# AI Automation Project RFP Template

Replace bracketed text. Have procurement, security, privacy, legal, data, engineering, product, and affected operational owners review the final RFP for your jurisdiction and risk profile.

## 1. Organization and procurement

- Organization: [name]
- Procurement owner: [name and contact]
- Technical owner: [name and contact]
- Question deadline: [date]
- Proposal deadline: [date]
- Target start and decision dates: [dates]
- Contract form and budget boundary: [details]

## 2. Problem and users

Describe the current workflow, users, baseline, pain, volume, constraints, and measurable desired outcome. State why AI may be relevant while allowing suppliers to propose a simpler alternative.

## 3. Scope and non-goals

List in-scope users, systems, regions, languages, decisions, actions, and data. List explicit non-goals and prohibited autonomous actions.

## 4. Success and acceptance

Define task success, critical failures, evaluation dataset ownership, offline thresholds, pilot outcomes, latency, availability, cost, manual-review effort, and go/no-go gates.

## 5. Data and lifecycle

List sources, owners, sensitivity, consent/legal basis where applicable, location, access, quality limitations, freshness, retention, deletion, export, derived artifacts, and training-use restrictions.

## 6. Security, privacy, and safety

Require a data flow, threat model, identity/authorization design, tenant isolation, encryption, secrets management, logging controls, prompt-injection testing, side-effect approval, vulnerability management, incident notification, subprocessors, regions, and verified deletion.

## 7. Architecture and integration

Describe required systems and interfaces. Ask suppliers to propose replaceable boundaries for models, retrieval, tools, identity, state, evaluation, and observability, with fallback and rollback behavior.

## 8. Evaluation and monitoring

Require versioned datasets, deterministic checks, human review, calibrated model judges where used, failure slices, baseline comparison, CI gates, online sampling, drift monitoring, user feedback, incident regressions, and reproducible reports.

## 9. Delivery and governance

Request named team, allocation, responsibilities, discovery plan, proof of capability, pilot, production readiness, risk/decision log, reporting cadence, change control, incident roles, and stage exit evidence.

## 10. Deliverables and transfer

Define source code, infrastructure/configuration, prompts, schemas, evaluation data/reports, architecture and threat models, runbooks, dashboards, training, pairing, support, acceptance, and internal ownership milestones.

## 11. Commercial, IP, and exit

Request implementation and recurring cost breakdowns, usage assumptions, licenses, subprocessors, IP and data rights, warranties/liability for review, service levels, portability, export format, termination assistance, escrow if applicable, and deletion evidence.

## 12. Supplier response format

Require: executive response; proposed outcome/alternative; assumptions; architecture; data/security; evaluation; delivery plan; named team; relevant evidence; risks; cost; transfer/exit; deviations; and completed scorecard.

## 13. Scoring

Publish weights and critical minimums. Example: problem/product 10%; team 10%; evaluation 15%; security/privacy 15%; architecture/operations 10%; proof 15%; delivery/governance 10%; transfer/exit 5%; commercial 10%. A critical security or data failure is not offset by price.

## 14. Proof-of-capability brief

Give shortlisted suppliers the same controlled task, representative minimized data, time boundary, allowed services, required artifacts, scoring rubric, confidentiality terms, and compensation terms where appropriate.

## 15. Declarations

Require disclosure of models/services, generated proposal content where required by policy, subprocessors, conflicts, security incidents relevant under the procurement rules, accessibility, environmental information requested by policy, and all assumptions or exceptions.

This engineering template is not legal advice and does not replace your organization's procurement documents or applicable law.
