New-build controls are comparatively easy. The containment is going in anyway, the ceilings are open, nobody is working under them, and the cost of a cable run is buried in a package that was always going to be spent. Retrofit is a different discipline entirely. In an occupied building the device on the drawing might cost a few hundred dirhams and the cable to reach it might cost several times that, if a route exists at all. That single asymmetry, cheap device and expensive cable, is what has driven the whole wireless building controls market, and it is also why so much wireless gets sold on a promise it cannot fully keep. Wireless removes the cable. It does not remove the commissioning, the power, the batteries, the interference, or the fact that nobody has accurate drawings of the plant you are trying to control.
The message up front: in a retrofit, the constraint is almost never the controller. It is containment, ceiling access, out-of-hours working and the quality of the existing documentation. Wireless is a genuine answer to the cabling half of that problem and no answer at all to the rest. The pattern that works on most occupied buildings is wireless sensing with wired control, and the spend that de-risks everything else is a sensing-only overlay first, because most retrofit business cases rest on assumptions about a building nobody has ever measured.
1. Why retrofit is hard, and it is not the technology
Walk a 1990s office tower or a hospital wing with a controls contractor and count the reasons a simple sensor becomes a three-week negotiation. Almost none of them are electronic.
- No containment routes. The original design provided trunking for the original design. Twenty years of churn later, the trays are full, the risers are congested, and the route from the plant room to the zone you now care about does not exist. New containment through occupied floors means builder's work, fire-stopping, and a permit for every penetration.
- Asbestos and other legacy materials. In older stock, any intrusive work above a ceiling or through a wall triggers a survey and potentially licensed removal. This converts a half-day cable pull into a managed project with its own programme and its own cost, and it is the single most common reason a retrofit scope quietly shrinks after survey.
- The building is occupied and working. You cannot isolate a floor of traders, a ward, or a data hall because the controls upgrade needs a shutdown. Every isolation is negotiated, and some are simply refused.
- Ceiling access is worse than the drawings suggest. Plasterboard instead of tiles. Tiles that have been screwed shut. Voids stuffed with later services. Sprinkler pipework exactly where the cable wants to go. Surveying access is the most under-scoped activity in retrofit controls.
- Out-of-hours working. If work can only happen between 22:00 and 05:00, labour rates rise, productivity falls, supervision and security escorts are needed, and the programme stretches. A task that is four hours in daylight can be two nights in practice.
- The cost is in the cable, not the device. This is the sentence to carry into every retrofit design review. Field device cost is often a minor line. Installation, containment, making good, access, permits and out-of-hours premium dominate. Design the system to minimise the expensive thing, not the cheap thing.
If you have not yet read the foundation material, the complete guide to building management systems and the building automation systems explainer set out what a BMS is actually doing before we start changing how it is wired.
2. What wireless genuinely solves, and what it does not
Be precise about this, because vendor positioning blurs it deliberately. Wireless attacks one specific cost, and leaves the others intact.
What it genuinely solves:
- The signal cable from field device back to controller or gateway. This is the big one, and on a difficult route it is a real saving measured in days of access rather than metres of cable.
- Coverage of places a cable was never going to reach economically: a remote plant enclosure, a listed facade, a tenant fit-out you do not control, a temporary or seasonal space.
- Density. Because the marginal cost of one more sensor is low, you can measure per-room rather than per-floor, which is where most of the useful insight actually lives.
- Programme risk. Fewer access events, fewer permits, fewer night shifts, less making good, and a scope that survives the asbestos survey.
What it does not solve:
- Power. A sensor can run on a battery or harvest energy. A valve actuator, a damper actuator, a variable speed drive and a controller cannot. If the device does work, it needs power, and power is a cable. Wireless actuation usually means you still pulled a local supply, at which point you should ask honestly what you saved.
- Commissioning. Every point still has to be identified, addressed, mapped, graphed, alarmed and proven. Wireless slightly increases this burden because you also have to verify signal quality at each location, under real occupancy, not on an empty floor.
- Documentation. Wireless does nothing about the fact that the existing drawings are wrong. See section 9.
- Integration. Getting the data into the head-end, the analytics platform or the CMMS is the same problem it always was. That architecture is covered in IoT and BMS integration.
- Lifecycle. You have swapped a cable that lasts thirty years for a radio ecosystem with a firmware roadmap, a battery population and a vendor dependency. That is a trade, not a free win.
The test I apply to any wireless proposal
For each proposed wireless device, ask one question: does this device need a local power supply anyway? If yes, the cable is coming regardless and wireless is buying you very little, so put the data on the same cable. If no, wireless is buying you a genuine access saving and you should take it. That single question sorts most retrofit schedules into the right technology within an afternoon.
3. The wireless technologies, compared honestly
There is no single best radio for buildings, and anyone who tells you otherwise is selling one. Each technology trades range against power against data rate against ecosystem maturity. The comparison below reflects how these behave in real occupied buildings rather than in a datasheet, and the range figures are indicative only: concrete cores, foil-backed insulation, plant rooms, lift shafts and metal-stud partitions will all reduce them, sometimes severely.
| Technology | Typical indoor behaviour | Power model | Strengths | Honest weaknesses | Best retrofit fit |
|---|---|---|---|---|---|
| EnOcean (868 / 902 MHz, energy harvesting) | Room to floor scale, sub-GHz penetration better than 2.4 GHz; needs repeaters across cores | Harvested: solar cell, thermal gradient, kinetic press. Often no battery at all | No battery maintenance on harvesting devices; very mature building ecosystem for switches, room sensors, window contacts | Tiny energy budget means low data rate and infrequent transmission; solar-harvesting devices need real ambient light, so dark plant rooms and back-of-house are poor candidates | Room-level temperature, occupancy, window and door contacts, wireless light switches in occupied offices |
| Zigbee (2.4 GHz mesh) | Short hop, extended by mesh through mains-powered nodes; 2.4 GHz attenuates hard through concrete and foil | Battery for sensors, mains for routers and coordinators | Self-healing mesh, high device density, strong lighting-control ecosystem | Mesh reliability depends on a healthy population of mains-powered routers, which a sensor-only deployment does not have; shares the crowded 2.4 GHz band with Wi-Fi and Bluetooth | Lighting control and dense sensing where luminaires provide the mains-powered mesh backbone |
| LoRaWAN (sub-GHz, long range, star topology) | Excellent penetration and building-wide or campus-wide reach from very few gateways | Battery, with genuinely long life because transmissions are tiny and rare | One or two gateways can cover an entire tower including basements and risers; no mesh to maintain; ideal for metering and slow-moving data | Very low duty cycle and small payloads make it unsuitable for control loops or fast feedback; downlink to devices is limited; not a real-time technology | Sub-metering, tank levels, remote plant status, spot temperature and humidity, anything measured in minutes rather than seconds |
| Bluetooth Low Energy (2.4 GHz) | Room scale, extended by BLE mesh; heavily dependent on node density | Coin cell for beacons and sensors, mains for mesh relays | Ubiquitous in phones and tablets, so commissioning and local override by handset is easy; cheap silicon | Short range, 2.4 GHz congestion, and a fragmented profile landscape; BLE mesh in buildings is less proven than its marketing suggests | Asset tracking, occupancy and utilisation analytics, local commissioning access, wayfinding |
| Wi-Fi (2.4 / 5 GHz) | Follows existing corporate coverage, which rarely extends to plant rooms and risers | Mains, or battery with poor life; Wi-Fi is power-hungry by building-sensor standards | Infrastructure already exists; high bandwidth; familiar to IT | Battery life is the weak point, so Wi-Fi sensors usually need power anyway; puts operational devices on the corporate network, which raises a security and ownership question IT will rightly push back on | Mains-powered gateways, cameras, panels and displays; rarely the right choice for battery sensing |
| Proprietary sub-GHz (vendor specific) | Usually good, because the vendor tuned the radio to their own device population | Battery, sometimes long life | Often the most reliable and best-integrated option inside one manufacturer's controls range; single point of support | Lock-in. Devices, gateways, tools and spares come from one source, and a head-end change later can orphan the whole field layer | Single-vendor retrofits where the head-end is also being replaced and you accept the lock-in knowingly |
Two vendor-neutral references worth having open when you specify: the EnOcean Alliance for the energy-harvesting ecosystem and device profiles, and the LoRa Alliance for LoRaWAN specifications and certified-device listings. For open building protocols on the wired side of the same system, ASHRAE remains the authority on BACnet.
4. RF reality: range, interference and structure
The most common wireless retrofit failure is not a dead device. It is a device that works on the day of commissioning and becomes intermittent three months later. The causes are boringly physical.
- Structure eats signal. Reinforced concrete, foil-backed plasterboard and insulation, metal stud partitions, lift shafts, plant room enclosures and large water volumes all attenuate heavily. 2.4 GHz suffers worst; sub-GHz penetrates noticeably better, which is why EnOcean and LoRaWAN behave so much more forgivingly in real buildings.
- Occupancy changes the RF environment. An empty floor is an RF paradise. Fill it with people, partitions, filing, monitors, metal furniture and a hundred personal hotspots and the same link budget looks very different. Never accept a survey done before fit-out as proof of coverage after fit-out.
- The 2.4 GHz band is congested. Corporate Wi-Fi, guest Wi-Fi, Bluetooth headsets, wireless presentation systems and neighbouring tenants all share it. Sub-GHz bands are quieter, which matters more than raw data rate for sensing.
- Mesh is not magic. A mesh heals around a failed node only if there are alternative mains-powered nodes to route through. A sparse, battery-only deployment has no real mesh, just a chain, and a chain fails at its weakest link. Mesh also adds latency per hop and makes fault-finding harder, because a symptom at one device may have its cause three hops away.
- Things move. A tenant installs a metal shelving run. A contractor puts a new riser door in. Someone stacks pallets against a gateway wall. Retrofit wireless lives in a building that keeps changing, and the design margin you left on day one is the only thing protecting you.
Where wireless does not belong
I would not put safety, life-safety interlock, statutory, or fast closed-loop control on a battery radio link in a retrofit. Fire and smoke control systems have their own certified route and are not a BMS discussion. Critical plant interlocks, generator and UPS control, and anything where a missed message has a safety or continuity consequence should stay hardwired. A dropped sensor reading is an inconvenience. A dropped command is an incident.
5. Batteries: the recurring cost nobody budgets
This is the part of the wireless business case that is routinely left out, and at scale it is not trivial. A datasheet says five to ten years of battery life. Real life shortens that: shorter reporting intervals than assumed, retries on a marginal link, temperature extremes in plant rooms and on facades, and the ordinary variance of cell quality. Assume the realistic figure is materially less than the datasheet figure and plan for a replacement population rather than a replacement event.
The cost is not the cell. The cell is trivial. The cost is the same cost that drove you to wireless in the first place: access. Replacing a battery in a ceiling void, above a ward, behind a tenant's furniture, or in a locked riser needs the same permit, the same escort, the same ladder and possibly the same out-of-hours window as the original install. Deploy three thousand sensors across a portfolio and you have created a permanent, recurring, access-driven maintenance task that arrives unevenly and forever.
What I would insist on at design stage:
- Standardise the cell type across the whole estate. One or two part numbers, not eleven. This single decision halves the logistics problem.
- Require battery voltage as a monitored point on every device, trended and alarmed on a rising-risk threshold, not on flat. You want to batch replacements, not chase failures.
- Plan campaign replacement, not reactive replacement. Replace a whole floor or zone in one access event on a planned cycle. Reactive single-device visits are where the money disappears. This belongs in the PPM schedule, not in the reactive queue: see BMS maintenance, servicing and lifecycle.
- Record every device location properly at install, including the access method and any permit needed. A sensor you cannot find is a sensor you will eventually abandon.
- Put the replacement cost in the business case as an annual operating line over the full appraisal period. If wireless only wins because you excluded this, it does not actually win.
Energy harvesting changes this calculation genuinely, and it is the strongest single argument for EnOcean-class devices in an occupied retrofit. A solar-harvesting room sensor in a daylit office, or a kinetic wall switch, has no recurring access task at all, which is worth more over fifteen years than the hardware price difference. The caveat is honest: harvesting needs an energy source, so a windowless store, a dark riser or an internal plant room is not a harvesting location, and thermal harvesting needs a real and sustained temperature differential. Harvesting solves the battery problem exactly where the physics allows, and nowhere else.
6. The hybrid pattern: wireless sensing, wired control
After enough retrofit scopes, the same architecture keeps emerging as the right answer, and it is a hybrid rather than a position.
Sense wirelessly. Actuate by wire. Sensing is a good fit for wireless: the device is low power, the data is small, an occasional missed reading is tolerable because the next one is minutes away, and the locations are exactly the awkward ones that make cabling expensive. Actuation is a bad fit: the actuator needs power anyway, the command must arrive, and the consequence of a stuck valve or damper is comfort loss, energy waste or plant damage. Since the power cable is going to the actuator regardless, the control signal should ride the same route.
In practice this means the plant room, the risers and the primary distribution stay conventionally wired and conventionally engineered, with a proper points list, and the wireless layer sits out in the occupied space where the access cost is real. That keeps the reliability where reliability matters and the flexibility where flexibility matters. The discipline of the points list does not relax because devices are wireless: see BMS controls, points lists and field devices for the structure, and add signal quality, battery state and last-seen timestamp as points in their own right.
A second element of the hybrid worth naming: wireless does not have to report into the BMS at all. A LoRaWAN sub-metering and environmental overlay reporting into an independent analytics or monitoring platform, alongside an untouched legacy BMS, is a legitimate and often faster architecture. It gives you visibility without touching a controls system you may not want to disturb, and it can be procured and delivered without a controls shutdown. That overlay pattern connects directly to real-time smart building monitoring and to the analytics layer described in from BMS to building analytics.
One boundary to keep clear: this article is about building services and controls. Condition monitoring of rotating equipment, where vibration and oil analysis predict bearing and mechanical failure, is a related but separate discipline with its own sensor economics, covered in IoT sensors for predictive maintenance. Do not let a chiller vibration pilot and a floor comfort overlay be sold to you as the same project; they have different payback logic and different owners.
7. Retrofit strategies, and when each one is right
There are four credible ways to approach a controls retrofit in an occupied building, plus the option of doing nothing yet. They are not ranked. They suit different constraints, and the honest skill is matching the strategy to the building rather than defaulting to the largest scope the budget will carry.
| Strategy | What you actually do | Disruption | Relative cost | Best when | The catch |
|---|---|---|---|---|---|
| Sensing-only overlay | Add wireless sensing and sub-metering with no change to control. Measure comfort, occupancy, temperatures, energy, run hours | Very low. Largely daytime work, minimal permits | Lowest | You do not yet know what the building is really doing, or the business case rests on unmeasured assumptions | It changes nothing on its own. It buys evidence, not performance, and needs a follow-on decision to realise value |
| Head-end replacement first | Replace the supervisory layer, graphics, trending, alarms and integration, keeping existing field controllers and devices via BACnet, Modbus or gateways | Low to moderate. Concentrated in plant rooms and comms rooms | Moderate | Field layer is sound but the head-end is obsolete, unsupported or unusable | You inherit the existing field layer's limitations and its bad point naming; gateway integration can be slower and less complete than promised |
| Zone-by-zone rolling upgrade | Replace controls a floor, wing or plant group at a time, running old and new in parallel behind one head-end | Moderate, but contained and schedulable around occupancy | Higher total, spread over years | Occupied building with rolling vacancy, lease events or phased refurbishment to work around | Long period of dual-system operation, dual spares, dual skills and integration seams; needs sustained multi-year ownership to finish |
| Full replacement | Strip and replace head-end, controllers and field devices as one project | High. Needs shutdowns and significant out-of-hours access | Highest | Major refurbishment, decant or change of use is happening anyway, so access is free | Only affordable when the access is paid for by another project. Rarely justifiable on controls benefit alone in an occupied building |
| Targeted remediation | Fix the specific known faults: failed sensors, seized valves, broken schedules, defeated interlocks, bad setpoints | Low | Low | Overlay or survey shows the existing system is capable but broken or badly configured | Unglamorous, so it is often skipped in favour of new kit. Frequently delivers more per dirham than any upgrade |
The sequence I would advise for most occupied buildings: sensing-only overlay, then targeted remediation on what the overlay exposes, then head-end replacement if the supervisory layer is genuinely the bottleneck, then zone-by-zone only where the field layer is proven inadequate. Full replacement is a decision made by the refurbishment programme, not by the controls strategy.
8. Specifying a wireless retrofit without being locked in
The commercial risk in wireless retrofit is different from wired. A wired BACnet field layer is reasonably portable between head-ends. A proprietary radio field layer may not be, and that matters over a twenty-year asset life. Things worth writing into the specification:
- Gateway output must be open. Whatever the radio is, require that the gateway presents data as BACnet/IP, Modbus TCP, MQTT or a documented REST API, so a future head-end change does not orphan the field devices.
- No cloud dependency for local control. If a comfort or plant function stops working when the internet link drops, that is a design defect, not a feature. Local control must survive loss of WAN.
- Device data ownership and export. Specify that historical trend data is exportable in a documented format without vendor involvement or additional licence.
- Named spectrum and duty cycle. Require the frequency band, the transmit power and the reporting interval to be stated, so you can assess coexistence with existing systems and with the neighbours.
- A witnessed RF survey under occupancy, with signal margin recorded per device, as a hold point before full rollout. Not a desktop prediction, and not an empty-floor walk test.
- Security posture stated explicitly: encryption at the radio layer, device join and provisioning process, key management, firmware update mechanism and its authentication. A wireless field layer widens the attack surface of the building, and the questions to ask are in BMS cybersecurity for connected buildings.
- Spares, tools and training available to the client or a third party, not only to the installing contractor. If only one company can commission a replacement sensor, you do not own the system.
9. Commissioning a retrofit when the documentation is wrong
Here is the reality of most occupied buildings over fifteen years old: the as-installed drawings do not describe the plant that exists. Valves have been changed, indexes renumbered, zones re-partitioned after fit-outs, dampers wired shut, interlocks defeated during a long-forgotten fault, schedules edited by someone who has left, and sensors replaced with whatever was in the van. The BMS graphics show a building that was decommissioned conceptually years ago.
That means retrofit commissioning has a step that new-build does not: establishing the truth before you design against it. What I would build into the programme as its own funded activity, not an assumption:
- Physical asset verification. Walk the plant and record what is actually installed, with photographs, nameplate data and asset IDs. This is the same exercise as building an accurate asset register, and it pays for itself several times over across the rest of the project.
- Point-by-point proving of the existing system. For every existing point you intend to reuse, force it and observe the physical result. A point that reads plausibly is not a point that works. Expect a meaningful proportion of existing points to be dead, stuck, reading a different device than labelled, or disconnected entirely.
- Sensor verification against a calibrated reference. Room and duct sensors drift and are frequently in the wrong place: above a photocopier, in a sun patch, behind a cupboard. A sensor in the wrong location produces a control problem no amount of tuning will fix.
- Sequence archaeology. Read out and document what the existing controllers are actually programmed to do, then compare with the design intent. The gap between the two is usually where the energy waste lives.
- Access and permit register per device. Record how each location is reached, what permit it needs, and whether it is out-of-hours only. This is what makes future battery campaigns and maintenance plannable instead of exploratory.
- Seasonal commissioning. A retrofit commissioned in one season has only been proven in that season. Heating sequences commissioned in summer, and cooling sequences in winter, will be proven by complaints instead. Hold a portion of the commissioning scope and fee for the opposite season and say so in the contract.
For the energy and metering side of the same verification exercise, and how measurement feeds into a sustained reduction programme rather than a one-off report, see energy management systems for buildings.
10. The honest recommendation: buy measurement before you buy control
Now the uncomfortable part. Most retrofit controls business cases I am asked to review are built on assumptions about a building nobody has measured. The savings model assumes occupancy patterns that were estimated, run hours that were quoted from a schedule rather than observed, overcooling that is believed rather than logged, and a plant efficiency that comes from a nameplate. The case is internally consistent and externally unverified, and it is presented with a payback period to two decimal places.
A sensing-only overlay is usually the best first spend for exactly this reason. It is the cheapest strategy, the least disruptive, the fastest to deliver, and it is the only one that replaces assumptions with evidence. Put wireless sensing and sub-metering into a building for one full seasonal cycle and you typically discover several things that change the scope you were about to buy: plant running when the building is empty, zones fighting each other, a floor that has been overcooled for years because one sensor is badly placed, spaces occupied at a fraction of their design assumption, and a handful of simple schedule and setpoint faults that cost nothing to fix.
None of that requires new controllers. Some of it requires nothing more than a corrected schedule. And the parts that genuinely do need a controls upgrade are now specified against measured behaviour rather than against a spreadsheet, which is the difference between a business case that survives post-occupancy scrutiny and one that quietly is not revisited.
What an overlay-first phase should commit to
A defined measurement period covering at least one heating and one cooling season, a fixed list of questions the overlay exists to answer, a named owner who will act on the findings, and a pre-agreed decision point at the end where the full retrofit scope is either confirmed, reduced or dropped. An overlay without a decision point is just more dashboards, and the site will be paying for batteries in it for a decade.
Where overlay-first is the wrong advice
If the existing head-end is genuinely unsupported and you cannot get a trend, an alarm or a spare controller, measuring for a year is a delay you cannot afford. If a refurbishment or decant is already programmed, the access is paid for and waiting means losing it, possibly for fifteen years. And if the plant is at genuine end of life, no amount of measurement changes the answer. Overlay-first is a way to spend well under uncertainty, not a reason to defer a decision that is already clear.
11. The idea to walk away with
Retrofit controls is a logistics discipline more than an engineering one. The design that wins is the one that minimises access events in an occupied building, and that is the honest reason wireless matters: not because the radio is clever, but because a device you can mount in twenty minutes without a permit, a ladder crew and a night shift costs a fraction of the same device on a cable.
Use that advantage where it is real and do not pretend it extends further than it does. Sense wirelessly, actuate by wire. Prefer sub-GHz and energy harvesting in occupied space because they survive real buildings and real maintenance budgets. Put battery replacement in the business case as an annual operating cost, because at portfolio scale it is one. Insist on an open gateway so the field layer outlives the head-end. Verify the plant before you design against the drawings. And spend on measurement before you spend on control, because the most expensive line in any retrofit is the work you did to fix a problem the building did not actually have.
Final thoughts
Wireless building controls have matured to the point where a sensing overlay on an occupied building is a low-risk, well-understood piece of work with a credible supply chain behind it. That is a genuine change from ten years ago and it is worth using. What has not changed is the harder part: knowing which zones matter, which plant is actually misbehaving, which points can be trusted, and which of the savings in the model are real. Wireless makes the measurement affordable. It does not make the judgement for you.
If a controls retrofit is on your capital plan, the most useful thing you can do before committing is small: instrument the building, watch it through a full seasonal cycle, fix what turns out to be simply broken, and let the measured behaviour write the scope. The retrofit that follows will be smaller, cheaper and defensible, which in an occupied building is the only kind worth starting.
Disclosure
Alongside advisory work I also build a CMMS and CAFM platform, so I have a commercial interest in this category. Nothing above is a recommendation for it, and no vendor named here has paid for inclusion or had any editorial input. Weigh the analysis accordingly.
Planning a controls retrofit in an occupied building?
Independent advice on retrofit strategy, wireless versus wired scoping, sensing overlays, open gateway specification and commissioning where the existing documentation cannot be trusted. 22+ years across BMS, CAFM, CMMS and EAM implementations. No controls vendor margins, no reseller arrangements.
Book a conversationRelated reading: Building management systems: a complete guide, BMS controls, points lists and field devices, IoT and BMS integration, BMS maintenance, servicing and lifecycle, Energy management systems for buildings, BMS cybersecurity for connected buildings.
Muhammad Abbas
CMMS / CAFM Manager & Independent Advisor · 22+ years across enterprise CMMS, EAM, CAFM and ERP implementations in utilities, oil and gas, manufacturing, government and facility operations.
Work with me