WTWilly Tai
The Minimum Twin · Part 4

What to put in a digital twin tender

If ten lines of data and a browser can carry the monitoring loop, what exactly are you buying when you procure a digital twin? A closing argument for owners, with the clauses I would write.

Willy Tai · Smart Cities · AI · Sustainability · September 2026

This series began with a picture and ended up somewhere less comfortable. Part 1 showed a governed operating loop running in a browser. Part 2 deleted most of the model and the loop kept working. Part 3 rebuilt the building's geometry from one photograph and a table of observed and assumed values. Put those together and a question falls out that I have never seen written into a tender: when an owner buys a digital twin, which part of the money buys the twin, and which part buys polygons?

What this is, honestly. The demo behind this series is synthetic and says so on every page, and the clauses below are my own drafting from delivery experience, offered as a starting point and not as legal or procurement advice. Every estate is different and a good quantity surveyor and a good lawyer will improve on them. What I can stand behind is the argument they encode, because I have watched its absence cost owners real money.

What the industry is now saying out loud

The people who build the most detailed models are arriving at the same conclusion. At a SimBuild 2026 session on the PAE Living Building in Portland, the team described being unable to reach their own building's data after handover, and taking nine months to reverse-engineer what they had designed. Their answer was to write data delivery into the contract, in an open, machine-readable form, or watch the intelligence evaporate at practical completion. That is the conclusion the Gemini Principles reached in 2018 from the policy side: a twin is judged on purpose, trust and function. Fidelity costs money, and the specification should say which decision that money serves.

The three things a monitoring twin owes you

Part 2 reduced the job to three answers: what is broken, what state everything is in, and roughly where it sits. Everything the Estate Twin does to catch a fault, route it through rules, put a model's proposal in front of a named person and log the outcome runs on relationships and telemetry. The stepped wireframe of the Lattice view is enough geometry for all of it. That is the test I would put in front of any twin proposal: which of the three answers does each expensive component improve, and by how much?

What the tender usually buys instead

In my experience, most twin tenders specify a platform, a level of detail for the model, an integration count, and a dashboard. They rarely specify who owns the point schedule, whether the relationships between assets and the spaces they serve exist as data anyone else can read, or what happens to the time series when the contract ends. The vendor is rewarded for polygons and integrations, both of which are countable at handover, and nobody is rewarded for the relationship layer, which is the part that keeps paying for the next fifteen years. The vendor built what the tender asked for, and blaming them for it misreads the incentive.

Five clauses I would write instead

Illustrative drafting only. Adapt these with your own lawyer and quantity surveyor before they go near a real contract.

  1. The owner owns the point schedule and the relationship model. Every asset, the system it belongs to, the signals it produces and the spaces it serves, delivered as machine-readable data in an open format, with stable identifiers, before practical completion.
  2. Time series are exportable in bulk, at any time, without vendor assistance, in a documented format. If the contract ends, the history leaves with the owner.
  3. Fidelity is tied to named decisions. Each level of model detail in the specification names the operational decision it serves. Detail without a decision is optional, and priced separately.
  4. Handover is passed by a test. The operator, without the vendor in the room, must answer the three questions for a scripted fault: what is broken, what state is the rest of the estate in, and where is it. If they cannot, the twin has not been delivered.
  5. Lifecycle obligations are explicit. Firmware support windows, end-of-support dates for every device class, and the procedure for adding an asset without the original integrator, all written down at contract.

Why the timing matters in Singapore

As at August 2026, Green Mark In-Operation certificates run for three years, and since April 2025 the certificate names the stage at which the assessment was made. Buildings caught by the Mandatory Energy Improvement regime must cut EUI by ten percent within three years of submitting their improvement plan, and hold it for a year. Check current BCA guidance before relying on either. Both make the twin's data something the owner will have to show a regulator. The evidence the regulator will ask for comes out of the relationship layer. Nothing in the geometry produces it.

Where this leaves the demo

The Estate Twin on this site was built to make the argument pressable, and each part has said what the demo can and cannot show. The twin is small, its data is synthetic, and its geometry came from a photograph that does not exist. None of that weakens the clauses, because they rest on the loop. The loop is the part I have delivered at estate scale.

The Minimum Twin, Part 4 of 4 · Open the twin · Part 1 · Part 2 · Part 3
References: The Gemini Principles, Centre for Digital Built Britain, 2018 · "You Don't Design Net Zero: You Operate It", SimBuild 2026 session on the PAE Living Building, recording published openly by Onuma Inc
Views are my own, not my employer's.