DMS Support Solicitation Amendment 3 01232026.pdf
PDF 629 KB Posted
- Attached to
- Data Modernization Section Support Federal contract opportunity
- Solicitation number
- 21842
- Issued by
- Federal Deposit Insurance Corporation
About this file
Solicitation Summary: Data Modernization Section (DMS) Support Contract
This is a Request for Proposal (RFP) issued by the Federal Deposit Insurance Corporation (FDIC) for a Data Modernization Section Support Contract. The solicitation number is CORHQ-25-R-0450, with proposals due February 6, 2026 at 12:00 p.m. EST. The contract will be awarded to a single prime contractor on a time-and-materials (T&M) basis with a one-month transition period, 12-month base period, and three optional 12-month periods. Performance will be predominantly off-site at a contractor service location with highly interactive roles potentially required at the FDIC Virginia Square facility in Arlington, VA. The NAICS code is 541519 (Other Professional, Scientific, and Technical Services).
The FDIC seeks a highly skilled, agile team to provide full lifecycle support across four primary areas: (1) Cloud Data Management and Analytics (CDMA) Platform ongoing operations using Azure cloud technologies (Databricks, Synapse, Data Lake, Data Factory, Machine Learning, AI Services, Functions, Container Registry, API Management, GitHub Enterprise, Splunk, and Terraform); (2) AlphaRex modernization and operations, migrating an on-premises NLP/AI tool to Azure cloud; (3) AI enterprise capability operations supporting multiple FDIC enterprise AI solutions; and (4) new DMS initiatives starting January 2027 for data, AI, and advanced security solutions. The estimated effort spans 16,234 to 18,889 hours across the base and option periods depending on work allocation. The contractor must provide resumes and demonstration of key personnel expertise in Microsoft Azure Cloud and Enterprise Data Architecture, Azure Databricks Engineering, and AI Engineering. Award selection will use best-value evaluation with factors weighted in descending order: Oral Presentation (Factor A), Technical and Management Approach (Factor B), Key Personnel (Factor C), Past Performance (Factor D), and Price (Factor E). A Technical Acceptability Matrix review screens for six mandatory constraints, including secure generative AI with RAG capabilities, AI integration with measurable outcomes, NLP production capabilities, active Microsoft Solutions Partner status in Azure, five consecutive years in FedRAMP Azure, and demonstrated use of seven specific Azure services in government environments within the past three years.
View the file
Other files for this federal contract opportunity
Show all 18
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOLICITATION/AWARD
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
1. REQUISITION NUMBER PAGE 1 OF
2. CONTRACT NO. 3. AWARD/EFFECTIVE
DATE
4. ORDER NUMBER 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE
DATE
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME b. CONTACT INFORMATION 8. OFFER DUE DATE/
LOCAL TIME
9. ISSUED BY
13b. N/A
14. METHOD OF SOLICITATION
CODE
15. DELIVER TO 16. ADMINISTERED BY CODE
18a. PAYMENT WILL BE MADE BY CODE17a. CONTRACTOR/
OFFEROR
CODE
FACILITY
CODE
CODE
TELEPHONE NO.
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN
OFFER
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK
BELOW IS CHECKED
RFQ RFP
Price only
SEE ADDENDUM
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QTY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. N/A 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL
SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED
29. AWARD OF CONTRACT: REF.
YOUR OFFER ON SOLICITATION
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH
HEREIN, IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR
30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED
31a. FEDERAL DEPOSIT INSURANCE CORPORATION (SIGNATURE OF CO)
31b. NAME OF CONTRACTING OFFICER (Type or print) 31c. DATE SIGNED
FDIC 3700/55 (3-08)
10. SOCIO-ECONOMIC STATUS
NO
NAICS:
ETHNICITY:
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
OFFER
13a. SUB-CONTRACTING
PERMITTED/APPROVED
YES
SDB
MWOB
SERVICE-DISABLED VETERAN-
OWNED SMALL BUSINESS
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
YES NO
YES NO
27a. SOLICITATION INCLUDES ATTACHMENTS 27b. AWARD INCLUDES ATTACHMENTS
RFI RFP
Best Value
CORHQ-25-R-0450
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QTY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED:
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42a. RECEIVED BY (Print)
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
40. PAID BY
32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f. TELPHONE NUMBER OF AUTHORZED GOVERNMENT REPRESENTATIVE
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
33. SHIP NUMBER 34. VOUCHER NUMBER 35. AMOUNT VERIFIED
CORRECT FOR
PARTIAL FINAL
37. CHECK NUMBER
38. S/R ACCOUNT NO. 39. S/R VOUCHER NUMBER
36. PAYMENT
COMPLETE PARTIAL FINAL
FDIC 3700/55 (3-08)
Section B - Supplies or Services and Prices/Costs
CLIN # Description Quantity Unit Unit Price Total Price
0001 New contract for Data Modernization
Section (DMS) Support - CDOS
1 EA
No attachments were added for this section.
Section B - Supplies or Services and Prices/Costs PAGE 3 OF 54
Section C - Description/Specifications/Work Statement
Attachments for this section start after this page.
Section C - Description/Specifications/Work Statement PAGE 4 OF 54
Federal Deposit Insurance Corporation
NONPUBLIC//FDIC INTERNAL ONLY
Data Modernization Section (DMS) Support Contract Statement of Objectives (SOO)
1. Introduction The Federal Deposit Insurance Corporation (FDIC) Chief Data Officer Staff (CDOS) leads the vision, design, development, and transformation of FDIC’s Data Strategy from a culture of silo data management and governance to one where FDIC’s data becomes an enterprise resource. CDOS is establishing FDIC’s data-driven culture across the Corporation, where trusted data are securely shared, and used to support FDIC’s mission of maintaining stability and confidence in the nation’s financial system.
The Data Modernization Section (DMS) reports to the Chief Data Officer (CDO) and provides the Corporation with modern, cloud-based, secure, and operational advanced data analytic, enterprise data management, and artificial intelligence (AI) capabilities and services to facilitate FDIC’s data-driven mission delivery modernization objectives.
DMS is a new section within the Chief Information Officer Organization (CIOO) / Chief Data Officer Staff (CDOS) organization. DMS is seeking a contractor that can provide highly skilled, agile teams to support multiple simultaneous initiatives and ongoing operations (full lifecycle from new development to production operations as defined in the scope section).
The contractor must work with other FDIC contractors and work with multiple groups and organizations across the FDIC (such as Security, Privacy, infrastructure, Enterprise Architecture, CIO organizations, and FDIC business divisions and offices). The teams will follow agile principles in performing the work. Expertise using and administering key cloud-based technology is required (listed in the scope section).
There are four areas that require support under this contract.
1. CDMA Platform. DMS created FDIC’s Cloud Data Management and Analytics (CDMA) Platform in FDIC’s Azure environment. CDMA includes a suite of Azure cloud technologies that collectively provide the FDIC with enterprise data management and enterprise AI / advanced analytic capabilities. CDMA technology supports modern enterprise data management (Lake House), self-service business data management, advanced data analytics, and enterprise AI and MLOps. Ongoing full lifecycle support is required for the CDMA Platform technology, business adoption support, and continuous modernization. CDMA has 25 FDIC business initiatives using the CDMA platform and approximately 30 TB data has been migrated from on-premises to CDMA Lake House.
2. AlphaRex. DMS, working with FDIC’s Risk Management Supervision (RMS) Division, created an on-premises analytic tool that utilizes NLP and AI to analyze FDIC’s Report of Examination (ROE), Examiners Work Papers, examination documents and examination meta data. This solution was first created in 2016, and it is being modernized to take advantage of new, modern cloud technologies available using the CDMA Platform. Rebuilding and maintaining the Alpharex on the CDMA platform is the main task of this area.
3. AI enterprise capability operations. Includes providing operational support for AI
Section C - Description/Specifications/Work Statement PAGE 5 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
capabilities created by the FDIC AI Program Innovation team. It is anticipated that several FDIC enterprise AI solutions will be created that require support. For example, an Enterprise AI solution in FDIC’s Azure is being created. This solution will require operations support of FDIC’s configuration in FDIC Azure using Azure AI services.
Flexibility is required to support this work area since FDIC has a multi-cloud environment and in the future there might be Enterprise AI solutions created using AI technology that is part of Appian, ServiceNOW, SalesForce, cloud.gov, or Azure. The requirement will be to onboard the appropriate resources based on the technology utilized to create the enterprise AI capability.
4. New DMS initiatives. Option starting January 2027. Full lifecycle support for new initiatives. New requirements to create data, AI, and advanced data security solutions are anticipated starting in 2027. This work is required to support the Corporation and create modern, cloud-based, secure, and operational advanced data analytic, enterprise data management, and artificial intelligence (AI) capabilities to facilitate FDIC’s data-driven mission delivery modernization objectives.
The aforementioned areas are critical to establishing FDIC’s data-driven culture and modernizing FDIC’s data capabilities across the enterprise.
2. Scope Scope includes providing full spectrum of analysis, development, deployment and operations of FDIC’s data-related emerging technologies including IT modernization, data management and analytics. Scope includes full lifecycle support for CDMA Platform, modernization of legacy AlphaRex NLP solution, enterprise AI capability operations, and full lifecycle support for new DMS solution development initiatives (experimentation / ideation to production).
1. CDMA scope includes ongoing full lifecycle support for the CDMA Platform technology, FDIC business adoption support (business initiatives using the platform), and continuous modernization of the platform. Implementing advanced data security capabilities (including enterprise data labeling), multi-cloud and on-premises data fabric architecture, ongoing maturation of the CDMA platform, ongoing maturation of the Lake House for enterprise data management, ongoing improvements to automated management of the platform infrastructure via Terraform Infrastructure as Code (IaC), and business self-service capability improvements. Scope includes key technology: Azure Databricks, Azure Synapse, Azure Data Lake, Azure Data Factory, Azure Machine Learning, Azure AI Services (aka collection of Azure cognitive services
– including Azure Open AI), Azure Cosmos DB, Azure App Services, Azure Functions, Azure Container Registry, Azure API Management, GitHub Enterprise, Splunk, and Terraform. The CDMA program, led by CDOS, includes establishing and providing ongoing support to the FDIC business Divisions as they adopt this new, strategic, enterprise-wide data management and data analytic foundation capability.
2. AlphaRex scope includes full lifecycle support for the on-premises solution and development / implementation and operations of the new modernized solution that will take advantage of new, modern cloud technologies available using the CDMA Platform. This Task Order also includes support for the FDIC’s on-premises Alpha-Rex solution, the migration of Alpharex to Azure native tools within the CDMA Platform, all operational, maintenance, and enhancement activities post-migration, as well as
Section C - Description/Specifications/Work Statement PAGE 6 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
specialized support for the Enterprise Data Modernization initiative of which the AlphaRex migration is a part of. The contractor shall ensure seamless migration and execution of Alpharex operations in the Azure environment while contributing expertise to the development of enterprise-wide cloud data solutions. This support includes operating the solution that extracts intelligence from unstructured and semi-structured FDIC examination data and includes predictive analytics and trend analysis that provide new insights into FDIC’s Report of Examination (ROE), examination risks, policies, and effectiveness of FDIC’s examination process. Alpha- Rex consists of Python AI and NLP code, extract transform and load (ETL) code, semi-structured, unstructured, and structured data processing code, data management and meta-data management, then landing the extracted and structured data into a persistent structured / semi-structured data store and performing further analytics and data visualization via PowerBI, Tableau and Tableau Server, other visualization tools, and consumption by other tools.
3. AI enterprise capability operations scope includes work to enable business users and initiatives access to the AI capability, enable role-based access, ensure access controls are in place, monitor usage and user feedback of the AI solution, respond to user requests, trouble shoot issues, work with the development team and business representatives as required, and manage the configuration of the AI capability.
Includes providing operational support for AI capabilities created by the FDIC AI Program Innovation team. It is anticipated that several FDIC enterprise AI solutions will be created that require support. Initially, an AI solution leveraging the CDMA Platform will be required.
4. New DMS initiatives scope includes (option starting January 2027) full lifecycle support for new implementation initiatives. New requirements to create data, AI, and advanced data security solutions are anticipated starting in 2027. This work will require supporting business needs. As FDIC modernizes data-driven mission delivery, there will be potential full lifecycle work to create modern, cloud-based, secure, and operational capabilities. The requirement is to provide an agile team with the expertise needed to support work from architecture, infrastructure, development, and production deployment.
3. Objectives The contract will work with FDIC federal staff and other FDIC contractors to support ongoing operations, innovation and maturation of existing capabilities. The contractor will also support s technical, business adoption, process improvement, and modernization through developing new technical solutions and re-usable architecture patterns, new designs, improved processes, and modern approaches to satisfy FDIC’s current and future data and AI related business needs. The contractor will:
3.1 Business Objectives
3.1.1 CDMA
o Support CDOS with achieving applicable FDIC annual Performance Goals (FPGs) related to CDOS business and technical objectives.
Section C - Description/Specifications/Work Statement PAGE 7 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
o Provide ongoing support to the FDIC business divisions and offices with onboarding services as business initiatives move to the cloud and utilize this new, strategic, enterprise data management, data analytic, and AI/ML foundation capability in FDIC Azure.
o Work with FDIC federal staff across the CIOO and Business Divisions and other FDIC contractors to establish (as required) and mature the CDMA Program foundation capabilities in FDIC Azure.
o As needed, conduct proofs of concept and hands-on evaluations of cloud data management and analytics or AI/ML technologies to support the ongoing maturation of the CDMA Platform capabilities.
o Support ongoing collaboration with CIOO and Business Divisions/Offices on the ongoing development, support, maturation, and modernization of CDMA enterprise data management, analytics and AI/ML capabilities.
o Support business adoption of CDMA and as needed, the retirement of on-premises capabilities. Provide expert assistance to the FDIC Divisions to transform traditional data solutions into modern data architectures and technologies in the cloud. Develop data patterns and cloud technology reference models for data solutions, design for a portfolio of business solutions in the cloud to implement connected data intelligence strategy and architectures that align with FDIC Data Strategy, FDIC AI Strategy and target data ecosystem, and support modern data architectures.
o Perform development, operations, enhancement, and FDIC Governance work and ensure compliance and coordination with: Data Action Working Group (DAWG) enterprise data intake, Enterprise Data Council (EDC), FDIC AI Program Governance, Security and Enterprise Architecture Technical Advisory Board (SEATAB), FDIC OCISO Assess & Authorize (A&A) Process, Security Impact Assessment (SIA), and Azure Major Architecture Decision
(AMAD).
o Collaborate with FDIC business stakeholders, CDO, other FDIC Contractors, Enterprise Architecture (EA), Infrastructure, and Security stakeholders as needed to obtain the appropriate necessary approvals and/or authorizations required in support of prioritized FDIC business initiatives that will be utilizing the CDMA foundation in Azure.
o Work with FDIC’s Infrastructure and Operations Services Branch (IOSB), EA, Office of the Chief Information Security Officer (OCISO), and FDIC contractors to support the architecture, design, and implementation, and maturation of the secure, end-to-end CDMA Platform in FDIC’s Azure environment, test and validate the cloud foundation solution and deliver the CDMA foundational components and repeatable architecture patterns that are in scope of the agile work plan and process.
o For each of the CDMA foundational capabilities that are in scope, ensure the architecture options and recommendations provided (using FedRAMP certified services and full-managed or serverless pay-per-use cloud
Section C - Description/Specifications/Work Statement PAGE 8 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
services to reduce FDIC infrastructure and operations costs and leverage secure, certified cloud services) meet FDIC regulatory and business requirements and provide recommendations for the design to be implemented.
o Maintain, create, and update all project artifacts and documentation as appropriate per the implementation and conclusion of the agile sprint activities. This includes, but is not limited to, the Project Plan, Risk Management Plan, Requirements Management Plan, Requirements Baselines, Software Architecture Document, Data Models, Security Documentation (System Security Plan and others), Master Test Plan, and UAT Scripts as examples of documentation.
o Ensure that the respective solution, data, and technology are in-line with the FDIC’s EA standards, technology, access control, and FDIC security/privacy policies and standards.
3.1.2 AlphaRex
• Rebuild and optimize the AlphaRex capability to leverage the services in the CDMA framework as the first project to test and refine the enterprise solution pattern pipeline and process. This objective will require specialized Azure cloud expertise.
• Support the ongoing operations, management, and use of the AlphaRex capability to provide FDIC business with insight into trends, topics, risks and process effectives as required.
• Work with FDIC federal staff (CIOO, CDOS, and Business Divisions) and other FDIC contractors to provide ongoing support and operations of the current Alpha-Rex AI/NLP capability while simultaneously modernizing / rebuilding / improving the capability within the CDMA platform using Azure native technologies, cloud best practices, and AI / ML.
3.1.3 New DMS Initiative
• Support new DMS initiatives as they arise and are approved by FDIC CIOO. Some potential example initiatives may include:
o Support the multi-office Enterprise Data Modernization Section initiative.
o Create enterprise AI Model management implementation o Create an enterprise capability to implement advanced data security o Establishing a enterprise solution pattern pipeline to maximize speed to implementation for recurrent needs and duplicative use cases within the FDIC by building solutions within the CDMA framework to include ML/NLP/AI and other data analytics solutions that can be reused for other similar projects in the future that fit the same technical requirements.
o Map projects to CIOO, FDIC, and federal data, AI, and technology modernization goals and continuously track progress towards them through a set of established KPIs grounded in enterprise data maturity standards and best practices and working with FDIC stakeholders as required to monitor.
Section C - Description/Specifications/Work Statement PAGE 9 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
3.1.4 AI Operations Support
Support business and FDIC use of the AI solution. Provide onboarding and troubleshooting support. Develop applicable ServiceNOW knowledge articles and ‘how to’ instructions.
Enable business users and initiatives access to the AI capability, enable role-based access, ensure access controls are in place, monitor usage and user feedback of the AI solution, respond to user requests, trouble shoot issues, work with the development team and business representatives as required, and manage the configuration of the AI capability.
Provide operational support for AI capabilities created by the FDIC AI Program Innovation team. Support emerging FDIC enterprise, including AI solution(s0 that leverage the CDMA Platform.
3.2 Technical Objectives
3.2.1 CDMA
o Ensure CDMA operational builds are managed and maintained via agile development ceremony using FDIC’s Enterprise GitHub infrastructure code (Terraform).
o Resolve technical issues and recommend an appropriate course of action to ensure the CDMA foundational cloud technical design and implementation meet the FDIC business requirements.
o Implement CDMA foundation solution and ensure that it addresses all aspects of operating the CDMA foundation in FDIC Azure.
o Ensure CDMA builds are tested and validated continuously to meet the relevant business, security, and production requirements.
o Support the full spectrum of CDMA platform operations and maintenance activities, including security and monitoring.
o Support the CDMA Platform modernization and enhancements. Several candidate enhancements include:
o implementing advanced data security (applying AI to identify events such as data spillage and using advanced methods to perform data tokenization and masking).
o Implement a new 'data fabric' data architecture that integrates CDMA Platform with FDIC's multiple cloud and on-premises environments).
o Implement Zero Trust compliance as that matures at FDIC.
o Implement fine-grained access control to unstructured data by applying
ACLs and security groups at the sub-document or chunk level.
o o
3.2.2 AlphaRex
Section C - Description/Specifications/Work Statement PAGE 10 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
o Ensure Alpha-Rex operational builds are managed and maintained via agile development in FDIC’s GitHub) such as requirements, configuration items, work items, bugs, change requests, and infrastructure code via TFS, including the implementation of a change.
o Successfully migrate the Alpharex program from on-premises Python implementation to Azure native tools within the CDMA system, ensuring all functionality is preserved or enhanced while leveraging cloud capabilities, rebuilding the application completely or lifting and optimizing in a way that ensures reusability for other ML/NLP document extraction use cases.
o Ensure Alpha-Rex builds are tested and validated continuously to meet the relevant business, security, and production requirements.
o Enhance NLP capabilities using Azure Cognitive Services to improve unstructured data processing. Develop methodologies for entity recognition and relationship mapping using Azure AI services
3.2.3 New DMS Initiatives
o Support new DMS initiatives as they arise and are approved by FDIC CIOO.
Some potential example initiatives may include:
o Support the multi-office Enterprise Data Modernization initiative by assisting with establishing and supporting a centralized intake process for data analytics / AI projects, facilitating collaboration between key stakeholders across different CIOO functions (architecture, security, data management, etc.).
o Establishing a enterprise solution pattern pipeline to maximize speed to implementation for recurrent needs and duplicative use cases within the FDIC by building solutions within the CDMA framework to include ML/NLP/AI and other data analytics solutions that can be reused for other similar projects in the future that fit the same technical requirements.
o Map projects to CIOO, FDIC, and federal data, AI, and technology modernization goals and continuously track progress towards them through a set of established KPIs grounded in enterprise data maturity standards and best practices and working with FDIC stakeholders as required to monitor.
3.2.4 AI Operations Support
Provide operations support to business initiatives and applications using the AI solution.
Update operations guide as appropriate. Monitor usage and identify adaptive maintenance actions required. Utilize an agile management approach and leverage FDIC GitHub Enterprise for managing work and work products. Follow FDIC’s Change Control Board (CCB) release process for all change requests.
3.3 Security Objectives
o Implement the identified security controls required by FDIC for all aspects
(solution components, cloud services, user authentication) o Ensure that the work performed complies within the stated rules and guidelines of the FDIC IT security and privacy procedures and policies, including but not limited to:
Section C - Description/Specifications/Work Statement PAGE 11 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
1300.4 Acceptable Use Policy (AUP) for FDIC Information
Technology
1300.4 AUP FAQs
1310.3 Information Technology Security Risk Management
Program
1311.1 Measuring and Customizing User Activity on FDIC External
Websites
1360.1 Automated Information Systems (AIS) Security Program
1360.2 FDIC Computer Virus Protection Program
1360.9 Protecting Sensitive Information
1360.10 Corporate Password Standards
1360.12 Reporting Information Security Incidents
1360.16 Mandatory Information Security Awareness Training
1360.17 Information Technology Security Guidance for FDIC
Procurements/Third Party Products
1360.20 Privacy Program
o Provide support as required during FDIC’s Assess & Authorize (A&A) process to address the National Institute of Standards and Technology (NIST) 800-53 controls identified as in-scope of the System Security Plan (SSP) and OMB A-130 for FDIC Authority to Operate (ATO).
o Provide support as required to address security findings and POA&Ms resulting from FDIC’s periodic security assessments by the Chief Information Security Organization (CISO) and FDIC Information Security Managers (ISMs).
o Identify the candidate solution approaches to address security requirements.
o Provide ongoing support as required during FDIC’s annual security assessment requirement.
o Provide support to address any FDIC Azure policy non-compliance (discovered via Azure Policy scans).
o Provide support to ensure that in scope Azure technologies (utilized by CDMA or any CDOS Data Modernization Section initiative) comply with FDIC’s Hardening Guides o Provide support to follow FDIC’s Security Impact Assessment (SIA) process when any new technologies or connections are added to CDMA or CDOS Data Modernization Initiatives.
o In addition to the FDIC security objectives, the security objectives include ensuring that the AI solution limits access to data based on authorization
Section C - Description/Specifications/Work Statement PAGE 12 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
and the configuration of the AI solution prevents FDIC data from leaving FDIC’s environment.
4. Requirements This section contains detailed descriptions of the services required in connection with this effort. Contractors are expected to comply with all requirements as requirements specific to this scope when providing services under this Task Order.
4.1 Planning
o Create plans to mature the operations support provided for the AI solution.
o Perform initial and periodic assessments of existing components and identify gaps and areas for improvements.
o Create plans to complete development, implementation, operation, and production releases of prioritized CDMA foundation components in FDIC Azure.
o Create sprint plans including epics with backlog, success criteria, retrospectives, backlog grooming, daily standups, and show and tell at the end of each sprint.
o Plan for future sprints, manage the established product backlog items (PBIs), and recommend the approach for the sequencing of all scope related activities as appropriate.
o Manage and maintain the project plan and project related activities per the sprint.
o Manage all sprint scope, requirements, code, artifacts, product backlog, bug/fixes, requirements baselines, system features and business rules via FDIC GitHub.
o Manage team and individual project budgets and provide cost projections for ongoing work.
o Identify the appropriate resources needed per the scope and sprint activities defined for development and operations activities.
o Prepare weekly submittal of status reports per the project, including projected/actual cost, current/planned activities, risks and action items.
4.2 Architecture
o Maintain any architectural diagrams of the AI solution o Ensure that each work product includes creating or updating architecture artifacts.
o Ensure that each architecture option is evaluated based on factors such as cost, security, operations, best practices and meeting business requirements and that architecture analysis includes recommendations for FDIC to consider.
Section C - Description/Specifications/Work Statement PAGE 13 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
o Ensure that cloud architecture options presented utilize FedRAMP authorized cloud services that meet FDIC regulatory, security and business requirements. When there is not a FedRAMP authorized cloud services option, then alternative approaches are required. The last resort is to use non-FedRAMP certified cloud services in the solution architecture.
o Ensure the respective solution, data and technology are in-line with the FDIC’s EA standards, technology, access control and FDIC security/privacy policies and standards.
o Ensure each of the prioritized capabilities identified as in-scope of the work plan include architecture implementation options with tradeoff analysis and recommendations.
4.3 Implementation
o Ensure that the AI solution support services are implemented that follow
FDIC’s security and operations guidelines.
o For in-scope and approved work - implement the secure, end-to-end, solution capabilities, validate the solution and iteratively and incrementally deliver working, production solutions.
o Cloud implementation must include creating infrastructure as code with parameters where feasible for maximum flexibility in provisioning the implementation.
o Solution implementation must include API-driven solutions.
o Implementation must utilize FDIC’s CI/CD Pipeline capability (Github
Enterprise).
o Implementation must ensure that it addresses all aspects of operating the solution such as provisioning, leveraging FDIC Service Desk, integration with FDIC Splunk for security logging and monitoring, integration with FDIC ServiceNow for configuration item management, and integration with cost management and enterprise tagging requirements.
o Implementation builds must be tested and validated continuously to meet business, security, and Authority to Operate (ATO) requirements.
o Implement security for all solution aspects (solution components, cloud services, user authentication).
o Manage and maintain all PBIs and bug fixes via GitHub including the implementation of a change to the existing solution.
o Manage change requests via FDIC’s Change Control process using ServiceNOW o Use Terraform (Infrastructure as Code (IaC)) to manage all Azure cloud technology
4.4 Process, Procedures and Governance
o Ensure that production change requests follow FDIC’s Change Control
Section C - Description/Specifications/Work Statement PAGE 14 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
Process (CCB) o Maintain the integrity of the code, data files, and associated documentation at each point of the agile delivery life cycle from analysis through deployment. Include the approved requirements baselines for each sprint release.
o Maintain, create and/or update all project artifacts and documentation per the implementation and conclusion of the sprint’s activities. This includes, but is not limited to, the Project Plan, Risk Management Plan, Requirements Management Plan, Requirements Baselines, Software Architecture Document, Data Models, Security Documentation (System Security Plan and others), Master Test Plan, and UAT Scripts as examples of documentation.
o Collaborate with FDIC business stakeholders, CDO, other FDIC Contractors, Enterprise Architecture, Infrastructure, and Security Stakeholders within the CIOO as needed to obtain the appropriate necessary approvals and/or authorizations required.
4.5 Security
o Ensure compliance with FDIC IT security directives listed in the contract terms o Ensure that work complies within the stated rules and guidelines of the
FDIC IT security procedures and policies.
o Support the identification, assessment and addressing security issues and findings from periodic security assessments by the Office Chief Information Security Organization (OCISO) and FDIC Information Security Managers (ISMs) o Identify the candidate solution approaches to address security requirements.
o Provide ongoing support as required during FDIC’s annual security assessment requirement.
4.6 Contractor Team
o The FDIC requires a contractor to provide support and expertise in these functions. An Agile team will be used for this task order. The Contractor’s team will work with an FDIC product owner to plan and carry out work. The Contractor is responsible for providing a team of business and information technology professionals with appropriate skills and composition to meet the program needs. The team’s skills and composition may evolve over time as program needs mature.
o At any point in time, the Agile team provided by the Contractor shall be scalable and may include personnel involved on a full-time basis, on a part-time basis, or on an as-needed basis. The Contractor must be responsive to and adapt to these needs.
o For each performance period (base and option), the Contractor is
Section C - Description/Specifications/Work Statement PAGE 15 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
responsible for keeping its charges to the FDIC within the period’s ceiling amount – under no circumstances shall the Contractor’s charges to the FDIC exceed a period’s ceiling amount.
o The FDIC expects the contractor’s employees to be professional and productive. The Contracting Officer may require, in writing, that the Contractor remove from work any employee the Contracting Officer deems unprofessional, unproductive, or otherwise objectionable.
o Agile team with expertise in key AI cloud technologies such as Azure Open AI and Azure AI Search.
5. Timing and Deliverables
5.1 Contract Type
The contract type will be time-and-materials (T&M).
5.2 Period of Performance
The period of performance for this Task Order consists of the following:
Base Period: 12 months Option Period 1: 12 months Option Period 2: 12 months Option Period 3: 12 months
5.3 Deliverables
The Deliverables to be provided by Contractor are set forth below. This is not an exhaustive set and is subject to change. The Contractor shall deliver the following to the FDIC Technical Monitor and the FDIC Oversight Manager. Deliverables (will be defined per CLIN and work plan).
Deliverables Description Frequency Acceptanc e Criteria
1. Planning These deliverables include support to plan, determine and manage requirements scope, risks, budget and time using the appropriate FDIC tools or approved tools.
Also, a weekly status report is produced to include the actual and projected cost, accomplishments, risks and planned activities for the subsequent week.
Deveiop roadmap of XYZ on ABC.
Due at the date specified in the Project Work Schedule (PW S).
Approved by the TM
2. Architecture These deliverables include defining and maintaining the solution architecture to the current FDIC enterprise architecture (EA) standards in order to meet the solution objectives. Recommend solution alternatives
Due at the date specified in the PWS.
Approved by the TM
Section C - Description/Specifications/Work Statement PAGE 16 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
Deliverables Description Frequency Acceptanc e Criteria and tradeoffs as needed with respect to cost, risks and benefits in order to allow the business stakeholder(s) to choose the appropriate services that meet their business needs.
3. Implementati on
These deliverables include a spectrum of work required to support the technical implementation of the solution’s sprint delivery and code to meet the stakeholder’s business requirements.
Due at the date specified in the PWS.
Approved by the TM
4. Process, Procedures and Governance
These deliverables include support to improve service delivery, establish and operationalize the solution’s Development and Operations Lifecycle processes (which includes but not limited to, billing, development, requirements management, testing, configura tion management, change management, operation procedures, roles, governance) to support the solution’s implementation
Due at the date specified in the PWS.
Approved by the TM
5. Security These deliverables include support to identify, define and implement the security architecture, roles, compliance with Hardening Guide requirements for each cloud technology, FDIC security best practices and obtain approval for the key artifacts such as (if applicable) Authority To Operate (ATO) and Security Impact Assessment (SIA), from FDIC security, CIO Organization and FDIC business executives
Due at the date specified in the PWS.
Approved by the
TM
6. Other Deliverables and/or Reporting
The deliverables for all CLINs will be agreed upon on an ongoing basis according to agile long and short term planning activities and ceremonies including yearly roadmaps with milestones and quarterly program increments.
As directed by the Oversight Manager
Approved by the OM or TM
6. Key Personnel The following roles are considered key personnel on the Development Tools Task Order:
Microsoft Azure Cloud and Enterprise Data Architect o BA/BS/MS in Computer Science, Engineering, or an equivalent combination of education and/or experience. More than 5 years of experience as a Solution Architect. Minimum 5 years’ experience in other technical roles such as developer or systems analyst. Strong consultative skills at a cross functional
Section C - Description/Specifications/Work Statement PAGE 17 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
level. Good presentation and communication skills with the ability to translate and clearly formulate technical issues. Strong project and team management skills. One or more Microsoft Azure Cloud Certifications.
o Enterprise-scale technical experience with cloud and hybrid infrastructures, enterprise solution architecture designs, data pipeline, cloud and data security, data management, and cloud operations.
o Hands on experience with Azure cloud and data architecture. Experience with both SQL and NoSQL databases. Experience with serverless, container, and pay-per-use cloud services and architectures. Big Data experience with Azure cloud technologies. Advanced Analytics and reporting/dashboarding experience with Azure cloud technologies. Experience with Data Governance, Data Engineering, and Data Science. Machine Learning experience and machine learning operations (MLOps) experience. Expertise with both structured and unstructured data management and analytic technology.
Azure Databricks Engineer o Education and Experience: BA/BS/MS in Computer Science, Engineering, Data
Science, or equivalent experience. Over 5 years of experience as a Data Engineer, with 3+ years specifically in Azure Databricks and related Azure data services.
o Key Skills: Expertise in Apache Spark, Delta Lake, Python, SQL, and Scala.
Hands-on experience designing and optimizing large-scale data pipelines.
o Technical Proficiency: Experience with Azure Data Factory, Azure Data Lake Storage, Azure Synapse Analytics, and other Azure services. Strong understanding of ETL/ELT processes, data modeling, and big data technologies.
o Preferred Qualifications: One relevant certifications like Microsoft Certified:
Azure Data Engineer Associate (DP-203) or Databricks Certified Data Engineer or equivalent certification or experience.
o Professional Attributes: Excellent analytical, problem-solving, and communication skills. Experience with Agile methodology and implementing data governance and security.
o Data Pipeline Development & Management - Design, build, and maintain scalable ETL/ELT pipelines using Databricks workflows, Delta Lake, and Apache Spark to process large volumes of structured and unstructured data o Data Architecture & Optimization - Architect and optimize data lakehouse solutions, implement data modeling best practices, and ensure efficient data storage and retrieval using Delta Lake format and partitioning strategies o Collaborative Analytics Platform Management - Configure and manage Databricks workspaces, clusters, and compute resources while implementing security controls, access management, and cost optimization strategies o Real-time & Batch Processing - Develop streaming data solutions using
Section C - Description/Specifications/Work Statement PAGE 18 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
Structured Streaming and implement batch processing jobs for data transformation, aggregation, and integration across multiple data sources o MLOps & Data Science Support - Collaborate with data scientists to deploy machine learning models, implement MLflow for model lifecycle management, and create automated ML pipelines for training and inference o Performance Monitoring & Troubleshooting - Monitor data pipeline performance, troubleshoot issues, implement data quality checks, and optimize Spark jobs for improved efficiency and reduced processing costs
AI Engineer o Requires three years proficiency in data and AI. Experience providing operational support, experience with CI/CD pipelines and agile work management using technology such as GitHub Enterprise, infrastructure as code (such as Terraform).
o
7. Estimated LCATs and Hours
The hours shown below are the FDIC's estimates of the work that will be required from the Contractor. The Contractor may propose in its pricing workbook using the FDIC estimate, and propose an LCAT mix that the contractor thinks will accomplish the objectives outlined in this document for each program successfully; provided the overall number of hours equals the sum of the hours below for each period.
Estimated Total Hours
Option Period Program Base FTE
Transiti on Period Base
Period 1 2 3
CDMA 160 9975 9975 9975 3507
AlphaRex 160 3360 1695 0 AI Operations 160 2899 2899 2899 2899 DMS Initiative 0 4320 4320 4320 Totals 0 480 16,234 18,889 17,194 10,726
8. Additional Notes Requires operation and usage knowledge of the below list of technologies.
CDMA Platform Technology as of June 2025
Section C - Description/Specifications/Work Statement PAGE 19 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
- Data Lake Gen2
- Azure Databricks*
- Azure Synapse
- Azure Key Vault
- Azure Storage (blob, file, queue, and table)
- Azure Machine Learning
- Azure AI Services (Azure Open AI, AI Search, Content Safety, Document
Intelligence, Language, Speech, and Vision)
- Azure Application Insights
- Azure Functions
- Azure Data Factory
- Azure App Service (Windows and Linux)
- Azure App Service Plan (windows and Linux)
- Azure Container Registry
- Azure API Management
- Azure Cosmos DB
*Azure Databricks (with the Azure Data Lake Gen2) forms the foundation for FDIC’s Lake House capability.
9. Transition Period The Contractor shall propose a comprehensive and detailed Transition Plan that ensures a seamless and efficient transfer of responsibilities and operations from the incumbent or previous arrangements to the Contractor's performance under this Contract. The transition should occur 30 days before the base period of performance to ensure smooth continuity of the work in progress.
The Contractor's proposed Transition Plan should address, at a minimum, the following objectives:
• Maintaining continuity of services throughout the transition period.
• Minimizing disruption to ongoing operations and stakeholders.
• Ensuring timely and effective knowledge transfer from the incumbent or agency personnel to the Contractor's staff.
• Facilitating the orderly transfer of any necessary resources (e.g., personnel, equipment, documentation, data).
• Ensuring compliance with all applicable contractual, regulatory, and security requirements during the transition.
• Establishing clear communication channels and reporting mechanisms throughout the transition period.
The Contractor shall outline key milestones and a realistic timeframe for the transition, demonstrating a well-structured approach to achieve a successful and risk-mitigated handover. The Contractor shall also identify potential risks associated with the transition and propose effective mitigation strategies.
Section C - Description/Specifications/Work Statement PAGE 20 OF 54
Corporation
NONPUBLIC//FDIC INTERNAL ONLY
10. Quality Assurance Surveillance Plan (QASP) Purpose:
This QASP outlines performance objectives, acceptable quality levels (AQLs), and surveillance methods for monitoring Contractor performance under this multi–work stream agile contract. Performance will be tracked at both the overall contract and individual CLIN levels.
Objective Standard AQL Surveillance Method Frequency
• Budget adherence CLIN burn rate within ±5% of plan ≤ 5% variance Financial review Monthly
• Risk mitigation 90% risks mitigated on time ≤ 10% late Risk log review Monthly
• Deliverable acceptance 95% accepted on first submission ≤ 5% rework Acceptance log review Per Deliverable
Surveillance Methods:
• Review of agile metrics (e.g., Jira, Github)
• Deliverable inspection against acceptance criteria
• Financial and burn rate analysis
• Stakeholder feedback during sprint reviews
• Risk and issue tracking review
Section C - Description/Specifications/Work Statement PAGE 21 OF 54
Section H - Special Contract Requirements
Clauses Incorporated By Reference
Clause # Title Date
No reference clauses were found for this section.
Full Text Clauses
7.5.2-03 - Background Investigations - May 2025
a) Any contractor personnel or subcontractor personnel who:
• work on-site at and have unescorted access to FDIC offices or facilities,
• have access to FDIC networks/systems, or
• have access to sensitive information must undergo a background investigation, in accordance with FDIC Directive 1610.02. In addition, background investigations may be conducted on other Contractor Personnel and subcontractor personnel at the discretion of the FDIC. The extent of the background investigation conducted will be in direct relation to the risk level assigned either in clause 7.5.2-08, Risk Level Designation (Functional Responsibility) or in clause 7.5.2-10, Risk Level
Designation (Labor Category). FDIC Directive 1610.02 is available at the FDIC website:
https://www.fdic.gov/buying/goods/acquisition/index.html
b) Prior to obtaining an FDIC identification/access badge and commencing work under the contract, contractor personnel and subcontractor personnel subject to the background investigation requirement are required to undergo both a fingerprint and a credit check, and submit an IRS Tax Compliance Report. In addition, contractor personnel and subcontractor personnel may be subject to a Defense Counterintelligence and Security Agency
(DCSA) background investigation, based on the risk level assigned to the functional responsibilities or to the labor categories. No contractor personnel or subcontractor personnel subject to the background investigation requirement, including any new personnel added at any time during the term of the contract, shall be permitted to begin work until the fingerprint, IRS Tax Compliance Report, and the credit check processes have been completed, FDIC has rendered a favorable preliminary trust determination, and the paperwork for any further DCSA background investigations has been submitted.
c) FDIC’s Enterprise Workforce Solution (eWORKS) is a tool that automates the background investigation process for new applicants and contractors. Via eWORKS, the Contractor must provide the Oversight Manager with the following for all contractor personnel and subcontractor personnel subject to the background investigation requirement:
1) An executed Background Investigation Questionnaire for Contractor Personnel and Subcontractors (FDIC
1600/04);
2) An executed Notice and Authorization Pertaining to Consumer Reports (FDIC 1600/10); and
3) A current (within the last 30 days) IRS Tax Compliance Report.
Section H - Special Contract Requirements PAGE 22 OF 54
For reference, FDIC Forms 1600/04 and 1600/10 are available at the FDIC website:
https://www.fdic.gov/about/doing-business/acquisition/index.html
Contractor personnel and subcontractor personnel who meet the conditions in paragraph (a) above must obtain a copy of their IRS Tax Compliance Report by visiting the IRS webpage, creating an individual online account, and downloading the PDF document. FDIC will provide instructions on how to access the IRS webpage and obtain a
Tax Compliance Report, as well as how to submit the report in eWORKS.
Fingerprinting is required and must be completed at a GSA USAccess Shared Facility, which may include a FDIC
Regional Office, FDIC’s Virginia Square location, or FDIC’s main office in Washington, DC. Additionally, fingerprinting may be completed at a third party FBI approved fingerprint channeler.
In addition, where the assigned risk level of the contract mandates background investigations by the DCSA, the
Contractor must provide the Oversight Manager with the completed paperwork for contractor personnel and subcontractor personnel needed to initiate a DCSA background investigation. The Oversight Manager will notify the
Contractor of the method by which to submit the paperwork.
d) Contractor must comply with Homeland Security Presidential Directive-12 (HSPD-12) and Federal Information
Processing Standard Publication 201 (FIPS 201) entitled “Personal Identification Verification for Federal Employees and Contractors”. Contractor personnel and subcontractor personnel must present two forms of identification in original form prior to badge issuance; at least one document must be a valid State or federal government-issued picture ID. Acceptable forms of identification are listed in Form I-9, OMB No.1615-0047, “Employment Eligibility
Verification.” In addition, contractor personnel and subcontractor personnel must appear in person at least once before an FDIC official who is responsible for checking the identification documents. FDIC will not issue identification/access badges to contractor personnel and subcontractor personnel until proof-of-identity has been established.
e) Any contractor personnel or subcontractor personnel, whose background investigation reveals an adverse finding, may be excluded from working on the contract at the discretion of the Contracting Officer. Contractor is obligated to replace any personnel so excluded with personnel acceptable to FDIC.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .