Attachment A - PWS _IVA_26NOV24_ Amendment 01.pdf

PDF 675 KB Posted

Attached to
Individual Identity Verification and Authentication Support Services Federal contract opportunity
Solicitation number
70FB70-24-R-00000002
Issued by
Federal Emergency Management Agency

About this file

This is a Performance Work Statement (PWS) issued by FEMA's Recovery Technology Programs Division for Individual Identity Verification and Authentication Support Services (IV&A). The contractor will provide identity verification, authentication, and fraud prevention services for FEMA's disaster assistance programs, including verification of applicant identities, occupancy status, ownership records, and demographic information.

The key requirements include achieving 99% accuracy in identity verification and 95% authentication success rates within three months of implementation, maintaining 24x7 availability with 99.9% uptime, and processing up to 25,000 concurrent users with surge capacity for 50,000 transactions per hour. The scope encompasses multiple verification tools and services including one-time password authentication, email intelligence risk assessment, digital identity verification for account creation/login, bank account validation, transaction velocity monitoring, business document validation, dark web monitoring, and funeral assistance program verification services. The contractor must provide real-time fraud detection capabilities, maintain strict data security protocols, and report incidents involving personally identifiable information within one hour. The period of performance consists of a 12-month base period with four 12-month option periods.

View the file

Other files for this federal contract opportunity

Other files attached to Individual Identity Verification and Authentication Support Services, newest first.
File Type Posted
70FB7024R00000002 Pricing Questions and Answers Amendment 03.xlsx XLSX spreadsheet
Attachment D Small Business Subcontracting Plan Amendment 03.pdf PDF
70FB7024R00000002 Pricing Questions and Answers Amendment 02.xlsx XLSX spreadsheet
70FB7024R00000002 Amendment 01.pdf PDF
Attachment C- Price Schedule Amendment 01.xlsx XLSX spreadsheet
Attachment E Past Performance Questionnaire Amendment 01.docx DOCX document
70FB7024R00000002 - Questions and Answers 11-26-2024 Amendment 01.xlsx XLSX spreadsheet
70FB7024R00000002.pdf PDF
Attachment B QASP.pdf PDF
2.2.1 Attachment F-DHS Form 700-23.pdf PDF
Attachment D Small Business Subcontracting Plan.pdf PDF
2.2.1 Attachment C- Price Schedule.xlsx XLSX spreadsheet
Attachment A- PWS _IVA_.pdf PDF
2.2.1 Attachment E Past Performance Questionnaire (2).docx DOCX document
Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Performance Work Statement (PWS)

Individual Identity Verification and Authentication Support Services (IV&A)

U.S. Department of Homeland Security

Federal Emergency Management Agency Recovery Technology Programs Division

November 26th, 2024

CONTENTS

1.0. GENERAL

1.1. BACKGROUND

1.2. SCOPE

2.0 SPECIFIC REQUIREMENTS/TASKS

2.1 IDENTITY VERIFICATION AND AUTHENTICATION SERVICES

2.2 ONE TIME PASSWORD (OTP)

2.3 EMAIL INTELLIGENCE RISK ASSESSMENT TOOL

2.4 DIGITAL IDENTITY TOOL GOVERNMENT NEW ACCOUNT OPENING

2.5 DIGITAL IDENTITY TOOL GOVERNMENT ACCOUNT LOGIN

2.6 BANK ACCOUNT DATA INFORMATION TOOL

2.7 TRANSACTION VELOCITY TOOL

2.8 BUSINESS DOCUMENT VALIDATION TOOL

2.9 INVESTIGATION TOOL LICENSES

2.10 TECHNICAL ASSISTANCE

2.11 VEHICLE SEARCH

2.12 REAL WORLD IDENTITY RISK ASSESSMENT TOOL

2.13 PHONE NUMBER RISK ASSESSMENT TOOL

2.14 CALL CENTER SOCIAL ENGINEERING SUPPORT

2.15 DARK WEB MONITORING

2.16 DOCUMENT SCANNING AND VALIDATION

2.17 FUNERAL BUSINESS IDENTIFICATION VALIDATION

2.18 FUNERAL FRAUD PREVENTION AND DETECTION BATCH SERVICE

2.19 RELATIVES AND ASSOCIATES BATCH SERVICE

2.20 DECEASED FLAG AND DATE BATCH SERVICE

2.21 BANK ACCOUNT OWNER VERIFICATION TOOL

3.0 OTHER APPLICABLE CONDITIONS

3.1 PERIOD OF PERFORMANCE

3.2 PLACE OF PERFORMANCE

3.3 TRAVEL

3.4 POST AWARD CONFERENCE

3.5 PROJECT PLAN

3.6 BUSINESS CONTINUITY PLAN

3.7 PROGRESS REPORTS

3.8 PROGRESS MEETINGS

3.9 GENERAL REPORT REQUIREMENTS

3.9.1 MULTIPLE APPLICATION REPORT

3.9.2 INVOICE SUMMARY REPORT

3.10 PROTECTION OF INFORMATION

4.0 DELIVERABLES

5.0 GOVERNMENT FURNISHED RESOURCES

6.0 TRANSITION PLAN

7.0 QUALITY ASSURANCE SURVEILLANCE PLAN

8.0 PERFORMANCE REQUIREMENTS SUMMARY (PRS)

9.0 CURRENT “AS IS” DESCRIPTION

10.0 RECORDS MANAGEMENT OBLIGATIONS

11.0 ACCESSIBILITY REQUIREMENTS (SECTION 508 REQUIREMENTS)

12.0 DHS ENTERPRISE ARCHITECTURE COMPLIANCE

13.0 SECURITY

Appendix I: Government Furnished Equipment (GFE) Appendix II: CISO Cyber-Supply Chain Risk Management (C-SCRM) Appendix III: Privacy Documentation Requirements Appendix IV: Contractor Transition Plan Appendix V: Continuity of Services Appendix VI: FedRAMP Certified Language Appendix VII: Artificial Intelligence Clause Appendix VIII: DHS Geospatial Information System Compliance Appendix IX: Safeguarding of Controlled Unclassified Information (July 2023) Appendix X: 3052.204-73 Notification and Credit Monitoring Requirements for Personally Identifiable Information Incidents (July 2023) Appendix XI: Privacy Training – Alternate I (Deviation) Appendix XII: Information Technology Security Awareness Training (July 2023)

1.0 GENERAL

1.1 BACKGROUND

The Federal Emergency Management Agency (FEMA) is authorized to provide disaster relief and emergency assistance to survivors during recovery of disaster and emergencies. Disaster survivors are encouraged to request FEMA assistance by dialing a toll-free number to access one of FEMA’s permanent or disaster specific call centers or by applying on-line at DisasterAssistance.gov where the Disaster Survivors’ registration is entered into the Individual Assistance (IA) information system formerly known as the National Emergency Management Information System (NEMIS). A critical component to supporting FEMA's mission is ensuring that only bona-fide and eligible individuals are provided Government assistance. This is achieved through verifying the identity and authenticating individuals registering for disaster assistance.

The current environment uses an identity outcome of "pass/fail" with reason codes provided by the incumbent contractor based on the profile information FEMA gathers from the applicant during disaster registration intake or registration and search processes. The point of entry exists when a disaster survivor provides information during registration and FEMA's Human Services Specialists enter the data or the disaster survivor enters the data directly into DisasterAssistance.gov to send a digital record to the contractor for verification. Both property and identity validation are obtained from this set of data. Services provided will determine if the property at the address specified is owned or occupied by the applicant.

Occupancy and ownership are key eligibility factors for most FEMA programs. As a result, FEMA is interested in obtaining additional information such as property ownership and occupancy records associated with the name and Social Security Number (SSN). To streamline our disaster registration intake process, FEMA also requests additional information such as:

address, phone, vehicle, and other data to ‘pre-populate’ our disaster registration intake form.

FEMA is also required to assess disaster assistance registrations to detect and prevent fraudulent activity. As a result, FEMA requires services to assist us in validating device identity, Internet traffic origin, velocity of transactions, and risks associated with use of bank accounts, phone numbers, or email addresses in conjunction with identities.

Document fraud is an additional risk faced by FEMA in delivering disaster assistance. FEMA requests a service and interface to allow transactions to validate business identity from the business name, address, phone number, and other business relevant information. Results of business identity checks will be returned with risk scoring assessments of the validity of the document(s).

1.2 SCOPE

FEMA requires support services which include, but are not limited to, a One Time Password (OTP) authentication solution, verification and authentication of identity, occupancy, ownership, vehicle, and demographic information for individuals registering for FEMA disaster assistance or family reunification purposes where a disaster has occurred or been declared. Furthermore, FEMA seeks products and services in the prevention of fraud, waste, and abuse within the domain of Government financial assistance programs. FEMA shall continue to seek information on new or emergent capabilities in support of fraud detection and prevention.

2.0 SPECIFIC REQUIREMENTS/TASKS

2.1 IDENTITY VERIFICATION AND AUTHENTICATION SERVICES

FEMA uses Identity Verification and Authentication (IV&A) services as a part of the registration process for disaster survivors to apply online for disaster assistance, and for registration and search processes. The request for identification verification and authentication services will identify the source system making the request. The Contractor’s Identity Verification service shall verify that an applicant's name, address, phone, SSN and Date of Birth (DOB) exists and is related to the person registering or searching. The contractor shall provide a strong identity verification service which shall include validation of a person based on the full name, phone, SSN, date of birth, and address across an array of public, private, and proprietary databases.

Identity verification shall check (among other validations of the person’s data) that:

a) SSN is valid.

b) SSN is not associated with a deceased person.

c) SSN is related to the named person.

d) SSN is not associated with more than one person.

The Contractor shall define the level of assurance they intend for identity verification within the fastest obtainable timeframe providing scores of probabilities of success that an identity is reliable. Outcome results, either pass/fail with reason codes, or equivalent system, must be the highest possible for a survivor to be granted service, but the fastest obtainable for FEMA to decide to grant services. Name matches should take into consideration common use of nicknames, e.g., Jonathan could match to Jon, Jonny, etc. The Contractor provides an ID verification of the applicant associated with the profile.

IV&A services are expected to provide near-perfect performance in terms of identity verification and allowing users to authenticate. The Contractor shall verify the identity of a person successfully at a rate of 99% or better after three months of general availability and authenticate users successfully 95% or better after three months of general availability. Furthermore:

• FEMA uses the National Emergency Management Information System (NEMIS) / Integrated Security and Access Control (ISAAC) system for determining eligibility and tracking disaster grants and other assistance as well as for support to disaster operations. A Contractor establishes a query based on applicant information provided by FEMA via NEMIS/ISAAC and begins the process of validating and authenticating the disaster applicant as a "true identity." Many times, valid applicants do not have the necessary documents needed as a basis for identification. A process and protocol must exist to authenticate and verify applicant identities during a disaster and filter out fraudulent claimants repetitively and consistently.

• If the Contractor includes new technology, then commercial-off-the-shelf (COTS) products are preferred over custom development of software. The Contractor must comply with DHS/FEMA IT infrastructure. More information regarding existing systems, technology, and data sources that exist within FEMA are included in the Technical Environment section below.

• The Contractor shall scale to support transactions up to a maximum of 25,000 concurrent users in a disaster scenario during extreme demand for disaster assistance registrations with the ability to surge to support load capacity of 50,000 transactions per hour.

• The threshold for detecting fraud, waste, and abuse and for calculating risk scores shall be real-time or near real-time with 24x7availability and 99.9% uptime.

Response time per transaction shall be six (6) seconds or less.

• The Contractor shall comply with the rules and regulations for Government security and privacy of information such as the Privacy Act, Privacy Impact Assessment (PIA) and Federal Information System Management Act (FISMA). Overall, the Contractor must show credible safeguarding of Personally Identifiable Information (PII) including sensitive information such as Social Security Number (SSN).

Safeguarding PII data is paramount. The government will monitor the Contractor for satisfactory work practices, processes, and systems. The Contractor will be responsible for reporting all breaches/losses to the COR, or designate, within one

(1) hour of the loss. The Contractor is responsible for all PII protection and monitoring costs associated to a breach. The Contractor shall supply a plan to offer the identity theft protection or credit monitoring services at no cost to the government for the affected individuals. Plan(s) may require approval by the FEMA Privacy Office prior to execution.

Additional Information:

The Contractor shall provide a risk rating for the temporary address in cases where an assistance check is being requested. Vacant lots, cemeteries, government buildings, commercial buildings, massage parlors, etc. would receive a high-risk rating using a classification system such as Standard Industrial Classification (SIC) codes to identify high risk properties.

The Contractor shall not be contractually bound to save FEMA-provided information in their database but may store the transactions in their accounting system for the duration of the contract. FEMA’s copy of the information is stored in the NEMIS system and transmitted via the FEMA Switched Network – both NEMIS and the FEMA Switched Network are fully certified and accredited by DHS.

FEMA will obtain Contractor recommendations of the best query data tied to emergency survivors in the disaster region. If the Contractor verifies identity, occupancy, or ownership for an applicant that FEMA later has reason to question, the Contractor will be requested to provide specific information regarding why the applicant was verified. This research is estimated to occur for no more than one percent (1%) of applicants sent for verification.

2.2 ONE TIME PASSWORD (OTP)

The Contractor shall provide a One Time Password (OTP) authentication solution that utilizes a verified phone number and checks for porting, spoofing, then sends a one-time passcode to SMS, voice, or email to authenticate an individual. The OTP solution shall send a simple alphanumeric authentication code via email, text, or voice to a device that applicants may already have in their possession. The contractor shall also verify that the delivery phone number is indeed associated and bound to the identity that is being authenticated prior to delivering the One Time Password for authentication.

2.3 EMAIL INTELLIGENCE RISK ASSESSMENT TOOL

The contractor shall provide a fraud detection solution utilizing email intelligence as a core risk identifier. The tool shall identify and prevent fraud scams on online transactions, gauge the risk connected to a specific email address, verify domain information, and deliver a risk/fraud score.

2.4 DIGITAL IDENTITY TOOL FOR GOVERNMENT NEW ACCOUNT OPENING

The Contractor shall provide Digital Identity Tool for new account opening to provide real-time intelligence to assess identities during digital transactions. The tool shall include but is not limited to scripted registrations, bots, and Artificial Intelligence to analyze connections between devices, locations, past behaviors, and anonymized personal information. The tool shall enable the Government to pro-actively identify returning users using multiple devices, email addresses, physical addresses, and account names. The tool shall use the digital data or behavior captured by JavaScript during the application to determine the risk of fraud. The tool shall return a risk assessment based on multiple attributes.

2.5 DIGITAL IDENTITY TOOL FOR GOVERNMENT ACCOUNT LOGIN

The Contractor shall provide Digital Identity Tool for account login to provide real-time intelligence to assess identities during digital transactions. The tool shall include but is not limited to scripted registrations, bots, and Artificial Intelligence to analyze connections between devices, locations, past behaviors, and anonymized personal information. The tool shall enable the Government to pro-actively identify returning users using multiple devices, email addresses, physical addresses, and account names. The tool shall use the digital data or behavior captured by JavaScript during the application to determine the risk of fraud. The tool shall return a risk assessment based on multiple attributes.

2.6 BANK ACCOUNT DATA INFORMATION TOOL

The Contractor shall provide a bank data information tool for verification of Bank Account Information and Routing Numbers for Government. The contractor shall provide the data as a flat file, updated monthly, and delivered via SFTP site for download. The SFTP credentials shall be provided by Accuity Inc. The cost would be based on annual number of routing number lookups and includes standard support from Accuity Inc.

2.7 TRANSACTION VELOCITY DATA

The contractor shall provide reports on repetitive use of identity information in multiple transactions to FEMA’s COR within 24 hours of identification. This includes:

a) Multiple uses of the same identity in different system transactions over a short period of time

b) Uses of different identities within the same transaction

c) Uses of slightly varied data, e.g., address changes to circumvent occupancy or ownership verification failures.

The threshold for notification will be established separately for each scenario. The contractor shall provide the data as an encrypted file via email to the COR and other identified FEMA points of contact.

2.8 BUSINESS DOCUMENT VALIDATION TOOL

The contractor shall provide checks to validate the existence and legitimacy of a business indicated on a receipt, estimate, or lease to verify claims for Individuals and Household Program financial assistance. The contractor shall also return a risk/fraud score.

2.9 INVESTIGATION TOOL LICENSES

FEMA requests to obtain up to fifty (50) licenses/seats with the ability to add additional if the need arises to utilize an investigative tool to assist with enforcing laws and regulations, prevent fraud, waste, and abuse of FEMA individual assistance programs using advanced data linking technology.

The investigative tool will assist in identification and verification of applicants damaged dwellings, current address, telephone numbers, and household members and their associated relationships. The tool will provide quality data, including but not limited to, credit bureaus and non-credit bureau sources, such as Department of Motor Vehicles’ data (to include driver’s license and motor vehicle registration data), property tax roll and deed transfers, utility records, and Social Security Administration.

The tool shall:

• Be compatible to FEMA Security and IT systems.

• Enable users to instantly gather and analyze current, comprehensive, and authoritative public records information, allowing them to perform their jobs more efficiently and effectively.

• Enable FEMA approved users to submit electronic batch search requests to verify sensitive personal identifiable information such as names, social security numbers, date of birth, current or previous physical and mailing address, phone numbers, deceased person(s) etc.

• Enable FEMA appointed individual(s) to serve as the site/software administrator to establish, maintain, monitor, and terminate user rights to the system.

The Contractor shall provide training and guides to educate systems users, at no additional cost to the government. Software must be approved by the DHS/FEMA Enterprise Architecture Board to be listed on the Technical Reference Model (TRM). Monthly invoices shall be supported by access to reports to verify users’ activity and charges billed.

2.10 TECHNICAL ASSISTANCE

The Contractor’s Proposal shall describe in detail the proposed process for implementing and fulfilling the Government's requirement, including detailed staffing plans and performances dates, and specify deliverables, including reports and methods for delivering materials, delivery dates, locations, and the proposed labor to perform the task. The Government will provide the Contractor 72-hour notification of the end of the technical assistance need and shall not incur cost beyond the end date regardless of the estimated performance period.

FEMA is seeking an integrated, scalable, near or real time, cost-efficient solution that provides an adaptive risk assessment and risk mitigation strategy to identify, design, and implement necessary controls for preventing improper payments as a result of fraud, waste, and abuse within Government disaster assistance programs.

FEMA desires to work with an innovative contractor who can deliver the desired features, provide near- perfect performance in detection of fraud, and work seamlessly in an integrated technical environment with a comprehensive, end-to-end workflow that includes manual processes as well as automated processes.

The Contractor shall:

• Outline a process for analyzing the level of fraud, waste, and abuse (in the forms of improper payments and/or errors), setting up a baseline of measurements, monitoring the measures, and reporting the results with recommendations for improvement on the performance metrics. This requirement has several performance-related targets including a) hit rate of 99% or better for being able to identify the applicant, b) pass rate 95% or better for allowing applicants to proceed with assistance, and c) error rate such as false negative and false positives are 2% or less. The performance measures (and other metrics) will be base-lined, monitored, reported, and improved within a three (3) month period after general availability. For example, the DHS E-Verify system for verifying employment authorization reduced Final Non- Confirmations (or system mismatches) to less than 4% and system errors (i.e., initial mismatches that were later confirmed for work authorization) to less than 1%. FEMA aims to achieve similar or better results for any potential Contractor for fraud, waste, and abuse detection and mitigation.

• Integrate with a generic rules engine that supports sophisticated management of a configurable set of rules for risk assessment (i.e., fraud indicators) and automated, systematic processing of rules. Flexible rules definition and rules grouping are two desirable features for a rules engine.

• Provide a flexible, configurable risk scoring functionality using the out-of-the-box and/or additionally configured risk rules (i.e., fraud indicators) to assign a risk score for a particular disaster assistance application. The risk score shall be flexible to allow different risk categories (e.g., high risk, medium risk, low risk, and little/no risk), different weights for fraud indicators, and other changes to the risk score formulation.

• Provide risk analytics, showing a pattern or statistical data for different fraud indicators.

This will help find potential areas of fraud, waste, and abuse. The contractor should discuss tools and processes for data mining and matching algorithms to determine patterns of improper payments from fraud, waste, and abuse. Such information may be used to support fraud auditing and investigations as well as improve the fraud screening process.

• Provide FEMA with the ability to produce case reports for fraud investigation, ad-hoc reporting, and case management functionality as part of an overall approach for risk mitigation of improper payments and other forms of fraud, waste, and abuse.

• Leverage legacy IT systems, technology, and data sources for cost and design efficiency in a Service- Oriented Architecture (SOA) environment. For example, generic rules engines may already exist within the agency and may be used by existing FEMA systems. FEMA is looking for the best, cost-efficient Contractors, and data sources from the private sector (and/or public sector), and therefore, it may involve leveraging existing systems, services, and data sources.

• Provide out-of-the-box, industry proven rules for risk assessment (i.e., fraud indicators) of possible fraud, waste, and abuse within the domain of Government financial and other forms of assistance.

The Contractor shall use the following rules and fraud indicators:

• Social Security Number (SSN) is Valid. The SSN specified in the application for disaster assistance is validated against data from the Social Security Administration using the applicant’s first name, last name, and date of birth.

• Social Security Number is a multi-instance number: Check database(s) for multiple instances of the SSN with variations such as variations of the name.

• Social Security Number Belongs to a Minor. The validated person associated to the

SSN is less than 18 years old at the date of the inquiry. If the SSN holder is a minor/dependent, information such as name, SSN, relationship, and legal status for the parent(s) or legal guardian(s) will be desired.

• Non-verifiable Damaged Dwelling Address. Check the damaged dwelling address that is street, city, state, and zip code specified in the application for disaster assistance to determine if it can be verified consistently across industry database(s) including the United States Postal Service (USPS) database for mailing address.

• Verified Address Does Not Match. Check in industry database(s) that the verified address returned for the applicant matches the damaged dwelling address that is street, city, state, and zip code provided in the application for disaster assistance. Check that the verified current mailing address in the industry database(s) matches the current mailing address provided in the application for disaster assistance.

• Current Address Belongs to an Institution. Check that the current address specified in the application for disaster assistance belongs to an institution such as a prison, hospital, hotel, campground, etc. rather than a residential address.

• Valid Dependent(s) in Household. Check dependent(s) with first name, last name, and SSN specified in the application for disaster assistance to verify validity of dependent.

• Applicant has Previously Submitted a Fraudulent Application. Check Government database(s) and possible industry fraud database(s) for any fraud investigation whether fraud is pending investigation or confirmed cases for the SSN of the applicant.

• SSN of Deceased Person. Check the SSN of the applicant to determine if the Social Security Administration has reported the owner of the SSN to be deceased. In some cases, disaster assistance may be given to the beneficiary of the deceased person, but there is likely to be other requirements such as providing a death certificate.

• Primary Residence. Check the damaged dwelling address that is street, city, state, and zip code specified in the application for disaster assistance to determine if the dwelling was the primary residence of the applicant.

• Owner Occupied Residence. Check to determine that the applicant owns (e.g., check with title companies) rather than rents or just occupies the residence.

• Payment Address and EFT Verification. Verify that the payment address and/or EFT account information match the specified recipient (e.g., full name, SSN, and date of birth). Verify that the payment address is deliverable and not a forwarded mailing address.

2.11 VEHICLE SEARCH

The contractor shall utilize DMV records containing driver’s license registration information and vehicle information, sourced directly from states DMVs, where commercially available by law, and are supplemented with additional data from national aggregators to support data pre-population.

This data pre-population shall assist in expediting the completion of applications by pre-populating driver and vehicle information, where available.

2.12 REAL WORLD IDENTITY RISK ASSESSMENT TOOL

The Contractor shall provide real world identity risk assessment tool service – a transaction that provides a fraud risk score that indicates likelihood that an applicant’s transaction is fraudulent, based on data the user provided to include name, email, phone, address, date of birth, Social Security Number, IP Address, device, velocity, network, and behavioral intelligence.

2.13 PHONE NUMBER RISK ASSESSMENT TOOL

The Contractor shall provide Phone Number Risk Assessment service - a transaction that validates the subject's name and address are associated to the provided phone number. Returns a risk assessment of the phone number, including carrier and account age.

2.14 CALL CENTER SOCIAL ENGINEERING SUPPORT

The contractor shall provide tools and expertise to help identify and protect against account takeovers (an individual calling and accessing applications because they have answers to security questions), individuals calling by phone with stolen identities, and detect Artificial Intelligence and voice spoofing.

2.15 DARK WEB MONITORING

The contractor shall provide tools to monitor dark web activity to mitigate vulnerability of Government information.

2.16 DOCUMENT SCANNING AND VALIDATION

The contractor shall provide a tool to scan incoming documents to ensure the data from them can be captured and analyzed appropriately to ensure accuracy and validation.

2.17 FUNERAL BUSINESS IDENTIFICATION VALIDATION

The contractor shall provide checks to validate the existence and legitimacy of a funeral business to verify claims for the Covid Funeral Assistance Program. The contractor shall also return a risk/fraud score.

2.18 FUNERAL FRAUD PREVENTION AND DETECTION BATCH SERVICE

The contractor shall provide a fraud prevention and detection tool that delivers real-time visibility into identity activity and identity behavior for Covid Funeral Assistance Program claims. The contractor shall also return a risk/fraud score.

2.19 RELATIVES AND ASSOCIATES BATCH SERVICE

The Contractor shall provide checks to validate the identity of related individuals and associates for Covid Funeral Assistance Program claims. The contractor shall also return a risk/fraud score.

2.20 DECEASED FLAG AND DATE BATCH SERVICE

The contractor shall provide checks to validate the decedent date of death for Covid Funeral Assistance Program claims. The contractor shall also return a risk/fraud score.

2.21 BANK ACCOUNT OWNER VERIFICATION TOOL

The contractor shall provide a tool to validate the Bank Account Owner information for Covid Funeral Assistance claims. The contractor shall also return a risk/fraud score.

3.0 OTHER APPLICABLE CONDITIONS

The Contractor shall adhere to the following requirements:

• The Contractor shall have a high availability architecture and hot standby capability.

• The Contractor shall conform to the ISAAC (source system NEMIS) interface via its corporate Virtual Private Network.

• FEMA will provide ISAAC (NEMIS source system) interface assistance to send transactions on a near real-time basis to the contractor and to receive (in less than six seconds) an automated contractor response. This response may be a "PASS/FAIL" with reasons for a "FAIL" response to an identity verification request, a four-question quiz with the correct answer to each question noted for authentication purposes, or an "OWNER/OCCUPANT" response to that transaction. The interface is an extensible Markup Language (XML) exchange via the Contractor's Secure Socket Layer (SSL) tunnel through the Internet. FEMA will reconfigure this interface to support the Contractor's Internet Protocol addresses, make minor changes to the XML transaction and response formatting, and work with the Contractor's technical staff to establish an operational link.

• At time of award and thereafter, the testing of the process and protocols will be made available to predict the accuracy rates and compliance with industry best practice to meet or exceed the performance standard for achieving the highest accuracy within the commercial best practices approach. The Contractor shall have a test interface and a set of test transactional data that will enable FEMA to validate that its requirements are met, and to aid in regression testing application changes that may not involve changes to the Contractor's interface.

• The Contractor shall use a system that shows valid or invalid (pass/fail is used currently) in designating the identity of the applicant for monitoring and surveillance of outcomes. FEMA requires access to the rationale for both designations on each transaction.

• The Contractor shall report and measure validated identities by volume processed and scores provided as 'pass/fail' or other system.

3.1 PERIOD OF PERFORMANCE

The period of performance for this contract is a 12-month base period followed by four 12-month option periods.

3.2 PLACE OF PERFORMANCE

The primary place of performance will be the Contractor’s facilities.

3.3 TRAVEL

No travel is anticipated currently.

3.4 POST AWARD CONFERENCE

The Contractor shall attend a Post Award Conference with the Contracting Officer and the COR no later than ten (10) business days after the date of award. The purpose of the Post Award Conference, which will be chaired by the Contracting Officer, is to discuss technical and contracting objectives of this contract and review the Contractor's draft project plan. The Post Award Conference will be held at the Government’s facility or via teleconference.

3.5 PROJECT PLAN

The Contractor shall provide a draft Project Plan at the Post Award Conference for Government review and comment. The Contractor shall provide a final Project Plan to the COR not later than ten

(10) business days after the Post Award Conference.

3.6 BUSINESS CONTINUITY PLAN

The Contractor shall prepare and submit a Business Continuity Plan (BCP) to the Government. The BCP Plan shall be due ten (10) business days after the date of award and will be updated on an annual basis. The BCP shall document Contractor plans and procedures to maintain support during an emergency, including natural disasters and acts of terrorism.

The BCP, at a minimum, shall include the following:

• A description of the Contractor’s emergency management procedures and policy

• A description of how the Contractor will account for their employees during an emergency.

• How the Contractor will communicate with the Government during emergencies

• A list of primary and alternate Contractor points of contact, each with primary and alternate:

• Telephone numbers

• E-mail addresses

Individual BCPs shall be activated immediately after determining that an emergency has occurred, shall be operational within 24 hours of activation or as directed by the Government, and shall be sustainable until the emergency situation is resolved and normal conditions are restored or the contract is terminated, whichever comes first. In case of a life-threatening emergency, the COR shall immediately contact the Contractor Project Manager to ascertain the status of any Contractor personnel who were in Government controlled space affected by the emergency. When any disruption of normal, daily operations occurs, the Contractor Project Manager and the COR shall promptly open an effective means of communication and verify:

• Key points of contact (Government and contractor)

• Temporary work locations (alternate office spaces, telework, virtual offices, etc.)

• Means of communication available under the circumstances (e.g., email, webmail, telephone, FAX, courier, etc.)

• Essential Contractor work products expected to be continued, by priority.

The Government and Contractor Project Manager shall make use of the resources and tools available to continue contracted functions to the maximum extent possible under emergency circumstances. Contractors shall obtain approval from the Contracting Officer prior to incurring costs over and above those allowed for under the terms of this contract.

Regardless of contract type, and of work location, Contractors performing work in support of authorized tasks within the scope of their contract shall charge those hours accurately in accordance with the terms of this contract.

3.7 PROGRESS REPORTS

The Project Manager shall provide a weekly progress report to the COR and Contracting Officer via electronic mail. This report shall include a summary of all Contractor work performed, including a breakdown of labor hours by labor category, transaction quantities by transaction category, and all direct costs by line item, for the previous week’s activity.

The Project Manager shall also provide a monthly progress report to the COR and Contracting Officer via electronic mail. This report shall include a summary of all Contractor work performed, including a breakdown of labor hours by labor category, transaction quantities by transaction category, all direct costs by line item, an assessment of technical progress, schedule status, and travel conducted and any Contractor concerns or recommendations for the previous reporting period. The report shall be provided the end of the 5th work day of each month for the previous month’s work.

3.8 PROGRESS MEETINGS

The Project Manager shall be available to meet with the COR upon request to present deliverables, discuss progress, exchange information, and resolve emergent technical problems and issues. These meetings shall take place via teleconference.

The Project Manager shall be responsible for keeping the COR informed about Contractor progress throughout the performance period of this contract and ensure Contractor activities are aligned with DHS objectives. At a minimum, the Project Manager shall review the status and results of Contractor performance with the COR on a monthly basis by email.

3.9 GENERAL REPORT REQUIREMENTS

The Contractor shall provide all written reports in electronic format with read/write capability using applications that are compatible with DHS workstations (Windows 10, Microsoft Office, and Adobe Acrobat Applications).

At the time of a disaster declaration or amendment, FEMA will provide the Contractor with a list of counties included in the disaster declaration or amendment. The Contractor will be required to digitally provide to the COR, the following reports regarding the declared counties/regions. FEMA shall also obtain information from the Contractor regarding any demographic information available delivered in an agreed upon method after award or on an ad-hoc basis.

3.9.1 MULTIPLE APPLICATION REPORT:

FEMA will obtain from the Contractor a Multiple Application Report. The weekly reports will identify all individuals or households repeatedly sent for Identity Verification. The report will identify individuals who may have intentionally varied data (i.e., name, SSN, or street address) to defraud the Federal Government.

Further it should identify problems that individuals are having with the registration process that cause them to intentionally register more than one time per declaration.

3.9.2 INVOICE SUMMARY REPORT:

At the time of the billing, the Contractor shall submit a transaction summary and running accumulation report to support the monthly billed activity. File content, format and delivery method will be determined at the time of the award.

3.10 PROTECTION OF INFORMATION

Contractor access to information protected under the Privacy Act is required under this PWS.

Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with the law and Government policy and regulation. See Appendix IX: Safeguarding of Controlled Unclassified Information (July 2023).

4.0 DELIVERABLES

ITEM PWS

REFERENCE DELIVERABLE / EVENT DUE BY

DISTRIBUTION

3.4

Post Award Conference

10 Business Days After Award

N/A

3.5

Draft Contractor Project Plan

At Post Award Conference

COR, CO, PM

ITEM PWS

REFERENCE DELIVERABLE / EVENT DUE BY

DISTRIBUTION

3.5

Final Contractor Project Plan

10 Business Days After Post Award Conference

3.6

Original Business Continuity Plan

10 Business Days After Award

3.6 Updated Business

Continuity Plan

Annually COR, CO, PM

3.7

Progress Reports

Weekly (for previous week’s work) and Monthly (5 Business Days into the new month for previous month’s work)

3.9

Owner/Occupant Report

24 Hours After Each Disaster Declaration or Amendment

COR, PM

Multiple Application Report

24 Hours after requested

Invoice Summary Report

24 Hours after requested

6.0

Transition Plan

5 Business Days After Award

5.0 GOVERNMENT FURNISHED RESOURCES

The Contractor shall use Government furnished information, data, and documents only for the performance of work under this contract and shall be responsible for returning all Government furnished information, data, and documents to the Government at the end of the performance period.

The Contractor shall not release Government furnished information, data, and documents to outside parties without the prior and explicit consent of the Contracting Officer.

6.0 TRANSITION PLAN

A transition from the current service provider within ninety (90) days from award of contract is required. Transition is defined as a seamless operation on a non-interference and non-interruption-in-services basis. The Contractor shall finalize a Transition Plan five (5) days after award. The Plan will address all facets of the transition that the Offeror deems important but, at a minimum, should address the timeline, actions, responsibilities, and the processes for transition, including adjusting to surge requirements on a 24/7 basis, should a disaster strike at the same time the transition takes place.

7.0 QUALITY ASSURANCE SURVEILLANCE PLAN

The Government will provide the Contractor a Quality Assurance Surveillance Plan (QASP).

The Contractor’s performance will be monitored against specified performance measures outlined in the PWS and the QASP.

8.0 PERFORMANCE REQUIREMENTS SUMMARY (PRS)

The Contractor shall perform all requirements outlined in this PWS and achieve the performance standards for each function of the operation as described below.

Column 1 - Selected Service Performance Area (SSPA):

Lists the SSPA on which the Government will perform surveillance. The absence of any contract requirement from the PRS shall not detract from its enforceability nor limit the rights or remedies of the Government under any other provisions of the contract.

Column 2 – Standard:

Defines the standards of performance for each listed SSPA.

Column 3 - Performance Requirement:

Sets forth the maximum allowable deviation from standard performance for that service that may incur before the Government will invoke the payment computation formula, resulting in a deduction for unsatisfactory performance, or non-compliance with the contract.

Column 4 - Method of Surveillance:

Sets forth the surveillance methods the Government will use to evaluate the Contractor's performance for the listed tasks.

Selected Service Performance Areas

Standard Performance Requirement

Method of Surveillance

Successful Identity Verification as outlined in section 2.1

100% "True Identity" verification and authentication is ideal.

The Contractor shall verify the identity of a person successfully at a rate of 99% or better after an initial grace period of three (3) months.

Hit rate of 99% or better for being able to identify the applicant.

1. Random sampling

2. Periodic surveillance

3. Management reports Period: Random multiple checks within three (3) month period after initial availability then Monthly.

Timely Identity Verification (Individual transaction response speed)

Delivery of identity verification data to FEMA in near or real time across the ISAAC interface to the source system making the request. Transactions will be via the Internet to a government-provided interface housed at Mount Weather Emergency Operating Center in Bluemont, VA, and/or other DHS consolidated data center(s).

Identity verification data is delivered to FEMA in near or real time. Individual transaction response speed shall not take longer than six (6) seconds.

1. Random sampling

2. Periodic surveillance

3. Management reports

Period: Random multiple checks within three (3) month period after initial availability and then Monthly

Successful User Authentication as outlined in section 2.1

The Contractor shall authenticate users successfully 95% or better after an initial grace period of three (3) months.

Pass rate of 95% or better for allowing applicants to proceed with assistance

1. Random sampling

2. Periodic surveillance three (3) month period after initial availability and then Monthly

Maintain low error rate

The Contractor shall keep error rates for transactions such as false negative and false positives down to 2% or less.

Error rates such as false negatives and false positives are 2% or less.

1. Random sampling

2. Periodic surveillance three (3) month period after initial availability and then Monthly

Keep services accessible (Availability and Uptime)

The Contractor shall ensure that all contracted services are available to FEMA 24 hours a day, 7 days a week, 365 days a year, including holidays.

24x7 availability and 99.9% uptime.

A COOP plan shall be in place to ensure service is available.

1. Random sampling

2. Periodic surveillance

3. Management Reports

4. Contractor reports

Period: Monthly

9.0 CURRENT "AS IS" DESCRIPTION

The following is a description of how FEMA is performing this function at present to detail all the required steps in the process. The Contractor may recommend alternative ways to do this and meet the overall objective of verification and authentication. The FEMA/NEMIS system, as part of its enterprise-wide disaster response function, incorporates as one of its functional modules a standard universal access management system termed the Integrated Security and Access Control (ISAAC) authentication system which resides on a dedicated authentication server.

FEMA NEMIS/ISAAC provides internal and external user account access request, review, and approval for all FEMA disaster response systems, with the goal of meeting FEMA's immediate and continuing need to provide adequate access control and identity management process. As an enterprise service, this module will accept transaction data in XML or equivalent format. FEMA expects that any of the systems available in the commercial marketplace can interface with this FEMA system with minimal modification to the module by FEMA.

The following is a description of the required bi-directional transaction data items that must be exchanged between the Government and the Contractor.

• Applicants can initiate transactions in two different ways, either directly by using the Internet, or by telephone with a FEMA customer service agent entering the transactional data based upon the information provided by the applicant.

• The first step under either alternative results in the following information being presented to the third-party Contractor for anyone or combination of the menu of transactions which currently are:

o Identity verification o Identity authentication o Ownership/occupancy verification o Renter occupancy verification o Residency status (local region, state, nation of origin and status of citizenship)

Currently, separate transactions employing all the steps below are performed for each of these required parameters.

• Initial data presented to the Contractor from the Government (when available/applicable):

o First name o Last name o SSN o Date of Birth o Phone o Address-street o Address-city o Address-state o Address-zip o Transaction ID generated by the Government o Client ID (e.g., FEMA) o Action (request) ID (such as ID verification, ID Authentication, Ownership and/or Occupancy) generated by the Government

• Associated data created by the Contractor and included as a permanent record for all transactions:

o o Transaction ID generated by the Government and provided as inputs.

o Action (request) ID generated by the Government and provided as inputs.

o Transaction ID generated by the Contractor.

o Possible Exception message o Exception ID (predefined) o Exception message

The registration process halts while the Contractor is processing this transaction. The Government, therefore, expects that the reply is prompt. Expectations are that average response time is six (6) seconds or less per transaction with no transaction taking longer than ten (10) seconds.

• Processing results created by the Contractor are sent to the Government:

• ID verification

• Pass/fail value

• SSN-Last name match

• Address-Last name match

• SSN not issued to a deceased person

• SSN not issued before date of birth

• SSN is unique

• Ownership and Occupancy

• True/false value for Ownership and Occupancy

• Occupancy

• True/false value for Occupancy

• Based upon the results of the query, the application process either continues or is terminated pending further action by the applicant to resolve any discrepancy.

The Government expects the Contractor to, on a continuing basis; indicate to the Government a probability score, either in terms of a missed question on a quiz, or an overall scoring number that the applicant associated with each transaction is authentic. For high risk and postal service flags returned for addresses, the data currently returned from 'data' end to authentication end and ultimately to FEMA varies slightly. The data portion returns a Y or N flag via XML to the authentication service, which uses the terms PASS or FAIL based on the data.

To determine how to interpret the Y or N translations, the following is planned for use:

• If <addr_deliverable> is Y then Pass. If N or U is returned, then Fail

• If <addr_business> is Y then Fail. If N or U is returned, then Pass

• If <addr_maildrop> is Y then Fail. If N or U is returned, then Pass

• If <addr_highrisk> is Y then Fail. If N or U is returned, then Pass

10.0 RECORDS MANAGEMENT OBLIGATIONS

A. Applicability This clause applies to all Contractors whose employees create, work with, or otherwise handle Federal records, as defined in Section B, regardless of the medium in which the record exists.

B. Definitions “Federal record” as defined in 44 U.S.C. § 3301, includes all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them.

The term Federal record:

1. includes FEMA records.

2. does not include personal materials.

3. applies to records created, received, or maintained by Contractors pursuant to their FEMA contract.

4. may include deliverables and documentation associated with deliverables.

C. Requirements

1. Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.

2. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C.

552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.

3. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.

4. FEMA and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .