A19 Attachment 1 AI Use Compliance and Risk Management Plan.pdf

PDF 172 KB Posted

Attached to
Mobile SLAM LiDAR Scanning Systems Federal contract opportunity
Solicitation number
75D301-26-Q-79246
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Office of Acquisition Services

About this file

This document is a template for an Artificial Intelligence (AI) Use Compliance and Risk Management Plan designed for contractors using AI tools in federal contract performance when AI development or delivery is not the primary deliverable.

The template requires contractors to provide comprehensive disclosure and documentation across nine sections. Section 1 (Background) captures the AI tool name, contractor and subcontractor information, contract task supported, AI classification (generative, agentic, machine learning, computer vision, natural language processing, reinforcement learning), and whether use is limited to internal operations or touches government information. Section 2 identifies ownership and support contacts, including the contractor's AI owner, technical support contact, privacy/security contact, the CDC/HHS program office involved, and expected users (contractor staff, CDC/HHS staff, public users, or external parties). Section 3 (Tool Background) documents the tool/product name, developer/vendor, technology type (open-source, proprietary, government-furnished, contractor-developed, or subcontractor-provided), LLM/foundation model details, API requirements, and availability of supporting documentation (model cards, system cards, data cards, vendor security documentation, evaluation summaries, terms of service, privacy policies, and audit logs). Section 4 addresses hosting environment (contractor, commercial SaaS, FedRAMP-authorized cloud, CDC/HHS, or local/offline) and FedRAMP authorization status. Section 5 (Data) requires disclosure of what government information will be processed, types of data involved (public information, PII, PHI, procurement-sensitive, proprietary), specific data inputs and outputs, storage and retention practices, whether government data will be used for model training or improvement, and data sharing arrangements. Section 6 (High-Impact Assessment) evaluates whether AI output could materially affect individuals' or organizations' rights, benefits, services, health, safety, or access, and whether CDC/HHS personnel would rely on outputs as a principal basis for decisions. Section 7 addresses safeguards including output verification procedures, required human review, prevention of unauthorized disclosure, protection against misuse, and civil rights protections. Section 8 covers monitoring mechanisms (accuracy, performance degradation, data leakage, abuse, prompt injection, unauthorized access), CDC/HHS access to monitoring information and audit logs, issue detection and escalation procedures, and incident response protocols. Section 9 requires contractor affirmations that AI use is approved by the Contracting Officer, all planned AI use is disclosed, unapproved AI tools will not receive government information, government data will not be used for model training without authorization, the AI Use Card will be maintained and updated, the contractor will notify before any changes or expansion of AI use, unlawful discriminatory use will be prevented, and applicable privacy, security, data rights, records, civil rights, and AI requirements will be met.

View the file

Other files for this federal contract opportunity

Other files attached to Mobile SLAM LiDAR Scanning Systems, newest first.
File Type Posted
A19 75D301-26-Q-79246 Amendment 0002.pdf PDF
RFQ_75D301-26-Q-79246 Questions and Answers.pdf PDF
A19 Attachment 2 Minimum Requirements Compliance Checklist Amendment 0001.pdf PDF
A19 75D301-26-Q-79246 Amendment 0001.pdf PDF
A19 Attachment 2 Minimum Requirements Compliance Checklist.pdf PDF
A19 RFQ 75D301-26-Q-79246.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Artificial Intelligence (AI) Use Compliance and Risk Management Plan

Purpose: Use this when a contractor plans to use, may use, or later proposes to use AI in contract performance, but the primary deliverable is not the development or delivery of an AI system.

1. Background

Name of AI tool/system:

Contractor using the AI:

Subcontractor or service provider, if any:

Contract task/function supported:

Describe how AI will be used in contract performance:

Is AI use required to perform the work, or optional?

Required Optional Unknown

AI classification:

Generative AI

Agentic AI Classical/Predictive Machine Learning Computer Vision

Natural Language Processing

Reinforcement Learning Other: [Insert]

Is this use limited to contractor internal operations?

Yes No

Will the AI touch Government information, systems, identities, networks, or operations?

Unknown

Was the AI system procured to support this particular contract per requirements in the Statement of Work?

2. Who owns and supports this use?

Contractor AI owner:

Contractor technical support contact:

Contractor privacy/security contact:

CDC/HHS program office using or receiving outputs:

Expected users:

Contractor staff only

CDC/HHS staff Public users Beneficiaries, patients, applicants, regulated entities, or other external parties Other: [Insert]

3. Tool background

Tool or product name:

[Insert]

Developer/vendor:

[Insert]

Is the AI technology open-source, proprietary, Government-furnished, or other?

☐ Open-source ☐ Proprietary/commercial ☐ Government-furnished ☐ Contractor-developed ☐ Subcontractor-provided ☐ Other: [Insert]

If the system uses an LLM or foundation model, what is the primary model?

[Insert]

Who provides the LLM/foundation model?

[Insert]

What model options are available?

[Insert]

Does it require an API key?

☐ Yes ☐ No ☐ Unknown

Attach or link, if available:

☐ Model card ☐ System card ☐ Data card ☐ Vendor security documentation ☐ Evaluation summary ☐ Terms of service ☐ Privacy/data retention policy ☐ Audit-log documentation

4. Where is it hosted and authorized?

Hosting environment:

☐ Contractor environment ☐ Commercial SaaS ☐ FedRAMP-authorized cloud ☐ CDC/HHS environment

☐ Local/offline environment ☐ Other: [Insert]

Where is the system hosted?

[Insert country/region/cloud/provider]

Is the product directly FedRAMP authorized or available through a FedRAMP-authorized instance?

☐ Yes ☐ No ☐ Not applicable ☐ Unknown

If no, is it undergoing FedRAMP authorization?

☐ Yes ☐ No ☐ Unknown

5. What data will be used?

Will the AI process, store, transmit, summarize, analyze, or generate Government information?

Unknown

Types of data involved:

Public information Government nonpublic information

PII

PHI

Procurement-sensitive information Proprietary/business confidential information ☐ Other: [Insert]

What information will be entered into the AI tool?

What outputs will the AI generate?

Will prompts, uploads, outputs, logs, or user interactions be stored?

☐ Yes ☐ No ☐ Unknown

Retention period:

[Insert]

Will Government data, prompts, outputs, or logs be used to train, fine-tune, improve, or benchmark any model?

Yes

No

Unknown

Will any data, prompts, outputs, or logs be shared with other users, tenants, vendors, subcontractors, or third parties?

Yes No Unknown

Explain storage, use, retention, deletion, and sharing:

6. Is this high-impact?

Could the AI output materially affect an individual’s or organization’s rights, benefits, services, health, safety, access, eligibility, enforcement status, or other significant interests?

Yes No Unknown

Could CDC/HHS personnel rely on the AI output as a principal basis for a decision or action?

Yes

Unknown

Is the AI used only for internal drafting, summarization, or administrative support with human review before use?

Yes No

High-impact rationale:

7. What safeguards are in place?

How will contractor personnel verify AI outputs before relying on them?

What human review is required before AI-generated content is submitted to CDC/HHS?

How will the contractor prevent unauthorized disclosure of Government information?

How will the contractor prevent misuse, unauthorized use, or corruption of the AI system?

How will the contractor protect privacy, civil rights, and civil liberties?

What internal policies govern this AI use?

8. Monitoring and misuse protection

What is monitored?

Accuracy/performance Performance degradation or drift Data leakage signals Abuse/misuse Prompt injection Unauthorized access Other: [Insert]

Does CDC/HHS have access to monitoring information, audit logs, or summary reports?

Upon request Not applicable

How are issues detected, escalated, and corrected?

When will CDC/HHS be informed?

What is the standard operating procedure for incidents or unacceptable outputs?

9. Required contractor affirmation

The contractor affirms that:

AI will not be used unless approved by the Contracting Officer.

The contractor has disclosed all planned or potential AI use.

The contractor will not enter Government information into unapproved AI tools.

The contractor will not use Government data to train, fine-tune, or improve an AI model unless expressly authorized.

The contractor will maintain and update this AI Use Card throughout contract performance.

The contractor will notify the Contracting Officer and COR before changed, expanded, or new AI use.

The contractor will prevent unlawful discriminatory use or outputs.

The contractor will comply with applicable privacy, security, data rights, records, civil rights, and AI requirements.

File details come from the government source that posted it. Updated .