All insights

AI Tenders

RFP Annexure: Security and Audit Requirements

· 9 minute read

A security annexure that says 'ISO 27001 and best practices' cannot be marked. These rows make RBAC, logs, keys, egress, patch windows and CERT-In reporting failable.

An NIC-room review in a hill-state SDC asked the bidder where the key that wrapped the volume lived. The technical bid said keys are managed as per industry standard. The certificate on the wall said ISO 27001. Nobody in the room could say which HSM, which officer held the escrow, or what happened if the vendor engineer left with a laptop that had mounted the volume last Thursday. The review ended without a go-live. The annexure had been one paragraph long.

This is a paste-ready security and audit annexure for an agent RFP or a GeM ATC. It is not a complete ISMS. It is not a CERT-In accreditation. It is the minimum set of rows that let a CISO, a DPO and a technical evaluator fail a bid that only brought a certificate.

CERT-In's 28 April 2022 directions already speak to logs, clocks, and incident reporting clocks for covered entities. DPDP will speak to security safeguards as it commences. CAG will later ask whether expenditure produced a reconstructable system. Write the rows so those three conversations have artefacts.

Not a security certification and not legal advice. Fit the rows to your classification, your SOC, and counsel.

How to use the rows without writing a brand

Mark each row mandatory or scored. Mandatory should be binary and rare: no undeclared egress, keys in department custody, logs land in your store, CERT-In-relevant reporting support. Scored rows can allow different mechanisms (HSM versus locked offline keys, your SIEM versus an SDC SIEM you already own).

Do not name a SIEM brand, a PAM brand, or a particular CVE scanner unless you have a PAC-quality reason. Name the artefact.

Paste into the RFP as Annex S. 'Attach' means a document, not a paragraph in the technical bid.
RowArtefactFail if
RBAC: least privilege, named roles, no shared admin, SSO to department IdP if one existsRole matrix + screenshot of SSO or a local equivalent with joiners/leavers SOPA single vendor superuser, or 'we will configure later'
Logs: who, tool, data class, why, approval, output, override — immutable, 180 days in IndiaLog schema + landing zone in department/SDC SIEMLogs only in the product UI or only on a vendor host abroad
Key custody: department holds wrapping keys or HSM partitions; vendor break-glass is dual-control and recordedKey ceremony SOP + escrow namesVendor holds the only copy, or keys in a foreign KMS with no split
Egress: default deny; Schedule A empty or named; changes through department CABSchedule A + staging pcap'As required for the service'
Vulnerability window: named SLA to patch critical issues; air-gap media path for patchesPatch SLA + media SOPPatches only via a standing tunnel
CERT-In reporting: vendor notifies the department in time for the department to meet the CERT-In clock; evidence preservedIncident exhibit + notification clock in the MSAVendor reports 'as soon as practicable' with no clock

RBAC is not a dropdown

An agent has more identities than a web app. There is the officer, the approver, the service account that calls the MIS, the model runtime, the retrieval job, the vendor support user, and the evaluation user. Each needs a role. Shared 'admin@vendor' is a finding, not a convenience.

Joiners and leavers must work on the department's clock. If a deputy secretary is transferred, their right to approve an agent draft must die the same day as their file rights. Write that to the IdP, not to a vendor ticket.

The minimum trail — point at the governance piece

The companion article on audit trails in this batch states the minimum fields: who, what tool, what data class, why, approval, output, override. This annexure is where those fields become a contractual landing zone. If the product cannot emit them, it is non-responsive on this annexure even if the demo was charming.

Retention: at least the CERT-In 180-day rolling window in Indian jurisdiction, and longer if your retention schedule or a court-facing process needs it. Do not invent a new number because a vendor console defaults to thirty days.

Vulnerability windows and the [air-gap](/blog/patching-an-air-gapped-ai-stack-safely)

A seven-day critical patch SLA is fiction if the only path is a vendor tunnel you have forbidden. Write the media path, the hash, the test on staging, and a longer but honest window. An honest fourteen-day media path beats a fictional twenty-four-hour tunnel.

Ask what the vendor will do if a model-weight or tokenizer CVE arrives. Weights are part of the attack surface. 'The model is just a file' is not a patch plan.

  • Default-deny egress with a written Schedule A.
  • Department-held keys or partitions.
  • Logs in your SIEM, schema attached.
  • Incident clock that leaves the department time to report.
  • Patch path that matches the isolation claim.

Objections you will hear — and what to do with them

These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.

This annexure will scare away bidders.

It will scare away bidders who cannot land logs or surrender keys. That is the point. A larger field of certificate-only bidders is not a better field.

We already have an organisation-wide security schedule.

Keep it. Add the agent-specific rows: tool calls, model hash, retrieval data class, override, isolation pcap. Generic schedules were written for web apps and leased lines. Agents invent new processing.

CERT-In reporting is our duty, not the vendor's.

The duty sits with the covered entity. The vendor still has to notify you in time and preserve evidence. If they do not, you will fail a duty you cannot perform alone.

Key custody will make support impossible.

Support becomes a recorded break-glass, not an unofficial mount. If the vendor's only support model is unilateral key possession, they are not selling an on-prem product.

A twelve-day annexure you can publish

CISO drafts, DPO checks data classes, procurement kills brand names, counsel checks the incident clock.

  1. Day 1–3: inventory identities, keys, log sinks and current CERT-In practice.
  2. Day 4–6: fill the six-row table. Delete any row you will not mark. Do not keep ornamental rows.
  3. Day 7–9: run the rows past a friendly non-incumbent (a sister SDC, not a bidder) and remove exclusive mechanisms.
  4. Day 10–12: paste into the RFP. Brief evaluators on what 'attach' means.

How this shows up in the file

The note says Annex S is mandatory, certificates are not substitutes, and a missing pcap or key ceremony is a fail. It names the department officer who will own the SIEM landing zone and the key escrow.

If those officers do not exist, you are not ready to buy an agent. You are ready to buy a certificate.

This article is informational field guidance for Indian public institutions, not legal, procurement, security-accreditation or engineering advice. Confirm against the current Gazette, GFR, GeM term, CVC instruction, CERT-In direction, DPDP text, departmental manual and your counsel before you file it.

How to put this in the RFP, not the preamble

A P6 Compliance/DPO who searches “security annexure RFP AI” is usually drafting or scoring a bid. “RFP Annexure: Security and Audit Requirements” belongs in eligibility, the evaluation matrix, or a numbered annexure. If it only lives in the covering note, L1 will ignore it.

A security annexure that says 'ISO 27001 and best practices' cannot be marked. These rows make RBAC, logs, keys, egress, patch windows and CERT-In reporting failable. QCBS weights are a choice you must publish before opening. Accuracy is a task plus a dataset, not a slogan. SLAs for agents must name tool-calls, human gates and log export — uptime alone is a hosting metric.

Do not let a vendor write the specification and then bid on it. Record unsolicited proposals. Pay for pilots that touch personal data. Write exit before you write go-live.

  1. Move the control from the preamble into a scored or eligibility row.
  2. Attach a one-page definition (accuracy, SLA, language, data handling).
  3. Require an artefact in the technical bid, not a slide.
  4. Extend the bid date if a corrigendum is material.
  5. Minute the demo on your data, offline if you claimed air-gap.

Close this loop before the next CAB

Put “RFP Annexure: Security and Audit Requirements” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P6 Compliance/DPO, not “the vendor.”

Revisit the item when the model, the GeM term, the region, or the SI changes. “security annexure RFP AI” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.

Questions this usually raises

Is ISO 27001 enough to pass a government AI security annexure?
No. A certificate speaks to a vendor's system. Your annexure must speak to this runtime: keys, egress, log landing, and the CERT-In clock. Ask for artefacts.
How long must we keep agent logs?
CERT-In directions require covered entities to maintain ICT logs for 180 days and keep them available in Indian jurisdiction. Your own retention, litigation holds or sector rules may need longer. Do not keep less than the direction without counsel.
Can the vendor keep a copy of the keys for support?
Prefer department custody with recorded dual-control break-glass. A unilateral vendor copy is not custody. If a split exists, write it.
What is Schedule A?
The numbered list of allowed egress destinations, which may be empty. 'As required for the service' is not a schedule.

Sources