I have commissioned and inherited building management systems across Gulf estates for more than twenty years, and the pattern is always the same. The estate that feels trapped with one controls contractor did not get trapped on site. It got trapped at tender, in a handful of specification clauses that nobody read closely because they sounded like boilerplate. This is a clause-by-clause checklist of the wording that decides the next ten years, with the exact change I ask for and the commercial reason behind it.
The single most expensive omission
If you fix only one clause, fix this one. Failing to require the integrator to hand over the licensed engineering tool and the controller source programs turns every future change into a sole-source order at a premium. You keep paying the original contractor to touch your own building, forever, because nobody else can open the logic.
A quick disclaimer before the clauses. The wording examples below are illustrative, written to show the shape of the change, not to be pasted into a contract. They are not legal advice. Adapt them with your own procurement and legal teams, and align them to your jurisdiction and standard form of contract. Certification terminology also moves, so verify current listing scope with the source bodies rather than trusting a spec you were handed.
1. Open-protocol conformance and BTL listing
Almost every specification says the system "shall be BACnet" or "shall be open protocol." That sentence is worth nothing. A gateway with one BACnet point on it is technically BACnet. What you actually want is that the controllers themselves speak a standard protocol natively, that the device profile is stated, and that the units are independently listed as conformant, not merely claimed by the vendor's brochure.
What to require:
- Native BACnet or another named open protocol at the controller level, not translated at a single gateway.
- The specific BACnet device profile stated (for example a building controller profile rather than a smart sensor profile).
- Independent listing evidence from BACnet International for the exact model numbers being supplied.
- A Protocol Implementation Conformance Statement for every controller type on the project.
Verify the listing scope yourself
BTL listing terminology and certification scope change over time, and a listed brand does not mean the specific model on your job is listed. Check the current listing directory against the actual part numbers in the submittal. "Open" claimed in marketing and "conformant" as tested are not the same thing.
2. Controller programming-tool licences handed to the client
This is where most estates lose. The BACnet interface lets another system read and write points, but it does not let anyone reprogram the controller logic. That takes the manufacturer's engineering tool, and the licence for that tool is usually kept by the installing contractor. So even with a perfectly open protocol, you cannot change a control sequence, retune a loop, or add a plant item without going back to the one company that holds the software.
What to require:
- A named, transferable licence for the manufacturer engineering and programming tool, issued in the client name, delivered at handover.
- The controller source programs, in editable form, not compiled binaries.
- Any dongles, activation keys, or account credentials the tool needs to run.
- A written statement that no runtime licence or annual reactivation fee is required to keep the tool usable.
Without this, an "open" system is open in name only. I have watched an owner pay a premium change-order for a fifteen-minute logic edit purely because the licence sat on a laptop in the contractor office. The interface was open. The keys to the logic were not.
3. Graphics source-files ownership
The head-end graphics, the floor plans, plant schematics, and dashboards operators stare at all day, are drawn in an authoring environment. What you get by default is the published, view-only result. The editable source, the project files and page definitions, often stays with the integrator. Change a tenant fit-out, add a chiller, or rebrand the interface, and you are back to a sole-source order.
What to require:
- All graphics source and project files delivered in native editable format, with the authoring tool licence.
- The point-naming and tag reference used behind the graphics, documented.
- Ownership and reuse rights assigned to the client, including the right to appoint a different contractor to edit them.
4. Database and trend-data export rights
Your BMS accumulates years of trend logs, alarm history, and configuration. That data is an asset. It feeds energy analysis, it feeds your CAFM integration, and it is the baseline for any future optimisation. Many systems make it hard to get out in bulk, or lock historical data inside a proprietary store you cannot query.
What to require:
- Full export of trend, alarm, and configuration data in an open format such as CSV or SQL, on demand, without a fee.
- A documented schema so the export is usable, not an undocumented dump.
- Direct read access to the historian database, or a documented API to it.
- A clause confirming the data belongs to the client, not the vendor or the contractor.
5. Integration-gateway supply
When the BMS has to talk to chillers, meters, lifts, or a supervisory SCADA platform, a gateway usually sits in the middle translating protocols. The gateway is a favourite lock-in point: proprietary, licence-limited by point count, and configured with a tool only the contractor holds. Expand the estate and you find the gateway is "full" and a new one plus reconfiguration is a fresh order.
What to require:
- Gateways sized with a stated spare point capacity, typically twenty percent, at handover.
- The gateway configuration file and its editing tool delivered to the client.
- A complete register of every mapped point across the gateway.
- No per-point licensing that charges again to use capacity you already bought.
6. Third-party access to the API or BACnet/IP network
The final lock is contractual, not technical. Even with an open protocol, some contracts forbid connecting third-party equipment to "their" network, or void warranty if anyone else touches the BACnet/IP segment. That clause quietly makes the open system closed, because it removes your right to appoint anyone else.
What to require:
- An explicit right for the client and its nominated contractors to connect to the BMS network and API.
- Documented API access and the BACnet/IP network topology, including addressing and any credentials.
- Warranty that is not voided by third-party integration performed to the documented interface.
The rewrite table: as usually written versus as it should be written
Here is the same six-point checklist as the wording change I actually request, next to the version that turns up in most tenders, and the commercial consequence of leaving it alone.
| Clause as usually written | Clause as it should be written | Commercial consequence if unchanged |
|---|---|---|
| "The system shall be BACnet and fully open." | "Each controller shall natively support BACnet at the stated device profile, evidenced by an independent conformance listing for the supplied model numbers, with a PICS for every controller type." | A single translating gateway satisfies the loose wording. You buy "open" and get a black box with one open port. |
| "Contractor shall program the system." | "Contractor shall deliver a transferable engineering-tool licence in the client name, plus editable controller source programs and all activation keys, at handover." | Every future logic edit is a sole-source change-order at a premium. This is the most expensive omission on the page. |
| "Graphical user interface shall be provided." | "All graphics source and project files shall be delivered in native editable format with the authoring licence, and reuse rights assigned to the client." | A fit-out change or added plant means paying the original contractor to redraw screens you thought you owned. |
| "System shall provide trend and alarm reporting." | "Client shall have on-demand bulk export of trend, alarm, and configuration data in open format with a documented schema, and direct read access to the historian." | Years of operational data stay locked in a proprietary store, unusable for energy analysis or CAFM integration. |
| "Gateways shall be provided as required." | "Gateways shall carry twenty percent spare point capacity at handover, with configuration files, editing tool, and a full point register delivered to the client, and no per-point relicensing." | Expansion finds the gateway "full." New hardware and reconfiguration become a fresh sole-source order. |
| "Warranty applies to the installed system." | "Client and its nominated contractors may connect to the BMS network and API per the documented interface without voiding warranty." | An open protocol becomes contractually closed. You lose the right to appoint anyone else to touch the system. |
Commissioning acceptance, retention, and defects liability
Ownership clauses decide who can work on the system. The commissioning and defects clauses decide whether it works at all when they do. This is where I tie money to evidence, because a BMS can pass a visual handover and still be riddled with dead trends and nuisance alarms.
Commissioning acceptance criteria:
- Point-to-point verification of every input and output, signed off against the register, not a sample.
- Sequence-of-operation testing against the written control narrative, with witnessed results.
- Trend logs proven live and recording at the specified interval on every monitored point, verified over a defined period before acceptance.
Retention tied to trend-log verification:
I withhold a portion of retention against verified, continuous trend data, not against the day of handover. A percentage of the value is released only after the trend logs are confirmed complete and gap-free across an agreed window, typically thirty to ninety days. It costs nothing if the work was done properly, and it is the only lever that reliably gets trends configured correctly the first time.
Defects liability covering configuration, not just hardware:
A standard defects clause covers a failed sensor or a dead controller. It rarely covers a badly configured alarm that floods operators, or a control loop that hunts because it was never tuned. I extend defects liability explicitly to alarm-configuration quality and control performance, so nuisance alarms, missing alarms, and untuned sequences are correctable defects during the liability period, at no charge. Hardware failure is the easy case. Configuration quality is where the real operating cost hides.
Why vendor-supplied templates fail you here
When a controls vendor hands you a ready-made specification, it is a gift with a hook. Those templates are written to protect the vendor aftermarket revenue, which is the recurring income from being the only firm that can service, expand, and reprogram the system. Every clause above tends to be soft, absent, or quietly reversed in a vendor template.
- Open-protocol wording is present but loose enough to satisfy with a gateway.
- Programming-tool licences and source programs are simply not mentioned.
- Graphics and configuration files are delivered as view-only outputs.
- Data export and API access are described as features, not client rights.
- Third-party connection is discouraged through warranty conditions.
None of this is dishonest. It is a vendor writing a specification that serves the vendor. Your job, or the job of the independent specialist you appoint, is to write one that serves the estate. A clean asset structure helps too: see how I approach asset hierarchy design so the points you fight to own map cleanly into your maintenance system.
Conclusion: the ten-year test
Run every controls clause through one question. In year seven, when this contractor is unavailable or too expensive, can I appoint someone else to open the logic, edit the graphics, read my data, expand the gateway, and connect to the network, without buying anything I already paid for? If the answer is no, the specification failed, no matter how good the hardware is. Fix the wording before the tender closes. It is nearly free at that point, and nearly impossible to fix afterward. And bring your legal team to turn these illustrative changes into enforceable ones for your contract and jurisdiction.
Written by Muhammad Abbas
CMMS / CAFM Manager & Enterprise Integration Specialist · 22+ years across ERP, EAM, CAFM and enterprise integration.
Work with me