AI Tenders
RFP Annexure: Security and Audit Requirements
· 9 minute read
A security annexure that says 'ISO 27001 and best practices' cannot be marked. These rows make RBAC, logs, keys, egress, patch windows and CERT-In reporting failable.
An NIC-room review in a hill-state SDC asked the bidder where the key that wrapped the volume lived. The technical bid said keys are managed as per industry standard. The certificate on the wall said ISO 27001. Nobody in the room could say which HSM, which officer held the escrow, or what happened if the vendor engineer left with a laptop that had mounted the volume last Thursday. The review ended without a go-live. The annexure had been one paragraph long.
This is a paste-ready security and audit annexure for an agent RFP or a GeM ATC. It is not a complete ISMS. It is not a CERT-In accreditation. It is the minimum set of rows that let a CISO, a DPO and a technical evaluator fail a bid that only brought a certificate.
CERT-In's 28 April 2022 directions already speak to logs, clocks, and incident reporting clocks for covered entities. DPDP will speak to security safeguards as it commences. CAG will later ask whether expenditure produced a reconstructable system. Write the rows so those three conversations have artefacts.
Not a security certification and not legal advice. Fit the rows to your classification, your SOC, and counsel.
How to use the rows without writing a brand
Mark each row mandatory or scored. Mandatory should be binary and rare: no undeclared egress, keys in department custody, logs land in your store, CERT-In-relevant reporting support. Scored rows can allow different mechanisms (HSM versus locked offline keys, your SIEM versus an SDC SIEM you already own).
Do not name a SIEM brand, a PAM brand, or a particular CVE scanner unless you have a PAC-quality reason. Name the artefact.
| Row | Artefact | Fail if |
|---|---|---|
| RBAC: least privilege, named roles, no shared admin, SSO to department IdP if one exists | Role matrix + screenshot of SSO or a local equivalent with joiners/leavers SOP | A single vendor superuser, or 'we will configure later' |
| Logs: who, tool, data class, why, approval, output, override — immutable, 180 days in India | Log schema + landing zone in department/SDC SIEM | Logs only in the product UI or only on a vendor host abroad |
| Key custody: department holds wrapping keys or HSM partitions; vendor break-glass is dual-control and recorded | Key ceremony SOP + escrow names | Vendor holds the only copy, or keys in a foreign KMS with no split |
| Egress: default deny; Schedule A empty or named; changes through department CAB | Schedule A + staging pcap | 'As required for the service' |
| Vulnerability window: named SLA to patch critical issues; air-gap media path for patches | Patch SLA + media SOP | Patches only via a standing tunnel |
| CERT-In reporting: vendor notifies the department in time for the department to meet the CERT-In clock; evidence preserved | Incident exhibit + notification clock in the MSA | Vendor reports 'as soon as practicable' with no clock |
RBAC is not a dropdown
An agent has more identities than a web app. There is the officer, the approver, the service account that calls the MIS, the model runtime, the retrieval job, the vendor support user, and the evaluation user. Each needs a role. Shared 'admin@vendor' is a finding, not a convenience.
Joiners and leavers must work on the department's clock. If a deputy secretary is transferred, their right to approve an agent draft must die the same day as their file rights. Write that to the IdP, not to a vendor ticket.
The minimum trail — point at the governance piece
The companion article on audit trails in this batch states the minimum fields: who, what tool, what data class, why, approval, output, override. This annexure is where those fields become a contractual landing zone. If the product cannot emit them, it is non-responsive on this annexure even if the demo was charming.
Retention: at least the CERT-In 180-day rolling window in Indian jurisdiction, and longer if your retention schedule or a court-facing process needs it. Do not invent a new number because a vendor console defaults to thirty days.
Vulnerability windows and the [air-gap](/blog/patching-an-air-gapped-ai-stack-safely)
A seven-day critical patch SLA is fiction if the only path is a vendor tunnel you have forbidden. Write the media path, the hash, the test on staging, and a longer but honest window. An honest fourteen-day media path beats a fictional twenty-four-hour tunnel.
Ask what the vendor will do if a model-weight or tokenizer CVE arrives. Weights are part of the attack surface. 'The model is just a file' is not a patch plan.
- Default-deny egress with a written Schedule A.
- Department-held keys or partitions.
- Logs in your SIEM, schema attached.
- Incident clock that leaves the department time to report.
- Patch path that matches the isolation claim.
Objections you will hear — and what to do with them
These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.
This annexure will scare away bidders.
It will scare away bidders who cannot land logs or surrender keys. That is the point. A larger field of certificate-only bidders is not a better field.
We already have an organisation-wide security schedule.
Keep it. Add the agent-specific rows: tool calls, model hash, retrieval data class, override, isolation pcap. Generic schedules were written for web apps and leased lines. Agents invent new processing.
CERT-In reporting is our duty, not the vendor's.
The duty sits with the covered entity. The vendor still has to notify you in time and preserve evidence. If they do not, you will fail a duty you cannot perform alone.
Key custody will make support impossible.
Support becomes a recorded break-glass, not an unofficial mount. If the vendor's only support model is unilateral key possession, they are not selling an on-prem product.
A twelve-day annexure you can publish
CISO drafts, DPO checks data classes, procurement kills brand names, counsel checks the incident clock.
- Day 1–3: inventory identities, keys, log sinks and current CERT-In practice.
- Day 4–6: fill the six-row table. Delete any row you will not mark. Do not keep ornamental rows.
- Day 7–9: run the rows past a friendly non-incumbent (a sister SDC, not a bidder) and remove exclusive mechanisms.
- Day 10–12: paste into the RFP. Brief evaluators on what 'attach' means.
How this shows up in the file
The note says Annex S is mandatory, certificates are not substitutes, and a missing pcap or key ceremony is a fail. It names the department officer who will own the SIEM landing zone and the key escrow.
If those officers do not exist, you are not ready to buy an agent. You are ready to buy a certificate.
This article is informational field guidance for Indian public institutions, not legal, procurement, security-accreditation or engineering advice. Confirm against the current Gazette, GFR, GeM term, CVC instruction, CERT-In direction, DPDP text, departmental manual and your counsel before you file it.
How to put this in the RFP, not the preamble
A P6 Compliance/DPO who searches “security annexure RFP AI” is usually drafting or scoring a bid. “RFP Annexure: Security and Audit Requirements” belongs in eligibility, the evaluation matrix, or a numbered annexure. If it only lives in the covering note, L1 will ignore it.
A security annexure that says 'ISO 27001 and best practices' cannot be marked. These rows make RBAC, logs, keys, egress, patch windows and CERT-In reporting failable. QCBS weights are a choice you must publish before opening. Accuracy is a task plus a dataset, not a slogan. SLAs for agents must name tool-calls, human gates and log export — uptime alone is a hosting metric.
Do not let a vendor write the specification and then bid on it. Record unsolicited proposals. Pay for pilots that touch personal data. Write exit before you write go-live.
- Move the control from the preamble into a scored or eligibility row.
- Attach a one-page definition (accuracy, SLA, language, data handling).
- Require an artefact in the technical bid, not a slide.
- Extend the bid date if a corrigendum is material.
- Minute the demo on your data, offline if you claimed air-gap.
Close this loop before the next CAB
Put “RFP Annexure: Security and Audit Requirements” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P6 Compliance/DPO, not “the vendor.”
Revisit the item when the model, the GeM term, the region, or the SI changes. “security annexure RFP AI” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.
Questions this usually raises
- Is ISO 27001 enough to pass a government AI security annexure?
- No. A certificate speaks to a vendor's system. Your annexure must speak to this runtime: keys, egress, log landing, and the CERT-In clock. Ask for artefacts.
- How long must we keep agent logs?
- CERT-In directions require covered entities to maintain ICT logs for 180 days and keep them available in Indian jurisdiction. Your own retention, litigation holds or sector rules may need longer. Do not keep less than the direction without counsel.
- Can the vendor keep a copy of the keys for support?
- Prefer department custody with recorded dual-control break-glass. A unilateral vendor copy is not custody. If a split exists, write it.
- What is Schedule A?
- The numbered list of allowed egress destinations, which may be empty. 'As required for the service' is not a schedule.