┬──┘ └──┬──┘ technical + operator baseline model MEASURED pilot savings ongoing verification GO / CONDITIONAL acceptable (CV(RMSE) clear FSU noise band + baseline re-adjustment / NO-GO met) AND fault- AND occupant comfort / + operator reversion- (series/min rule, corrected savings tenant-satisfaction monitoring (R3) §3.4) alone sufficient? metric within band (R2) + sustained AI-FDD │ │ │ fault-recurrence fail → remediation- fail → stop or fail (energy saved BUT tracking (§3.3) only path (§3.4) remediate baseline comfort complaints) → │ does NOT pass; halt fail → investigate reversion / re-tune; persistence at risk

The gate reasoning specific to this analysis:

  • GATE 1 operationalizes the §3.4 decision tree, including operator readiness, and applies the series/min rule (B-2) — a technically-ready plant with a distrustful operator is CONDITIONAL, not GO. Life-safety write-scope exclusion (§6.4, B1) applies from this gate onward.
  • GATE 2 carries a distinctive test: is the fault-corrected savings alone already sufficient? If retro-commissioning captures the value without the continuous optimizer, the owner may stop here — this gate protects against paying for an AI layer whose incremental value over commissioning is not established (the §3.3 attribution question, applied as a go/no-go). (A-10) It requires a $ figure, not just a fault count (see the Phase-2 checklist).
  • (R2) GATE 3 is where comfort becomes a pass/fail gate, not a soft metric: a pilot that saves energy but generates comfort complaints does NOT pass. Measured pilot savings must clear the FSU noise band AND the occupant comfort / tenant-satisfaction metric must stay within band. This is the structural enforcement of "net-positive on the value case" from §4.4.
  • (R3) GATE 4 makes persistence an ongoing verification: continuous M&V includes baseline re-adjustment, operator reversion-monitoring (are operators overriding the optimizer, a persistence risk to §4's realized savings?), and sustained AI-FDD fault-recurrence tracking (the §3.3 attribution, now measured over the M&V period).

Per-phase checklist artifacts:

Phase 1 — Readiness Assessment (executes §3 gates): - [ ] Complete §3.1 BMS/BAS readiness checklist — record pass/fail per item - [ ] Complete §3.2 required-point-matrix audit — record % Critical-tier coverage - [ ] Complete §3.3 FDD-baseline fault-log audit — confirm ≥6 months queryable history [ILLUSTRATIVE DEFAULT] or note the gap - [ ] Complete §3.5 operator-readiness checklist — confirm named owner + training-plan status - GATE 1 output: GO / CONDITIONAL (list remediation items + which §6.1 cost lines they trigger) / NO-GO — by the §3.4 series/min rule (verdict = worst dimension). Life-safety write-scope exclusion (§6.4, B1) applies.

Phase 2 — Baseline + FDD: - [ ] Acquire ≥12 months interval data at required resolution (§3.2) OR document why Option D (calibrated simulation) is selected instead - [ ] Fit baseline model per §5.2; compute CV(RMSE), NMBE, R² per §5.3 (targets: CV(RMSE) ≤ 15% monthly / ≤ 30% hourly; |NMBE| ≤ 5% monthly / ≤ 10% hourly per ASHRAE Guideline 14) - [ ] Quantify current fault burden (fault count/rate) per §3.3 — this becomes the pre-deployment baseline for the recurrence-rate metric - [ ] (A-10) Monetize the fault burden: convert the fault count/rate into a $ figure via a per-fault engineering savings calculation against Guideline 36-2021 correct-sequence operation (or a short post-RCx measurement period), producing a $ number comparable to the owner's hurdle — carried with its own uncertainty caveat (the estimate is itself [UNVERIFIED] until measured/engineered) - GATE 2 output: baseline model ACCEPTED (meets §5.3 resolved thresholds) / REJECTED (remediation = extend data window, add independent variables, or fall back to Option D); AND is the one-time fault-corrected $ savings alone (non-AI bucket) sufficient to justify proceeding, independent of the supervisory-AI mechanisms?

Phase 3 — Pilot / Partial Deployment (bounded scope, human-gated writes): - [ ] Define bounded pilot scope (e.g., one AHU system or one floor zone) with a human-approval workflow on every write; life-safety-adjacent points excluded from write scope (§6.4, B1) - [ ] Measure pilot-period savings against §5.3 FSU-derived uncertainty band (a saving is provable only if it exceeds the FSU ≤ 0.50-at-68%-CI-derived $ band) - [ ] Track tenant-satisfaction/comfort metric (complaint-ticket rate, satisfaction-survey score — specific instrument [UNVERIFIED — not specified in this envelope]) across the pilot - GATE 3 output: PASS only if BOTH (a) measured pilot savings exceed the FSU noise band AND (b) comfort/tenant-satisfaction metric stays within the defined acceptable band. A pilot that saves energy but degrades comfort does NOT pass (R2).

Phase 4 — Full Deployment + Continuous M&V: - [ ] Continuous M&V reporting per §5.4 governance cadence - [ ] Baseline re-adjustment protocol triggered on any non-routine event (§5.4) - [ ] Operator-reversion monitoring: track rate of manual overrides of optimizer setpoints (§3.5, R3) — flag if reversion rate trends upward (erosion of trust / potential savings decay) - [ ] Sustained AI-FDD fault-recurrence tracking against the Phase-2 baseline fault rate (§3.3) - GATE 4 output: ongoing — a rolling checkpoint, not a one-time pass/fail; triggers a remediation/retraining cycle if reversion rate or fault-recurrence rate regresses toward baseline.

7.2 Human-gate reminder & RACI

  • Human-gate reminder. At every phase touching control writes, the human-in-the-loop and occupant-comfort veto are explicit: the optimizer proposes, a human/occupant disposes. Autonomy compresses workflow; it never removes the override. The life-safety write-scope exclusion + licensed-PE requirement (§6.4, B1) is restated at each write-touching gate, not assumed once.
  • RACI (high-level, roles not vendor names). The stakeholder set the framework requires:
Role Accountable for
Owner / asset manager Overall go/no-go, capital approval, final risk acceptance
M&V referee (governance property per §5.4, R7 — no specific party presumed) Independent computation/audit of savings claims, CV(RMSE)/FSU compliance, baseline-adjustment protocol
Controls integrator BAS integration, gateway/point-mapping, supervisory-layer deployment
FDD provider Fault-detection tooling, fault-recurrence measurement support
Facilities / operations team (in-house) Day-to-day operation, override/approval of proposed setpoint changes, training completion, reversion-monitoring compliance (R3)
Licensed professional engineer (or jurisdictional equivalent) Sign-off on any life-safety-adjacent control modification, in addition to the standing human gate (B1)

Facilities/ops is explicitly included because operator trust and override behavior determine whether savings persist — leaving them off the RACI would structurally under-manage the §6.4 persistence risk.

(Evidence: gate thresholds reference the criteria established in §3 and §5 — none invented here; any duration/effort, comfort-metric acceptance band, or operator-reversion threshold is sourced or [UNVERIFIED]. Assumption: phasing assumes a CONDITIONAL-or-better §3 gate; a NO-GO short-circuits to remediation-only. Out of scope: detailed project schedule / Gantt; contract templates.)


8. Assumptions, Limitations & Verification Ledger

8.A Verification Ledger

Maps every load-bearing number → {value/range, section, source citation OR [UNVERIFIED], what data would verify it}. This section reconciles against every other section: a number appearing elsewhere but missing here (or a ledger entry with no home in the report) is an internal-consistency failure.

# Claim / value Section Source or [UNVERIFIED] What would verify it
1 ~100,000 sq ft floor area §2.A #1 Brief (stipulated) N/A — stipulated by brief
2 Occupied-hours profile (~50–60 hrs/wk) §2.A #3 [UNVERIFIED] Site lease/schedule data or BAS schedule-object export
3 BACnet IP vs MS/TP §2.A #5, §3.1 [UNVERIFIED] Site BAS network architecture documentation
4 US climate-zone bracket (Zone 4A; rep. city Baltimore, MD) §2.A #6 ASHRAE Standard 169 (zone definitions); Baltimore-as-Zone-4A per DOE/OpenEI (T2, conf 0.70); 169 current edition year [UNVERIFIED] Named weather-station assignment for the actual site; authoritative current-edition confirmation
5 APAC climate-zone bracket (Zone 1A/2A) §2.A #7 ASHRAE Standard 169 (zone definitions); Singapore-Changi confirmed in the 169 station DB, but specific 0A/1A letter [UNVERIFIED] Named weather-station assignment + the ASHRAE 169 tool's zone-output field for the station
6 Tariff stance (US, APAC) — NOT yet bracketed §2.A #8–9, §2.2 [UNVERIFIED] Named utility + rate schedule for the actual site
7 US office EUI benchmark band (~78 kBtu/sf/yr) §2.B CBECS 2018 (EIA) via envigilance.com (T2, conf 0.55) — single-source, primary-table confirmation pending Named ENERGY STAR Portfolio Manager or EIA CBECS 2018 primary table (direct read)
8 APAC office EUI benchmark band (~186 kWh/m²/yr avg) §2.B BCA Building Energy Benchmarking Report 2023 (T2, conf 0.65) — single-source, primary PDF not directly read Direct read of the BCA 2023 report table (current landing-page path)
9 Equipment lifetimes — chiller (~20–25 yr) §2.A #13 ASHRAE Service Life & Maintenance Cost Database via hvac-eng.com (T2, conf 0.55) — sources disagree 20/25/31 yr by sub-type; single-source range Direct query of the ASHRAE Service Life Database for the specific chiller sub-type
9b Equipment lifetimes — AHU / VAV box / DDC controller §2.A #14–15 [UNVERIFIED — AHU directional-only (conf 0.30); VAV box + DDC controller NOT FOUND, searched 2026-07-07] Direct query of the ASHRAE Service Life Database for each equipment class
10 Baseline-period definition (12-month convention) §2.A #12, §5.2 Industry-practice consensus (T3, conf 0.35); specific IPMVP Core Concepts 2022 section [UNVERIFIED] — login-gated primary Named IPMVP section citation (obtain the primary EVO document)
11 Required-point matrix critical-tier composition §3.2 Structural (derived from HVAC engineering first principles) — not an external citation N/A — engineering-logic derivation; verify against actual optimization-vendor point-list once vendor scope is set
12 12-month / 15-minute baseline data requirement §3.2 Stated as a criterion consistent with IPMVP/Guideline 14 M&V practice; specific clause [UNVERIFIED] Named IPMVP/Guideline 14 section
13 Guideline 13-2015 / Guideline 36-2021 as BAS/sequence reference standards §3.1, §3.3 ASHRAE Guideline 13-2015; ASHRAE Guideline 36-2021 Cited standard titles; edition currency reconfirmed at time of use
14 Typical fault prevalence (qualitative) §3.3 LBNL FDD research corpus (T2, conf 0.70) — cited qualitatively; specific % figures NOT pinned (conflation risk across two datasets) Named single LBNL/field-study citation read directly, mapping each % to its source paper
15 Savings decomposition — (a) commissioning ~16% median EBCx; (b) supervisory ~8%/7%/29% + ~40% MPC upper bound §4.2 Mills (2011) LBNL (T2); PNNL-25985 DOE BTO 2017 + LBNL MPC field demo (T1) — scope caveats: EBCx=whole-building; PNNL=nationwide-all-building-type; 40%=single-site upper bound Office-specific, dated citations per mechanism; direct read of the LBNL/PNNL primary PDFs
15b Savings decomposition — (a)-sustained + (c) demand-side ranges §4.2 [UNVERIFIED — no specific figure resolvable within this envelope] Named, dated source per mechanism
16 HVAC share of total building energy (denominator) §4.1 CBECS 2018 (EIA, T1): heating ~30% + ventilation ~20% directly reported; cooling % NOT separately broken out → combined HVAC share [UNVERIFIED] EIA CBECS 2018 end-use table (e.g., Table C13) with cooling % readable
17 CV(RMSE) acceptance threshold (≤15% monthly / ≤30% hourly) §5.3 ASHRAE Guideline 14 via OSTI/LBNL + reproduced criteria tables (T2, conf 0.90) — 2002/2014 values; 2023-edition revision [UNVERIFIED] Direct lookup in Guideline 14-2023 threshold table by model interval
18 NMBE acceptance bound (|NMBE| ≤5% monthly / ≤10% hourly) §5.3 Same G14 calibration-criteria table (T2, conf 0.90) — 2002/2014 values; 2023-edition revision [UNVERIFIED] Same
19 FSU maximum threshold + CI (≤0.50 at 68% CI) §5.3 ASHRAE Guideline 14 via TAMU thesis + LBNL Granderson (T2, conf 0.80) — search-summarized, not directly read; FEMP v4.0 does not independently specify the CI Direct read of the primary G14 FSU criterion sentence
20 IPMVP option-selection reference section §5.1 [UNVERIFIED — NOT FOUND: 2022 revision covers option-selection but no source gave the section number; searched 2026-07-07] Direct lookup in IPMVP Core Concepts 2022 (obtain primary)
21 CapEx cost-category ranges §6.1 [UNVERIFIED — all vendor-quote-dependent] Actual vendor quotes at time of live project
22 Discount rate (illustrative 6–10% placeholder) §6.2 [UNVERIFIED — presented as a common capital-screening range, not a sourced figure]; live case requires the owner's financial-analysis function (B4) Owner financial-analysis cross-call for a live >$100K decision
23 Contingency % (10–20%) §6.1 [UNVERIFIED — presented as common capital-project practice, not a cited standard] Named capital-project cost-estimating standard
24 AIM Act HFC step (2026 = 60% of baseline) §6.3 US EPA "Frequent Questions on the Phasedown of HFCs" (T1, conf 0.85) — general 2024–2028 step-band; archetype's specific refrigerant/GWP [UNVERIFIED] 2026 Federal Register allocation notice for exact tonnage; AIM Act HFC list once refrigerant identity is known
24a Kigali-Amendment HFC controls (APAC / Singapore NEA) (B-6) §6.3 Singapore NEA circulars via Lexology/Rajah & Tann (T2, conf 0.75): GWP-15 chiller rule (Oct 2022), GWP-150 broader rule eff. 1 Apr 2027; archetype refrigerant [UNVERIFIED — requires named refrigerant] Named APAC jurisdiction's adopted HFC-control schedule (direct NEA circular read)
24b Refrigerant GWP reference values (AR4) §6.3 R-134a 1,430 / R-410A 2,088 (high conf) · R-513A 630 / R-1233zd(E) 1 (T2, conf 0.65 — spot-check recommended); AR4-basis per EPA (T1) EPA SNAP/GWP table or IPCC AR4 Table 2.14 direct read
25 ASHRAE 90.1-2022 / local code capital-action trigger (US) §6.3 [UNVERIFIED — requires named jurisdiction's adopted code edition] Named local code adoption lookup
25a APAC minimum-efficiency / energy-code trigger (e.g., SG SS 553 / BCA Green Mark) (B-6) §6.3 [UNVERIFIED — requires named APAC jurisdiction's adopted edition] Named APAC code adoption lookup
26 ISA/IEC 62443 as OT-security reference (esp. -4-2 + -2-1) §6.4 ISA/IEC 62443 series (T2, conf 0.65) — layered framework; -4-2 component + -2-1 program are the relevant parts Direct read of the specific paywalled parts; edition currency reconfirmed at time of use
27 ASHRAE 55-2023 as comfort-bound reference §6.4, §7 ANSI/ASHRAE Standard 55-2023 (T1, conf 0.90 — supersedes 55-2020) Cited standard edition; reconfirm currency at time of use
28 Comfort/tenant-satisfaction acceptance metric instrument §7 GATE 3 [UNVERIFIED — no specific instrument named within this envelope] Project-specific tenant-satisfaction survey / complaint-ticket protocol defined at pilot design
29 Point-coverage GO/CONDITIONAL/NO-GO % bands (≥90% / 60–89% / <60%) (B-3) §3.4 [ILLUSTRATIVE DEFAULT — not a sourced/validated threshold; owner may recalibrate against the vendor's actual point-list] Optimization-vendor required-point specification + owner risk tolerance
30 Critical-check-count bands (1–2 vs ≥3 failures) + ≥6-month fault-history minimum (B-3) §3.4, §3.3, §7 Phase 1 [ILLUSTRATIVE DEFAULT — not a sourced/validated threshold; owner may recalibrate] Owner change-management standard + M&V baseline-data-sufficiency practice
31 EFLH (cooling) — climate-zone-specific (A-12) §2.A #16, §4.2b [UNVERIFIED — NOT FOUND: no numeric hot-humid-vs-mixed EFLH comparison table retrievable, searched 2026-07-07; only generic methodology sources] Named climate-zone EFLH source (ASHRAE climatic data / regional load study)
32 ~$1M Monte Carlo trigger (B-3) §6.1, §6.2 [ILLUSTRATIVE DEFAULT — not a sourced/validated threshold; owner may recalibrate] Owner capital-project analytics policy

8.B Standards & Sources Appendix

Standard / source Role in this report Edition cited
ASHRAE 90.1 Energy-code baseline reference; potential capital-action trigger (§6.3) 2022
ASHRAE Guideline 14 CV(RMSE) ≤15% monthly / ≤30% hourly, |NMBE| ≤5% monthly / ≤10% hourly, FSU ≤0.50 at 68% CI (§5.3) — resolved via OSTI/LBNL + TAMU/Granderson secondary sources (T2); values are the consistent 2002/2014 figures, 2023-edition revision [UNVERIFIED] 2002/2014 values cited (2023 assumed current edition)
ASHRAE Guideline 36 High-performance sequences of operation — fault-baseline correctness reference (§3.1, §3.3) 2021
ASHRAE Guideline 13 BAS specification practice — readiness benchmark (§3.1) 2015
ASHRAE 55 Thermal comfort bounds — hard constraint on optimizer (§6.4, §7); current edition confirmed (T1) 2023 (supersedes 2020)
ASHRAE Standard 169 Climatic-zone definitions for the US/APAC bracket selection (§2.A); Baltimore=Zone 4A rep. city (T2); Singapore in station DB but zone-letter [UNVERIFIED] Cited as standard title; current edition year [UNVERIFIED] (2013/2020/2021 conflicting)
IPMVP Core Concepts Option A/B/C/D definitions + selection guidance (§5.1); baseline-period convention (§5.2) — 12-month convention = industry practice (T3); specific section numbers [UNVERIFIED] (login-gated primary) 2022
ISA/IEC 62443 OT/BAS cybersecurity reference framework (§6.4); relevant parts -4-2 (component) + -2-1 (security program) per vendor/technical summaries (T2) Cited as standard title; specific part/edition [UNVERIFIED]
AIM Act US HFC refrigerant phase-down schedule (§6.3); 2026 = 60%-of-baseline step per EPA FAQ (T1) Cited as statute; specific HFC-list edition/date [UNVERIFIED]
US EPA — Frequent Questions on the Phasedown of HFCs / HFC Allowances AIM Act 2024–2028 step (60% of baseline) + AR4 GWP basis (§6.3) Directly fetched 2026-07 (T1)
Kigali Amendment (as locally adopted) / Singapore NEA circulars APAC HFC refrigerant phase-down basis (§6.3); SG GWP-15 chiller rule (Oct 2022) + GWP-150 broader rule eff. 1 Apr 2027 (T2, law-firm secondary) Cited as treaty basis + NEA circulars; primary PDF not directly read
Refrigerant GWP references (AR4 basis) R-134a 1,430 / R-410A 2,088 / R-513A 630 / R-1233zd(E) 1 (§6.3) — reference table, not archetype-specific AR4 (IPCC 2007) 100-yr basis; industry technical refs (T2), spot-check recommended for R-513A/R-1233zd(E)
CBECS 2018 (EIA) / ENERGY STAR Portfolio Manager US EUI benchmark ~78 kBtu/sf/yr (T2 single-source, §2.B) + US office end-use split heating ~30% / ventilation ~20% (T1 direct read, §4.1); cooling % NOT broken out CBECS 2018; specific EUI dataset vintage confirmation pending
BCA Building Energy Benchmarking Report (Singapore) APAC EUI benchmark ~186 kWh/m²/yr avg large-office (T2 single-source, §2.B) 2023
Mills (2011) LBNL — Building Commissioning meta-study Commissioning savings ~16% median EBCx (§4.2), whole-building scope (T2) 2011
PNNL-25985 (DOE Building Technologies Office) / LBNL MPC field demo Supervisory-control savings ~8%/7%/29% nationwide-all-building-type + ~40% single-site MPC upper bound (§4.2, T1) 2017 (PNNL-25985)
LBNL FDD research corpus Qualitative fault-prevalence basis (§3.3, T2); specific % not pinned (conflation risk) Cited qualitatively
DOE Building America / OpenEI Zone-4A representative city = Baltimore, MD (§2.A #6, T2) Cited as DOE designation
BCA Green Mark / NABERS / SG SS 553 (candidate APAC references) APAC EUI benchmarking + energy-code source categories (§2.B, §6.3) Specific dataset/edition [UNVERIFIED]

(B-3) Internal-consistency note (verified after the grounding-pass additions): every [UNVERIFIED] and [ILLUSTRATIVE DEFAULT] tag in the report body corresponds to a ledger row above (rows 1–32, including the split rows 9b/15b/24b and the newly named sources), and every ledger row has a home in a numbered section. The illustrative thresholds (rows 29–32) remain [ILLUSTRATIVE DEFAULT] (unchanged — the grounding pass introduced no source for them). Newly-resolved values (G14 thresholds, AIM Act step, ASHRAE 55-2023, CBECS partial end-use, PNNL/Mills mechanism figures, Baltimore Zone-4A, Singapore NEA) each carry their tier + scope caveat inline and in the ledger. Caveated single-source values (US/APAC EUI, chiller life, GWP sub-set) retain their visible caveat. No number in this report is asserted anywhere without its matching tag/citation appearing in this ledger, and no value not present in the grounding dossier was introduced.

8.C References — resolved source URLs (grounding pass 2026-07-07, verbatim from the web-verified grounding dossier; tier/confidence per §8.A/§8.B)


9. Cross-Section Coherence & Blocking-Check Summary

Three coherence properties tie the sections into one argument:

  1. The verdict is a conjunction, and each conjunct is a gate. §1's conditional decomposes into §3 (feasibility + operator readiness, combined by the series/min rule), §4 (savings clear the hurdle), §5 (savings are verifiable), and §6/§7 (comfort + persistence + risk hold). No single strong result — not a high savings %, not a clean point list — carries the verdict alone.
  2. Data flows forward and derives downstream choices; nothing is presumed. §3.2 point coverage derives the §5 IPMVP option (R1). §3.3 fault burden derives the §4 FDD attribution and the §5 measurability requirement (R5). §4's denominator (§4.1) flows into §6's payback so it cannot be inflated. §2's brackets (R6) bound §4's savings and §6's tariff sensitivity.
  3. The honesty and human-gate rails are load-bearing, not decorative. The archetype-not-asset rule, the [UNVERIFIED] discipline, the HVAC/energy-OpEx denominator, the derived-not-presumed IPMVP option (R1), the required-not-presumed M&V independence (R7), the life-safety write-scope exclusion (B1), and the human gate each map to a BLOCK condition — a section violating one is not shippable.

Blocking checks this report satisfies (any trigger = report not shippable):

Check Requirement Where discharged
B1 No life-safety-adjacent control modification without a human-gate + licensed-PE statement §6.4 write-scope exclusion + §7 gate echoes + RACI row
B3 No M&V claim without a baseline-model citation §5.2 baseline model spec (IPMVP + ASHRAE Climatic DB anchors)
B4 No live >$100K decision without the owner's financial-analysis function supplying the discount rate §6.1/§6.2 (illustrative rate labeled assumption + live-case pull note); ledger row 22
B5 No savings claim without a CV(RMSE)/FSU uncertainty bound §5.3 acceptance statistics (now resolved to G14) + §4.4 noise test
Honesty-rail No load-bearing number without a source or [UNVERIFIED]/[ILLUSTRATIVE DEFAULT] §8.A ledger (rows 1–32) reconciles every number
No vendor endorsement Categories only, never comparative product rankings Enforced throughout; RACI uses roles not vendor names
R1 No IPMVP option presented as settled "primary" without deriving it from the §3.2 data gate §5.1 (option [UNVERIFIED] pending §3.2)
R6 Dual-jurisdiction brackets; widen if the verdict flips within a jurisdiction's range §2.2 (climate axis bracketed; tariff axis flagged not-yet-bracketed)
R7 No specific party (incl. AISB) asserted as "independent M&V referee" inside the methodology, or without the supplier/referee-overlap disclosure §5.4 (property required, no party named; CoI disclosure mandatory)

10. Limitations Statement

The reader must leave knowing exactly what would need real data to firm up. Each limitation is traceable to a rail above:

  • Archetype-not-asset. Every quantitative statement about this building is an industry range or a decision criterion, never a measured finding (§0.1). There is no meter data; the whole analysis is a framework the owner runs against a real building. Consequently the report answers the brief at the methodology/decision-gate level — coverage items 2/3/4 are ranges, criteria, and rules, with building-specific numeric cells deliberately [UNVERIFIED] pending site data (§1.3), even where an industry-range citation now backs a mechanism.
  • Grounded values carry scope caveats — they are not building-specific findings. The grounding pass resolved industry values (G14 thresholds, AIM Act step, ASHRAE 55-2023, CBECS partial end-use, PNNL/Mills mechanism ranges, Baltimore Zone-4A, Singapore NEA) via web-verified sources, but each is a reference/benchmark with its tier and scope caveat (whole-building EBCx, nationwide-all-building-type, single-site upper-bound, single-source EUI) — none is a measured property of this archetype.
  • Dual-jurisdiction ranges — and the two-point-bracket adequacy caveat (R6). Region-sensitive values bracket US and APAC on the climate axis; the tariff axis is not yet bracketed and the R6 widening rule applies to it with full force (§2.2). If the verdict flips within a jurisdiction's climate/tariff range, the two-point bracket is inadequate and must be widened.
  • Savings are pre-M&V estimates. The realized value is [UNVERIFIED] until §5's M&V confirms it exceeds the measurement uncertainty band; a saving inside the noise is unprovable (§4.4). The mechanism % figures now carry named DOE/LBNL sources but at nationwide/whole-building/single-site scope — office-specific dated citations are still owed (§4.2); the (a)-sustained and (c) demand-side rows remain [UNVERIFIED].
  • The IPMVP option is unresolved until data (R1). The option is derived from §3.2 point coverage, not presumed; it is [UNVERIFIED] for the archetype (§5.1). The CV(RMSE)/NMBE/FSU numeric thresholds are now resolved to ASHRAE Guideline 14 (2002/2014 values; the 2023-edition revision status is [UNVERIFIED]) and the exact IPMVP option-selection section number is [UNVERIFIED] (§5.3, §5.1).
  • FDD-vs-AI attribution is measured, not assumed (R5). The AI-FDD persistence credit is a fault-recurrence measurement, not a claimed split (§3.3); fault-prevalence figures are cited qualitatively, not pinned.
  • Comfort and persistence are conditions on the verdict (R2/R3). Comfort degradation is a value-case downside and a pass/fail pilot gate; savings persistence is an ongoing monitored risk — the verdict is a conjunction, not a savings number (§1.1, §4.4, §7).
  • M&V referee independence is a required property, not a presumed party (R7). Independence is required and any supplier/referee overlap is a disclosed, mitigated conflict; no specific party (including AISB) is asserted as the referee inside the methodology (§5.4).
  • Gate thresholds are illustrative defaults where not sourced. The §3.4 point-coverage/critical-check/fault-history bands and the ~$1M Monte Carlo trigger are [ILLUSTRATIVE DEFAULT] values the owner recalibrates — not sourced/validated thresholds (§3.4, §6, ledger rows 29–32); the grounding pass introduced no source for them and did not upgrade them.
  • Life-safety scope is excluded by design. The optimizer's write scope categorically excludes life-safety-adjacent points; any such change requires a licensed-PE sign-off in addition to the human gate (B1, §6.4).
  • Financials are illustrative, not investment advice. A live decision re-runs them with real quotes and a real discount rate (from the owner's financial-analysis function, for >$100K) (§6.1).

Closing note on what this report is and is not: it is a complete, internally-consistent decision-gate framework and M&V methodology for a representative Class-A office tower, answering every coverage item of the brief at the level the archetype permits. It is not a building-specific feasibility verdict, a set of measured savings, or investment advice — those require the site data and named sources the framework tells the owner how to obtain, and the gates in §7 tell the owner how to act on them once obtained.

Read the next one first.
Subscribe free to The Intelligent Building Brief for weekly CRE intelligence and the Top-5 exclusive reports. Subscribe free →