Attachment_4_-_Statement_of_Work_(FINAL).pdf
PDF 273 KB Posted
- Attached to
- SEC Supplemental Retirement Plan (SRP) Federal contract opportunity
- Solicitation number
- 50310219Q0165
- Issued by
- Securities and Exchange Commission
About this file
Statement of Work
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment_00001_to_RFQ.pdf | ||
| Attachment_5_-_RFQ_Past_Performance_Questionnaire.docx | DOCX document | |
| RFQ_Questions_and_Answers.pdf | ||
| 5_Summary_Plan_Overview.pdf | ||
| Article_VIII_of_the_SECâs_Supplemental_Retirement_Plan_(November_11,_2015).pdf | ||
| Attachment_2_-_Non-Disclosure_Agreement_-_Contractor_Personnel.pdf | ||
| Combined_Synopsis_Solicitation_(FINAL).pdf | ||
| Attachment_3-_CLIN_Table_(FINAL).xlsx | XLSX spreadsheet | |
| Attachment_1_-_Non-Disclosure_Agreement_-_Contractor_Entity.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK
SUPPLEMENTAL RETIREMENT PLAN
1. BACKGROUND
The mission of the SEC is to protect investors, maintain fair, orderly, and efficient markets, and facilitate capital formation. The SEC oversees the key participants in the securities industry, including securities exchanges, securities brokers and dealers, and investment advisors.
As part of the SEC's compensation model, it has established a supplemental retirement program in addition to standard federal retirement programs such as the Federal Employees Retirement System (FERS), the Civil Service Retirement System (CSRS), and the Thrift Savings Plan (TSP), for eligible employees. SEC-OHR manages the Plan and currently provides services to approximately 4,600 SEC employees nationwide. Nearly all of the SEC’s employees, who are located in Washington, DC as well as in regional offices throughout the U.S. in nearly every time zone, are Plan participants. A list of SEC locations is available on the SEC’s public website: www.sec.gov. Occasional travel to the SEC’s headquarters in Washington, DC may be required.
2. SCOPE and BUSINESS REQUIREMENTS
2.1 Overview. The information specified in the Scope and Business Requirements section of this Scope of Work are general descriptions of the services the SEC is requesting. Any specific details relating to said services and the roles and responsibilities of the parties will be located in services agreements executed with the Contractor. The provisions of such service agreement(s) will apply where they are consistent with and do not conflict with this Scope and Business Requirements section.
The U.S. Securities and Exchange Commission (“SEC”) is searching for a Contractor (or contractors, see Teaming and Subcontracting, below) that will provide Trustee, Custodian, and Recordkeeper services for eligible SEC employees in a Section 401(a) defined contribution program (referred to herein as the “Plan”). The SEC’s existing contract expires in July 2020. The Contractor selected must be able to begin performance—including completing all transfers of assets and records from the existing contractor—no later than July 1, 2020.
The Plan does not allow for loans, participant contributions, participant selection or direction of investment(s), or annuities. The Plan permits in-service withdrawals of vested amounts as permitted by applicable IRS laws, rules, regulations, and policies (“IRS provisions”). Each in-service withdrawal must be for at least $500. The SEC will pay for two in-service withdrawals for each plan participant per calendar year; a plan participant bears the full cost of excess in-service withdrawals. The Contractor must be able to track the number of in-service withdrawals by each plan participant each calendar year and have a method for charging any excess withdrawal fees to participants (either directly or by charging such amounts to the correct participants’ accounts).
The Trustee is and will continue to be a nondiscretionary (directed) Trustee. All investment decisions are and will be made solely by the SEC. The Plan’s objective does not include maximizing return on principal. The Plan’s objective is to safeguard the principal amount of employer contributions and any increases due to interest (or other applicable) accumulation.
The Plan’s assets currently exceed $80 million, and there are approximately 4,600 Plan participants.
Over the past year, the total biweekly contribution has averaged approximately $850,000 and there have been an average of 100 withdrawals per month. On January 1, 2020, a significant number of vested participants will reach the 5-year Plan participation threshold (thereby gaining the right to withdraw the entire amount held on their behalf regardless of age or how long the money has been on deposit). As a result, beginning in January 2020, the average number of monthly withdrawals may increase, and/or the amounts withdrawn may cause the total assets held to decrease.
The Plan is an independently-designed Plan. The SEC does not anticipate amending the Plan to conform with prototype Plan documents customarily offered by the Contractor (if any). The Contractor must submit as part of its response to this solicitation any service agreement(s) it wants the SEC to consider incorporating into an award.
2.2 Custodial Account Requirements. The successful Contractor for Custodian must be able to hold the existing Plan assets and accept new Plan assets biweekly into a product that is highly secure, either because the assets are (1) FDIC-insured, in which case the Contractor must (i) expressly represent its current eligibility for FDIC insurance, and (ii) be able to comply with the requirements to qualify participants’ accounts for pass-through coverage – see, e.g., 12 CFR 330.5 and 330.14; (2) NCUA Share Insurance-insured, in which case the Contractor must (i) expressly represent its current eligibility for NCUA Share Insurance coverage, (ii) expressly represent that is “well capitalized” or “adequately capitalized” within the meaning of 12 U.S.C. 1790d(c) and 12 CFR 745.9-2, (iii) identify the provision(s) of the Federal Credit Union Act and regulations thereunder that it is relying on to permit a nonmember to maintain an insured interest in the Plan’s assets, and (iv) be able to comply with the requirements to qualify participants’ accounts for pass-through coverage – see, e.g., 12 CFR 745.9-2; or (3) otherwise fully collateralized and/or insured, in which case the Contractor must provide specific and detailed information including the name of the insurance provider, any limits on coverage, the specific asset(s) and valuation methodology(ies) supporting any collateral, the amount of any other assets covered by the same insurance or collateral, and any existing or proposed form(s) of collateral agreement. A Contractor’s response to this solicitation must specify the product(s) meeting these requirements that it proposes to hold the Plan’s assets. If the response identifies more than one possible product, the response must also discuss any key differences between each option, including any cost differences.
2.3 Teaming and Subcontracting. Ideally, one Contractor will provide a single solution that encompasses the entire Trustee, Custodian, and Recordkeeper aspects of administering the Plan. However, to the extent administratively feasible (as determined by the SEC), more than one Contractor may team or subcontract to provide the required services. In this solicitation, the term “Contractor” refers to both (1) each separate entity that proposes to work together to fulfill the SEC’s requirements and (2) to all such Contractors collectively except where the context clearly applies only to one or more specific Contractor. Contractors who choose to team or subcontract must have those arrangements in place prior to responding to this solicitation. If subcontracting is proposed, all labor and materials proposed must be contained within the prime contractor’s contract. Furthermore, the prime contractor must disclose to the SEC’s Contracting Officer a copy of the subcontract pricing, terms and conditions, or subcontracting agreement. The SEC will evaluate the acceptability of any teaming or subcontracting arrangement as part of its evaluation of price.
Failure to provide sufficient supporting documentation may result in no further consideration of an offer.
2.4 Limits on types of Contractor. The Contractor selected to serve as Custodian must not be directly regulated by the SEC, but a Contractor will not be disqualified solely because it is part of a corporate structure that includes one or more entities that are directly regulated by the SEC. The Contractor selected to serve as Custodian must itself be an entity that is directly regulated by the Office of the Comptroller of the Currency, the National Credit Union Administration, the Federal Deposit Insurance Corporation, or other federal or state regulator, and must expressly identify any and all federal or state regulators to which it is subject. Ideally, the Contractor(s) selected to serve as Trustee and/or Recordkeeper will also not be directly regulated by the SEC, but a Contractor that proposes to serve only in one or both of those capacities will not be disqualified solely on that basis.
In addition to offering a fully insured or collateralized vehicle for holding the Plan’s assets as discussed above, each Contractor must be fully insured against any liability it may incur as a result of providing services to the Plan.
2.5 Overview of Key Business Requirements. The Contractor will be required to:
As Trustee:
• Serve as the Plan Trustee in accordance with the requirements of Section 401(a) of the Internal Revenue Code.
• Keep the Plan assets in trust (i.e., exercise fiduciary responsibility).
• Maintain auditable records of all Plan assets and submit to periodic audits as required by law, including as required to enable the SEC to respond to inquiries by Congress, the Government Accountability Office, the Internal Revenue Service, or other similar entities.
• Successfully complete the SEC’s information technology security assessment process. A detailed description of the process is in section 3.5 Security Assessment.
• Fulfill the duties of Trustee as detailed in Article VIII of the SEC’s Supplemental Retirement Plan (November 11, 2015), a copy of which is contained in Appendix I to this Statement of Work.
As Custodian:
• Receive plan assets every two weeks via electronic wire transfer from the SEC’s payroll provider (currently the Department of the Interior/National Business Center).
• Accept discretionary payments the SEC may choose to make, whether through the SEC’s payroll provider or directly from the SEC.
• Provide confirmation of funding for every deposit received. This is currently done with a Funding Confirmation Email sent by the existing Trustee/Custodian.
• Provide reconciliation reports or the ability for the SEC to access such reports on a biweekly basis.
• Receive existing Plan assets from the Plan’s current Trustee/Custodian.
• Hold all Plan assets in an account that (1) meets the requirements for full FDIC insurance or NCUA Share Insurance to “pass through” to each individual Plan participant, and (2) to the extent any amount is not fully FDIC- or NCUA-insured, is otherwise fully insured and/or collateralized in accordance with applicable laws and regulations.
• Disburse Plan assets to Plan participants in strict compliance with instructions from the Recordkeeper, which is in turn required to first ensure that any disbursements are in strict compliance with applicable IRS provisions and the Plan’s vesting requirement. Note that many participants elect to rollover funds periodically to the Thrift Savings Plan (TSP), which does not accept rollovers electronically. (A check to the TSP f/b/o the named participant must be mailed to the participant.)
• For the purposes of plan asset verification, reconciliation of records, etc., provide a secure, web-based environment for the SEC-OHR’s SRP Program Manager/COR and additional SEC OHR personnel to review the plan asset balance.
• If applicable, provide a monthly report that discloses the current value of collateral and the methodology by which that valuation was made, the current value of any other assets secured by the same insurance or collateral, any changes to the insurance or collateral securing the Plan’s assets, and any other changes that could impact the security of the Plan’s assets.
• Maintain auditable records of all Plan assets and submit to periodic audits as required by law, including as required to enable the SEC to respond to inquiries by Congress, the Government Accountability Office, the Internal Revenue Service, or other similar entities.
• Successfully complete the SEC’s information technology security assessment process. A detailed description of the process is in section 3.5 Security Assessment.
As Recordkeeper:
• Separately account for any amounts forfeited by non-vested participants, and if applicable, notify the SEC any time that amount approaches $250,000 (or the then-applicable FDIC or NCUA insurance limit). Additionally, provide quarterly forfeiture reports that outline the names of non-vested participants who forfeited amounts that quarter, and the associated forfeited amount for each such participant.
• Process all relevant paperwork (including associated tax forms) for new and departing participants, in-service withdrawals, Required Minimum Distributions, beneficiary designation(s) and change(s), etc.
• Create and maintain individual participant records containing all pertinent financial data (e.g., account balance, bi-weekly deposits, in-service or other withdrawals, allocations of interest or other earnings on the omnibus trust account, vested amounts, and non-vested amounts). This information must be sufficient to meet the FDIC’s or NCUA’s “pass-through” insurance rules for retirement plans.
• Notify the SEC any time any participant’s account balance approaches $250,000 (or the then-applicable FDIC or NCUA insurance limit), if applicable.
• Provide a secure web-based platform for participants to manage and verify all aspects of their individual account, including the ability to make withdrawal requests (as permitted by law or by the Plan), submit initial or changed beneficiary designations, review amounts credited to their account (including, at least quarterly, the participant’s share of interest or other earnings on the omnibus trust account), review amounts deducted from their account, review amounts that are vested and amounts that are not vested, review total individual participant balance, view or request statements, and submit account inquiries.
• Provide call center services with hours that allow participants in any continental U.S. time zone reasonable access to those services, including support for account inquiries, for initial dispute management, and for escalation to SEC-OHR. The Contractor must be willing to work with the SEC on the customization of support representatives’ scripts to ensure accurate and consistent information is provided to plan participants.
• Provide participants with an account statement at least annually, and ideally provide participants the option to receive any such statement(s) electronically or in hard copy.
• Review the Trustee and/or Custodian’s biweekly reconciliation reports (if that service is provided by a different Contractor(s)) to ensure there are no discrepancies with the Recordkeeper’s records.
• Review all requests for withdrawal and determine whether the request is permissible in strict compliance with IRS provisions and the governing Plan document. If the Custodian service is provided by a different Contractor, transmit appropriate disbursement instructions to the Custodian.
• Submit to periodic audits of all Plan records and documentation as required by law or upon request by the SEC.
• Ensure strict compliance with all applicable IRS provisions, correct plan errors (as needed), and ensure corrections are properly recorded with the IRS and/or other appropriate entities.
• Create or revise for distribution and use by SEC employees informational materials describing the Plan in easy-to-understand terms, including any options for withdrawals, limitations on participation, vesting requirements, FAQs, etc.. These materials will be narrative and include graphics necessary to convey highlights and other pertinent facts and instructions of the Plan.
• Create or revise for SEC employees’ use standard forms required in the ordinary course of Plan administration (e.g., beneficiary identification or change, requests for withdrawal or rollover, etc.). Forms should be fillable, replicable from screen to print, and to the greatest extent allowable accept electronic signatures; and
• At least annually or more frequently as needed or requested by the SEC, and in collaboration with the SEC, review all forms and informational materials and assess whether any revisions will be made.
• All informational materials, forms, and any other documents prepared for SEC employees’ use must be made available both in print and electronically to the maximum extent possible. All electronically-available documents must be Section 508 Compliant.
• Present plan information to employees when needed (i.e., Contract Transition, Annual Health Fair, etc.) to assist SEC-OHR in ensuring employees’ understanding of plan provisions and procedures.
• Provide all services in a secure web-based environment that is Section 508 Compliant.
• Successfully complete the SEC’s information technology security assessment process. A detailed description of the process is in section 3.5 Security Assessment.
• For purposes of account verifications, record reconciliations, dispute resolutions, etc., provide secure web-based access to plan participant records to the SEC-OHR’s SRP Program Manager/COR and additional personnel as determined by the SEC.
Whether serving as Trustee, Custodian, and/or Recordkeeper, the Contractor’s expertise must include:
• Understanding contribution and matching principles of the federal government’s Thrift Savings Plan program. The SEC’s contribution for each employee is based on that employee’s biweekly contribution to the TSP.
• Experience with governmental or large-company payroll operations and transmittal and receipt of payroll-related file data.
• A proven service model that provides a high-quality and transparent participant experience; an efficient and high-quality plan sponsor experience; and consistent plan sponsor reporting mechanisms.
• Reliability and an ongoing commitment to quality and user-friendly secure technology.
• High level of data integrity to ensure maximum security of Personally Identifiable Information (“PII”), and the ability to provide annual internal-control attestations as a service provider to the SEC.
• Significant understanding of qualified defined contribution plans, common plan features, and provisions of law.
In addition, each Contractor is expected to:
Respond to telephone and e-mail inquiries by Plan participants and SEC staff responsible for managing the Plan within one (1) business day.
Travel to the SEC's headquarters in Washington, DC as required for plan transition. Thereafter, periodic travel to the SEC's headquarters may be required for employee presentations and to confer on matters pertaining to governance.
Ensure the privacy and security of all data, maintaining at a minimum the SEC's standards for handling sensitive data.
The Contractor will not make any decisions as to employee eligibility, contribution calculation methodology, or disputes, except that the Contractor can resolve disputes about minor errors but must promptly notify the SEC about the dispute and its resolution. Authorized Federal employees from the SEC retain all responsibility for making determinations as to eligibility, contribution methodology, and resolution of all other disputes.
The Plan will cover only Federal government employees and as such the Plan is not subject to ERISA.
However, the Contractor must be able to deliver financial disclosures similar to those required when a plan is subject to ERISA as required by DOL, IRS, or other regulatory entities. These deliverables must be provided at the intervals prescribed by applicable law or upon request.
2.6 Safeguarding of Information/Maintain Privacy and Security
Incident Reporting: If the Contractor knows of any actual unauthorized access, use, corruption, loss, or disclosure of SEC participant data, the Contractor must (1) promptly report such incident to the SEC and as otherwise required by law, and (2) immediately, so as to contain the incident, establish countermeasures to mitigate the impact of the incident and to recover from it. When reporting a security incident to the SEC, the report may be made in accordance with the Contractor’s procedures as long as those procedures do not delay prompt reporting.
3. Federal Requirements & SEC Regulations
3.1 Security Requirements. Contractor must implement, maintain, and enforce administrative, physical, logical, and other security measures to prevent the unauthorized access, use, corruption, loss, or disclosure of confidential information Contractor shall utilize security parameters that are consistent with the more stringent of the following: (a) industry best practices; (b) Contractor’s information security policies, or (c) laws and regulatory requirements applicable to the protection and use of Company Data and Confidential Information. Contractor shall and shall cause the Contractor Agents to encrypt all Company Data during transmission and shall provide proper, secure, and lawful storage, transmission, and disposal of the Company Data and Confidential Information.
The SEC reserves the right to make modifications based on evolving data security standards.
Contractor must strictly comply with applicable federal requirements and SEC regulations pertaining to information protection and privacy.
3.2 Requirements Management. The Contractor will provide all necessary personnel, administrative, financial, and managerial resources necessary to perform all tasks described in this Statement of Work
(SOW).
3.3 Security Issue Review. Contractor must conduct regular self-testing and independent audits to ensure that Contractor is in compliance with all applicable laws and regulatory requirements, including all confidentiality, non-disclosure, security, disaster recovery, contingency planning, and other similar obligations applicable to Contractor. The Contractor must remediate problems identified during these regular self-testing and independent audits.
3.4 SEC Instructions. Contractor must comply with the SEC Instruction documents for Cloud-Based Services, IT Security and Personally Identifiable Information (PII).
3.5 Security Assessment. Contractor must provide the SEC access to the following information for review:
a. Documentation that supports a risk assessment based on standards established by the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37. The documentation must include results of 3rd party assessments, security controls test results, system security plans (SSP), weakness remediation plans of action and milestone (POA&M), incident reports, and evidence of ongoing information security risk management activities.
b. Documentation related to compliance with Office of Management and Budget (OMB) Memorandum 03-22 and OMB Circular A-130 requirements for privacy assessments. This documentation must include results of 3rd party privacy assessments, privacy impact assessments, system privacy plans (SPP), and privacy control assessments (PCA).
c. Cybersecurity and privacy policies and procedures, including policies and procedures for cybersecurity and privacy incident/breach response.
3.6 Any SEC employee, contractor, or agent who will have access to this information for review must comply with the obligation to not divulge any confidential information as per 17 C.F.R. § 200.735-3(b)(2)(i), unless required by law to disclose such information.
3.7 System Requirements. Unless the SEC specifically directs the Contractor otherwise, at the conclusion of the SEC’s relationship with the Contractor, regardless of the cause or timing, the Contractor must archive and return all SEC data within the service using CSV files provided on Encrypted Removable Media or via a secure transmission method. The Contractor must then dispose of (and certify to the SEC that it has disposed of) all SEC data within the service as specified in the Contractor’s data disposal procedures.
3.8 Project Management
3.8.1 Project Coordination. The Contractor must coordinate with the COR and/or existing SEC Program/Project Managers and shall provide regular project plan and schedule updates. It is expected that the Contractor Technical Specialist - Client Relationship Specialist will drive the day-to-day aspects of the project for the Contractor and provide regular and appropriate updates to the COR and/or existing Program/Project Managers.
3.8.2 Project Status Reports. The Contractor must prepare and deliver to the COR periodic formal Project Status Reports and more frequent informal written status updates.
3.9 Project Meetings
3.9.1 Kick-Off Meeting. Within one (1) week after the award, the Contractor must participate in a kick-off meeting attended by Key Contractor personnel, the SEC Contracting Officer (CO), the Contracting Officer’s Representative (COR), and other key SEC personnel to introduce project members and their roles and responsibilities, introduce the SEC "Rules of the Road", and discuss the requirements of the systems, the project schedule, and security requirements, connections, and restrictions, at a minimum.
3.9.2 Status Meetings. The Contractor must participate in periodic project status meetings attended by key Contractor personnel, the COR and other key SEC personnel.
3.9.3 Meeting Minutes. The Contractor must provide kick-off and status meeting minutes to the COR for review. The Contractor must work with the COR to resolve any disagreements that may arise and provide the COR with final meeting minutes for review and approval.
3.9.4 Briefings. The Contractor must prepare and deliver quarterly briefings that cover key project accomplishments including milestones met and deliverables. The briefing must address matters that are essential to ensure overall success of the task including funding status, project schedule, and an analysis of the risks that may affect successful task completion. The Contractor must provide the COR with briefing materials for review prior to the presentation. The Contractor must incorporate feedback from the COR and must provide the COR with final briefing materials for review and approval.
3.10 Project Plans. The Contractor must develop and document a plan for implementation of the project that addresses considerations including, but not limited to:
• Possible business process and associated standards/procedures redesign and definition;
• Business process/system integration;
• Coding, configuration, and customization;
• Coordinated documentation, testing, and schedule;
• Production deployment which includes a back-out plan;
• Training;
• Communications/change management;
• Transition from manual and paper-based system of records; and
• Methodology for transitioning participants’ records and data (electronic and paper) to the SEC at prescribed intervals and upon conclusion of the contract, including a description of processes used to transition services to a successor provider; and procedures for data disposal and certification of data disposal.
The Contractor must review the implementation plan with the COR and relevant stakeholders. The Contractor must deliver the document to the COR for review, must incorporate feedback from the COR, and must provide the COR with a final document for review and approval. The approved Project Schedule will become the baseline for the contract. The Contractor must promptly notify the COR of any deviations from or changes to the plan and the reasons for the changes, and must provide the COR with a written draft of updates to the plan for review and approval.
4. RISK MANAGEMENT
The Contractor must coordinate and assist the COR in developing and maintaining a Risk Registry throughout the lifecycle of the project. The Contractor must immediately notify the COR of any major risk to the project and provide recommendations on the mitigation of the risk.
5. PACKAGING AND MARKING
5.1 Packaging and Marking. Preservation, packaging, packing, and marking of all deliverable contract line items must conform to normal commercial packing standards to assure safe delivery at destination.
5.2 Marking. All information submitted to the Contracting Officer or the COR, or their designated point of contact, must clearly indicate the number of the contract for which the information is being submitted.
6. INSPECTION AND ACCEPTANCE
Inspection and acceptance of the supplies and/or services to be furnished under this contract will be performed by the COR. The COR will assess performance of Contractor personnel on an ongoing basis, and communicate the results to the Contractor. The COR will not discuss performance concerns with Contractor personnel. Should a problem arise regarding performance or the overall level of service, the Contactor must have no more than three (3) business days in which to correct the problem. This may result in the SEC's requesting that the Contractor remove Contractor personnel from performing under the contract.
7. DELIVERIES OF PERFORMANCE
7.1 Period of Performance. The period of performance is two (2) one year from date of award, with three (3) nine (9) one-year option periods to follow the base year.
7.2 Option Periods. This contract has nine (9) one-year option periods. If all options are exercised, the period of performance will not exceed a total of ten (10) years six (6) months (the contract may be extended up to six months). If exercised, the period of performance for each successive option will begin the day after the expiration of the previous year and continue for one year. Exercise of any option requires a modification signed by an SEC Contracting Officer.
7.2.1 Award of an initial contract will not obligate the Government to exercise any contractual option.
Prior to exercising any option, the Government will make a determination that (1) funds are available, (2) the requirement covered by the option fulfills an existing need of the Government, and (3) the exercise of the option is the most advantageous method of fulfilling the Government's need, including consideration of price and other factors.
7.2.2 Failure to exercise an option will not obligate the Government to pay any charges other than the contract price including exercised options.
7.3 Place of Performance. Services will be performed electronically in a virtual environment, therefore, the
Contractor must be able to perform services to all SEC employees, who are located throughout the continental US.
7.4 Schedule of Deliverables. The Contractor must prepare and provide deliverables in electronic format to the
COR. The COR will review all deliverables and provide comments and/or approvals/ disapprovals in a timely manner so as not to adversely impact the project schedule. Deliverable schedules may include, but will not be limited to, the following:
Section Deliverable Schedule
Scope and Business Requirements
Per approved project schedule
2.5
Informational Materials
3.7.2
Project Status Reports
3.5 Security Assessment
3.8
Project Meetings Per approved project
3.8.4
Briefings Per approved project
3.9
Project Plans
4.
Risk Management Per approved project
8.17
Contractor Performance Evaluation
8.23
508 Compliance
7.5 Documenting, Inspecting, and Accepting Contract Deliverables. The Contractor must submit all deliverables requiring a transmittal sheet with either the attached Deliverable Transmittal sheet or an alternative transmittal sheet that contains substantially the same information.
7.6 Place of Delivery. The deliverables to be furnished under this contract must be delivered to the following addresses:
U.S. Securities and Exchange Commission 100 Street NE Washington, D.C. 20549 Attn: TBD
7.7 Hours of Performance. The Contractor must be available during normal business hours on all Federal Government business days during the term of the contract. This support must occur during normal business hours between 7:00 AM to 7:00 PM. EST, Monday through Friday, excluding Federal holidays and official Federal Government closures in the Metropolitan DC area. However, the SEC may require services outside of regular business hours. Exceptions may be made on a case-by-case basis and must be pre-approved by the Government COR.
8. SPECIAL CONTRACT REQUIREMENTS
8.1 Type of Contract. It is anticipated that this contract will be an Indefinite Delivery Indefinite Quantity Contract (IDIQ) with Firm Fixed Price (FFP) Task Orders.
8.2 Security and Privacy Act Matters. The security classification for work performed under this contract is
Public Trust. The documents that must be reviewed and produced are non-public and sensitive in nature and must be protected by the Contractor from unauthorized disclosure. Work on this project requires that Contractor personnel have access to information covered under the Privacy Act. All Contractor personnel who perform any work on this project must adhere to the Privacy Act, Title 5 of the U.S. Code, Section 552a, and applicable agency rules and regulations.
8.3 Conflicts of Interest
(a) General. Subpart 9.5 of the Federal Acquisition Regulations, 48 C.F.R. 9.5, prescribes responsibilities, general rules, and procedures for identifying, evaluating, and resolving organization conflicts of interest.
(b) Purpose. The purpose of this clause is to avoid, neutralize, or otherwise mitigate organizational conflicts of interest that might exist related to a Contractor's performance of work required by this contract.
Such conflicts may arise in situations including, but not limited to: a Contractor's participation, as an Offeror or representative of an Offeror, in a procurement in which it has provided assistance in the preparation of the Government's requirements and specifications; a Contractor's providing advisory assistance to the Government in a procurement in which the Contractor's firm or one the Contractor represents is an actual or potential Offeror; and a Contractor's participation, as an Offeror or representative of an Offeror, in a procurement where the Contractor has obtained confidential or proprietary information relating to competing Offerors as a result of the Contractor's work on prior task orders.
(c) Definition. For purposes of this clause, the term "Contractor" means: The Contractor; any of the Contractor's parents, affiliates, or other entities in which the Contractor or such parents or affiliates have a financial interest; successors in interest to the Contractor or any of its parents or affiliates; proposed consultants or subcontractors at any tier; and employees thereof.
(d) Restrictions. The Contractor agrees:
1. To remain ineligible to participate in any capacity (including participating as a prime Contractor, subcontractor, or as the representative of another party) in contracts, subcontracts, or proposals (whether solicited or unsolicited) that directly relate to the Contractor's performance of work under this Contract.
2. Prior to beginning work on a task order, to execute such Confidentiality Agreements, Statements of Non-Disclosure, or other documents the Contracting Officer may , in his/her sole discretion, require in order to protect the proprietary nature or confidentiality of information provided by the Government or otherwise received by the Contractor in connection with its work under this Contract.
3. Within the appropriate regulatory timeframe, to notify the Contracting Officer of any offer of compensation, other form of payment, or thing of value, made by a broker, potential lessor, or any source other than the Government to the Contractor related to services rendered under this Contract, regardless of whether such offer was made during Contractor's performance of work under a given task order or subsequent to Contractor’s completion of work under such task order.
4. Prior to the acceptance of a task order request, to immediately notify the Contracting Officer of any potential conflict of interest that would prevent or limit the Contractor's ability to perform the work requested.
5. To immediately notify the Contracting Officer of any conflict of interest discovered during Contractor's performance of work pursuant to a Government-issued task order; provided that the Contracting Officer shall have the right to impose such restrictions as he/she deems appropriate on Contractor's performance based on the existence of such a conflict or, if the Contracting Officer determines that such restrictions would not adequately address the conflict of interest at issue, to terminate the Contractor's performance of work under the task order at no cost to the Government.
6. As otherwise provided in this Contract, that if the Contractor declines to accept a task order request and subsequently participates (either directly or as a representative of another party) in a Government contracting action that was the subject of the task order request, then the fee the Contractor would have been entitled to receive for such task order work or the fee actually paid by the Government for the task order's performance by another Contractor, whichever is greater, must be applied toward the Contractor's minimum ordering guarantee.
7. If the Contractor knowingly withholds the existence of a conflict of interest from the Government, that the Contracting Officer may terminate this Contract at no cost to the Government and any minimum guarantee(s) otherwise applicable to the Contractor will be forfeited; provided, that the foregoing is in addition to all other remedies and causes of action the Government may have against the Contractor, including the suspension and/or debarment of the Contractor.
8. To ensure that conflicts are appropriately identified with respect to any subcontractors, and those measures are taken to alleviate and/or eliminate conflicts where they are identified with respect to a particular subcontractor.
9. That, in addition to the remedies enumerated above, the Government may terminate this Contract for cause in the event of the Contractor's breach of any of the above restrictions.
8.4 Compliance with Regulations. The Contractor must comply with all statutes, regulations, directives, instructions, and references applicable to the conduct of this acquisition as imposed by the Federal Government and the SEC, including, without limitation, those specified or referred to in this contract.
8.5 Non-Disclosure Requirements. Required non-disclosure forms are attached and must be completed and returned to the Contracting Officer before starting work under this contract.
8.6 Restrictions on Use, Disclosure, and Duplication of Confidential and Non-Public Information.
Confidential and non-public information, for purposes of this clause includes but is not limited to, all financial, statistical, personnel and/or technical data which is furnished, produced, generated, or otherwise available to the Contractor, during the performance of this contract. Unless otherwise specified, confidential and non-public information must not be used for purposes other than performance of work under this contract without the prior written consent of the Contracting Officer. The Contractor and its employees, agents, subcontractors, and subcontractor personnel are restricted from duplicating or disclosing confidential or non-public information, in whole or in part, outside the SEC for purposes other than fulfillment of the requirements set forth in this contract. Any presentation of any confidential or non-public information, or any reports or material derived from confidential or non -public information will be subject to review of the Contracting Officer prior to publication or dissemination. Any questions about whether information is confidential or non-public must be referred to the Contracting Officer prior to use, disclosure or duplication.
8.7 Non-Disclosure Agreement for Confidential and Non-Public Information. Rules 3(b)(1) and 3(b)(7) of the SEC's conduct regulation (17 C.F.R. 200.735-3(b)(1) and (7)) expressly prohibit unauthorized disclosure and improper use of confidential or non-public information or documents. The Contractor, and its employees, agents, subcontractors, and subcontractor personnel who will have access to confidential or non-public information or documents in the performance of the contract, agree to be bound by the provisions of Rules 3(b)(1) and 3(b)(7) of the SEC's conduct regulation and the terms set forth in the attached non-disclosure agreements (Attachments 1 & 2). The Contractor and all personnel assigned to the contract agree not to divulge to any unauthorized person non-public or confidential information obtained from the SEC in performance of their duties under the contract.
The Contractor must submit to the Contracting Officer the names of key personnel assigned to the contract. Each employee, agent, and subcontractor that will be authorized access to SEC information by virtue of performing the requirements set forth in this contract must be made aware of the obligation to not divulge non-public or confidential information as per the terms of the Non-Disclosure Agreement signed by a Contractor representative. Violation of this clause by the Contractor, its employees, agents, subcontractors, or subcontractor personnel may result in default of the contract and/or civil suits and/or criminal prosecution.
8.8 Personnel. The Contractor must provide skilled personnel required for the effective and efficient performance of this contract. The SEC reserves the right to review all resumes of all key personnel assigned to this contract. The SEC has the right to request that the Contractor remove Contractor personnel from working under this contract, at any time, for any reason.
8.9 Key Personnel. The Contractor must designate specific key personnel who are essential to the successful performance of this contract.
8.10 Contractor Substitution of Key Personnel. Following award, and throughout the life of this contract, the
Contractor will permit no substitution of key personnel without the written consent of the Contracting Officer, which shall not be unreasonably withheld, unless such substitutions are necessitated by an individual's sudden illness, death or termination of employment. In the event that substitution of personnel is desired, the Contractor must notify the Contracting Officer in writing at least thirty (30) calendar days before any key personnel substitution is made, if possible. The Contractor must submit a justification in sufficient detail to permit evaluation of the impact on the contract or its performance, with the resume of the proposed replacement personnel. The Contractor must obtain the Contracting Officer's written approval prior to any changes in the contract participation of the personnel named as key personnel. Proposed substitute personnel must have experience and education at least substantially equal to those of the personnel being replaced. Requests for substitutions must provide a detailed explanation of the circumstances necessitating such changes, a resume for each proposed substitute, and any other information as requested by the Contracting Officer. The Contracting Officer will evaluate such requests and promptly notify the Contractor of approval or disapproval thereof.
8.11 Contractor Responsibilities/Standards of Conduct (Nov 2012). The Contractor will furnish all managerial, supervisory, and other personnel necessary to successfully, effectively, and efficiently accomplish all work required by this contract. Contractor personnel are employees of the Contractor and under its administrative control and supervision. Contractor personnel are not employees of the Government.
The Contractor will select, supervise, and exercise control and direction over its employees under this contract. The SEC will not exercise any supervision over the Contractor's employees, but may, in coordination with Contractor management, provide sufficient direction to Contractor personnel to ensure that the purposes of the contract are met and the government's interests are protected.
The Contractor will be responsible for:
(a) Approving time cards of its employees;
(b) Approving leave requests of its employees;
(c) Performing performance evaluations of its employees;
(d) Making hiring and firing decisions for its employees;
(e) Informing its employees that they are not employees of the SEC and have not received an appointment in the federal service;
(f) Informing its employees that they are not to accept direction from employees of the SEC beyond that required to accomplish the purposes of the Contract;
(g) Informing its employees that the Contractor is responsible for approval of their time cards, leave requests, and performance evaluations, and for hiring and firing decisions;
The Contractor is accountable to the SEC for the actions of its personnel. The Contractor's employees, when on-site at SEC facilities under this contract, will only engage in duties specified in the statement of work, task order, or other work statement, and not in other business, political, charitable, or other activities. The Contractor will not recruit on SEC premises or otherwise act to disrupt official SEC business. The Contractor will be responsible when its employees are on-site at the SEC for maintaining satisfactory standards of employee competency, conduct, appearance, and integrity, and will be responsible for taking such disciplinary action with respect to its employees as may be necessary.
Contractor employees are expected to adhere to standards of conduct that reflect credit on themselves, their employer, the SEC, and the Federal Government.
8.12 Personally Identifiable Information (PII). A Contractor that designs, develops, or operates a system of records on individuals, or otherwise collects or has access to personally identifiable information (PII) in the performance of this contract must, prior to taking such action, comply with the following requirements:
(a) The Contractor must have established policies and procedures in place to safeguard SEC PII. The policies and procedures must provide the Contractor's processes for identifying, assessing, and mitigating privacy risks associated with PII. The policies and procedures must also cover training of employees on their roles and responsibilities for safeguarding SEC PII and incident management of suspected or confirmed loss of SEC PII.
(b) The Contractor must also ensure that all processes, procedures, and equipment associated with PII comply with all laws and regulations, and are consistent with industry-accepted information security standards, such as those recommended by the National Institute of Standards and Technology (NIST) and International Standard ISO/IEC 2700 I ("ISO 27001") or its successor provisions, including ISO 27002. In support of these requirements , the Contractor must have:
• policies, procedures, and mechanisms that prevent transmission or disclosure of SEC data to an unauthorized party;
• policies, procedures, and mechanisms that ensure SEC data on portable devices are protected using encryption that is consistent with industry-accepted information security standards; and
• policies, procedures, and mechanisms that ensure SEC data transmitted across public networks (i.e., the Internet) by the Contractor, its employees, agents, or subcontractors, are protected using encryption that is consistent with industry-accepted information security standards.
(c) The Contractor will ensure that all individuals who have access to any system of records that contains or has access to PII adhere to the Contractor's policies and procedures relating to PII.
(d) The Contractor must promptly alert the SEC of any confirmed loss of SEC PII that will affect the privacy rights of individuals or which violates any federal law or regulation by contacting the SEC Information Systems Security point of contact and the SEC Incident Response Team at soc@sec.gov. The Contractor must act in accordance with its policies and procedures in the event of any loss of SEC PII and must start an investigation of the incident and take all appropriate actions to remediate the effects of the incident and mitigate any risk that may arise from the incident. The Contractor shall preserve all records and other evidence relating to the incident and provide the SEC with a written report on the outcome of its investigation including any risk to SEC PII, the corrective action Contractor will take or has taken to respond to the incident, and such other information as the SEC may reasonably request.
8.13 Disaster Recovery. The Contractor must create and implement policies, processes, and procedures to address the information system security requirements needed for disaster recovery in the event of a disruption of the information service(s) provided. This includes regular review and test of a disaster recovery plan(s) related to recovering the information service(s) provided.
8.14 Approval of Subcontracts. The Government reserves the right to request that the Contractor not allow any subcontractor selected by the Contractor to perform work under this contract due to work performance, conflicts, and/or other issues of concern to the SEC. Therefore, the Contractor must provide the SEC the names of all subcontractors performing any work required by this contract and a description of services being performed.
8.15 Travel. There will be no reimbursement for travel expenses incurred within the Washington, DC metropolitan area. In the event that a requirement for travel outside the Washington DC metropolitan area arises, travel must be pre-approved by the COR by submitting travel plans with names, dates, locations, and estimated expenses at least two business weeks in advance of the planned travel. If the place of performance is other than the SEC Headquarters, travel may be allowable and reimbursable subject to the following limitations:
1. Any subsistence allowance (i.e., meals and lodging) is limited by a per diem allowance prescribed by the Federal per diem schedule - https://www.gsa.gov/travel/plan-book/per-diem-rates/per-diem-rates-lookup;
2. Expenses incurred as a result of travel using a personal automobile are reimbursed as prescribed on the link above;
3. Reimbursement of air and train travel is limited to the most economical rate and reasonably-traveled route; and
4. Each out-of-pocket travel and allowable miscellaneous administrative expense…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.