In a capacity review meeting, two things tend to occupy the room simultaneously: the line efficiency curve generated by the model, and the silence of the shift supervisor who actually runs that line. The model indicates that the second station constrains throughput and that an additional unit, once commissioned, would lift output by a defined margin, while on the floor a portion of that station has been bypassed for months, the genuine constraint having migrated to the feed line of the third station. Nobody in the meeting says anything untrue; the model computes correctly against its own inputs, the supervisor behaves correctly against his own observation, yet the two are no longer describing the same facility. What is notable about this configuration is that the separation did not occur during a crisis, but during an ordinary quarter in which nothing happened.
The same pattern deepens precisely because each of the individual decisions producing the separation was reasonable in its own context. A pump is substituted with an equivalent unit owing to a supply delay, and the substitution is properly logged in the maintenance management system; a setpoint is shifted to close out a quality complaint, and the shift is entered in the log book; a temporary fixture, fabricated for a three-week campaign, remains in place for two years. Every one of these records exists somewhere, yet none of them exists on the data path feeding the model. The change itself has been documented; what has not been documented is the change's counterpart inside the model. Searching for an institutional omission to attribute is unproductive at this point, since what is missing is not one person's attention but the connective tissue between two record systems.
The accumulation has a name — digital-twin drift, the progressive departure of a digital model from the current state of the physical system it represents — and its mechanism is essentially an asymmetry of cost. Executing a modification on the floor is inexpensive, fast and in most cases authorised at shift level, whereas reflecting that same modification in the model is expensive, requiring engineering hours, change approval, version control and revalidation. To the extent that the differential between these two costs approaches an order of magnitude, the system will predictably perform only the cheap half. Drift is therefore not an indicator of indiscipline but the direct output of the incentive structure surrounding it.
That the model is frozen is, moreover, not a defect introduced at the margin but a design necessity. A digital twin becomes computable, and therefore capable of supporting decisions, only because it abstracts away from reality to a defined degree, holding certain variables fixed; a model that internalised every micro-change the instant it occurred would forfeit its computability and, with it, its function. Zero drift is accordingly neither achievable nor desirable. The quantity requiring management is not the existence of drift but **the ratio of drift velocity to the decision cycle**: the model remains functional so long as it holds validity across the effective horizon of the decision taken on its basis, and beyond that accumulation it ceases to be decision support and becomes decision noise.
The threshold at which drift turns institutionally dangerous is the point where the accuracy curve and the authority curve begin travelling in opposite directions. Once the model is in service, the number of decisions resting on it grows over time — planning, maintenance, energy optimisation and investment justification are connected to the same source in sequence — while each new connection reduces the number of people deciding on the basis of direct observation. The more heavily the model is used, the fewer individuals remain positioned to notice that it might be wrong. Meanwhile a parallel mental model develops on the floor, unwritten and transmitted verbally from shift to shift, and the organisation's operation under two competing definitions of reality troubles no one until the person carrying that parallel model resigns.
The cost surfaces first not on the balance sheet but in spare parts inventory and in the planned maintenance window. When the wear profile the model anticipates separates from the profile of the equipment actually running, critical spares accumulate in a line item beyond requirement while a genuinely needed item runs short; the maintenance window, opened earlier than warranted, produces lost production, and opened later than warranted, produces breakdown-driven downtime. Both items are typically classified as operational variance and never traced to root cause, although a visible deceleration in the working capital cycle may well constitute the first numerical signature of drift. More explanatory than the inventory line itself is the question of why that line has failed to improve relative to its position a year earlier.
The second surface is contractual and considerably harder. In structures carrying a performance guarantee — an output undertaking on a production line, an energy consumption guarantee on a facility, a PUE commitment on a data centre — the reference against which the guarantee is measured is frequently the condition the model describes rather than the as-built condition of the plant. Drift opens a direct line of defence for the counterparty in any guarantee dispute, since the assertion that the configuration underpinning the undertaking was not maintained becomes technically demonstrable. The same logic operates on the insurance side, where post-loss investigation places the distance between the risk definition on which the policy rests and the plant as it exists at the centre of the settlement negotiation. It would be reasonable to observe that the gap between the as-built documentation in the EPC handover package and the operating reality two years later forms the common ground of both exposures.
The third surface is valuation, and it is the last to be recognised. In transactions where an asset or a facility changes hands, technical due diligence increasingly examines the model itself as an asset line item; the question asked is no longer whether a digital twin exists, but when and against which event it was last reconciled. Where no reconciliation record exists, buyer behaviour typically shapes itself not toward reducing the headline price but toward deferring the risk beyond closing: as-built verification is imposed as a condition precedent, the representation and warranty perimeter is widened to encompass technical documentation, and the escrow ratio is drawn upward. The result, from the seller's perspective, is a loss measured not in price but in **the timetable of access to cash**. Drift consequently presents as an engineering matter for a long period and closes as a cost-of-capital matter.
The mechanism governing drift is constructed through institutional architecture rather than individual diligence, and it separates into four components. The first is the trigger for the record: the change entry is captured not at the moment of documentation but **at the moment of physical intervention**, embedded in the work order closure of the crew performing it, with a distinct field left open for whether the change has been carried into the model, and the work order not closing until that field does. The second is the reconciliation rhythm: a calendar-bound annual review is too infrequent to catch drift, so reconciliation is bound to events instead — every capacity investment, every major maintenance outage and every contract renewal constitutes a reconciliation gate. The third is ownership: the model is defined not as a system sitting beneath the information technology function but as the asset of an operations role holding both a budget and decision authority. The fourth is measurement: the residual gap between predicted and measured values is tracked not as a standalone performance indicator but as a trend over time, the direction of the trend carrying more information than its level.
BEIREK's intervention in this problem begins by establishing model accuracy as a governance item rather than an engineering objective. On the capital-intensive projects we manage, as-built reconciliation constitutes a distinct gate within the commissioning protocol, and handover is completed not by punch list closure but by documenting and accepting the difference between model and plant; the accepted difference need not be zero, but it must be on record. During the operating phase we embed the change record within the work order system, make transfer to the model a closure condition, and tie reconciliation gates to the prerequisite of every capex file travelling to the investment committee — at a facility where model and plant disagree, keeping a new investment request off the committee agenda is immeasurably cheaper than correcting it once it has been tabled. We connect the same record to reporting discipline on the financing side, since demonstrating that the facility seen by the lender and the guarantor is the facility the operator runs costs less than any explanation offered afterwards.
A facility's digital twin is closest to reality on the day it is commissioned and moves only away from it thereafter; the question worth asking is not whether the model is correct, but for how long and since which event it has gone unverified. In organisations where that answer can be given as a date, drift is a manageable quantity; in organisations where the answer takes the form of "it updates continuously," it is an unmeasured liability.
