Draft SOW_ Interim Servicing Solution September 4_2020.docx

DOCX document 371 KB Posted

Attached to
Pre-Solicitation Conference for the Interim Servicing Solution Federal contract opportunity
Solicitation number
September_8_2020
Issued by
Department of Education

About this file

This document outlines the U.S. Department of Education's Interim Servicing Solution, which will ensure continued servicing capabilities for Federal Student Aid recipients until the implementation of a future permanent solution. The Department seeks to award up to two contracts to service providers to support loan servicing, processing, and customer engagement functions. Loan servicing responsibilities will include repayment plans, income-driven repayment, loan consolidation, customer communications and inquiries, payment processing, and financial reporting. Offerors must demonstrate the ability to migrate all existing customer accounts and data from multiple current servicers onto their proposed servicing platform. The anticipated contract period is five years with optional annual extensions. Offerors must meet detailed requirements for system functionality, integration, security, customer experience and service level agreements. The document provides information on expected account volumes and transaction types to inform offeror responses.

View the file

Other files for this federal contract opportunity

Other files attached to Pre-Solicitation Conference for the Interim Servicing Solution, newest first.
File Type Posted
Draft IRPE Elements v 5.0.2 September 4_2020.docx DOCX document
Draft ISS Pricing Template September 4_2020.xlsx XLSX spreadsheet
Draft ISS SLA - Performance Measurement Template September 4_2020.xlsx XLSX spreadsheet
Draft Service Level Methodology_Performance Metrics September 4_2020.docx DOCX document
Draft ISS Pricing Template Instructions September 4_2020.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Next Generation Statement of Work – Interim Servicing Solution (ISS) Version 1.0 – September 4, 2020

DRAFT

SECTION C, DESCRIPTION/SPECIFICATIONS/STATEMENT OF WORK

C.1 INTRODUCTION

The U.S. Department of Education, Office of Federal Student Aid (FSA), is issuing this requirement to ensure continued servicing capabilities for FSA’s aid recipients using the same requirements applicable under the current Title IV Additional Servicers and Not-For-Profit contracts, except as noted herein. This Interim Servicing Solution (ISS) will support loan servicing, servicing of grants (Teacher Education Assistance for College and Higher Education “TEACH” Grants), loan consolidation origination and disbursement, servicing of specialty programs (Public Service Loan Forgiveness “PSLF”, Total Permanent Disability “TPD”), financial reporting, processing specialty claims (discharge, forgiveness, and cancellation) and complete fulfillment. The Government expects the awardee(s) to support the transition to the Next Gen vision. The Government anticipates awarding not more than two contracts as a result of this solicitation.

C.1.2 Contract Type

The resulting award(s) will be a Firm‐Fixed Priced (FFP) Indefinite Delivery, Indefinite Quantity (IDIQ) Contract(s), with the ability to issue Fixed Unit Rate, Time and Materials and Firm-Fixed Priced Task Orders at the sole discretion of the Government. The Government anticipates awarding a five-year Base Ordering Period, followed by five (5), one-year Optional Ordering Periods.

C.2 BACKGROUND, GOALS, AND VISION

C.2.1 Background

FSA plays a central and essential role in America’s post-secondary education community. The federal student aid programs comprise the nation’s largest source of post-secondary education financing. FSA’s core mission is to ensure that all eligible customers benefit from Federal financial assistance – including grants, loans, work‐study programs – for education beyond high school. FSA’s strategic goals are to:

· Enhance the quality of service for customers and partners across the entire student aid life cycle,

· Improve the repayment experiences and outcomes of customers,

· Reduce the cost of loan servicing and collections, and

· Expand FSA’s operational efficiency and flexibility.

Information about FSA can be found in Figure 1 below, and in the 2019 Annual Report located at: https://www2.ed.gov/about/reports/annual/2019report/fsa-report.pdf. Figure 2 represents the Initial State for Servicing work by getting up to two Servicers. After the process of moving loans from the current Servicers to the ISS vendors, FSA plans to add the Busines Process Operations (BPO) Contactors as depicted in figure 3. The ISS vendors will then be the system processors in which the BPO will work to complete loan servicing requirements.

Figure 1: TODAY’S ENVIRONMENT ACROSS THE STUDENT AID LIFECYCLE

Figure 2: ISS ENVIRONMENT FOR PROCESSING AND SERVICING

Figure 3: BPO/ISS ENVIRONMENT FOR PROCESSING AND SERVICING

C.3 OBJECTIVES, REQUIREMENTS, AND MILESTONE

C.3.1 Objectives

The Interim Servicing Solution (ISS) will ensure continued servicing capabilities for FSA’s aid recipients. ISS will also support the transition to the Next Gen vision.

C.3.2 General Operating Requirements The Interim Servicing Solution shall satisfy these general requirements for all operating requirements identified in C.3.3:

a. Integration: Offerors shall integrate with existing FSA or third‐party solutions, and Next Gen solutions, as necessary. FSA will provide integration requirements post-award via the change control process.

b. Adaptability, flexibility, and ongoing performance: Offerors shall adapt and adhere to changes in the FSA operating environment. Contractor(s) shall adhere to the FSA Change Management process as described in Business Operations Requirements. Contractor(s) shall demonstrate that the Solution can easily scale to handle changes in account and transaction volumes.

c. Customer experience focus: Offerors shall prioritize customer needs and preferences to deliver an improved customer experience throughout the ISS environment. Offerors shall implement an approach that minimizes risk and disruption for customers while deploying more efficient and effective solutions. Specifically, FSA anticipates the immediate need for migration from multiple servicing solutions down to no more than two ISS vendors as a necessary step toward ultimately landing on a future state of a single servicing platform operating environment, to be acquired in a future solicitation.

FSA will need to migrate accounts from existing servicers on a rapid but feasible schedule that minimizes disruptions for customers while ensuring complete migration within FSA’s timeline. As part of this solicitation offerors are required to explain their migration plan along with a schedule for migrating the borrowers and their loan data, the timeline it will take to complete and risk mitigation strategies. The current process of loan transfers is described in “Business Operations Requirements – Series 18000”. However, Offerors may propose any solution that will increase the speed and accuracy of the data transfer process.

d. Monitoring and adhering to changes in laws, regulations, and other policies: Contractor(s) at a minimum shall meet existing Federal rules, laws, regulations, and agency guidelines or court mandates applicable to the FSA’s operating environment (including all accessibility elements such as 504/508 compliance). Contractor(s) shall establish a process for monitoring new or pending changes to applicable laws and regulations, then proactively partner with FSA to determine the implications to technical design and/or operational procedures.

e. Cybersecurity, hosting, and middleware: Contractor(s) shall ensure the Solution meets Federal Information Security Management Act (FISMA) and National Institute of Standards and Technology (NIST) standards. Offerors shall refer to the Information Resources Program Elements (IRPE) v 5.0.2 incl Monitoring ISS Tailored”. This attachment requires Offerors to document if they meet, partially meet or do not meet each element of the IRPE.

· Note: If the Contractor(s) elects to use a cloud hosted environment (not a requirement of this solicitation to do so), the FedRAMP‐approved cloud shall require a Department/Agency‐level Authorization to Operate (ATO), followed by the FSA‐issued ATO for the system, which must be FISMA and/or FedRAMP‐approved at either a Federal Information Processing Standard Publication (FIPS)‐199 High level or Moderate level, depending on the proposed architecture and corresponding FIPS‐199 category of the system.

Special Notices

· Section 6103: All Offerors are hereby placed on notice that compliance with the security requirements that are provided in IRS 1075 Publication (See Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies) may be applicable.

f. Financial accuracy and compliance: Contractor(s) shall include measures for ensuring the compliance and accuracy of financial transactions and reporting in ISS. Requirements for existing financial standards are included in “Financial Requirements and associated attachments”.

g. Business Operations Requirements: In addition to security and financial requirements, Contractor(s) shall adhere to the requirements in “Business Operations Requirements and associated attachments”. Offerors are required to document if they meet, partially meet or do not meet each requirement. These requirements are derived from existing laws, regulations, agency guidance, and business rules, and will change based on acts of Congress, updates to Federal regulatory and non‐regulatory guidance, and FSA goals and operational decisions. Moreover, the Life cycle of Title IV servicing functions such, as application processing (e.g., repayment, consolidation, deferment, forbearance, specialty claims), impact the Interim Servicing Solution, among other existing and future solutions, and often relate to multiple constraints/requirements. Specialty programs (e.g., PSLF, TEACH, TPD,) and specialty claims (e.g., discharge, forgiveness) require special handling as well as specific and unique processing rules that impact the ISS, along with other existing and future solutions, and often relate to multiple constraints/requirements.

h. Trained personnel: Contractor(s) shall ensure personnel are trained and aware of pertinent changes in laws, regulations, programs, and FSA’s performance expectations. Development of training content and material is expected to be done in coordination with FSA and/or FSA’s designees.

i. Performance Management: Contractor(s) shall adhere to FSA’s Common Performance Standards and shall include performance management mechanisms that would enable improved and ongoing achievement of metrics. FSA will utilize the performance management framework outlined in Service Level Methodology to support ISS Performance Management and to document achievement of the established Service Level Agreements (SLAs). FSA has established common performance metrics that Offerors shall agree to prior to contract award. Service Levels Agreements establishes the required performance metrics and associated targets that will be used by FSA to measure vendor performance against FSA’s vision and goals. ISS vendors will be expected to meet the required targets established for each Service Level Metric during contract performance.

j. Quality control: Contractor(s) shall document and provide policies/procedures on its quality management system to ensure that quality is measured and managed on a consistent basis.

C.3.3. Operating Elements and Related Requirements

a. Customer Accounts Migration:

· Contractor(s) shall transfer historical and current customer loan and grant accounts from existing servicers to ISS. Contractor(s) shall use the EA27 File, EA80 File, and Supplemental files as outlined in “Business Operations Requirements – Series 18000” to perform the transfers, unless otherwise directed.

· Contractor(s) shall ensure that the transfer successfully converts and maintains complete and accurate customer data, including, but not limited to: customer’s historical record of balances and transactions, loan consolidation, origination and disbursement records (e.g., underlying loan pay‐off, lender detail, funding histories), auto‐pay preferences, complete payment history, deferment and forbearance history, repayment plan history, contact preferences, and prior loan transfer imaged records.

· Contractor(s) shall transfer loan/grant data and images from closed/inactive accounts from each non-default Legacy Servicer. This includes demonstrating the ability to reopen/ rebuild loans and grants and return them to active servicing.

· Contractor(s) shall support the development and delivery of customer communications about the migration of customer accounts before, during, and after the migration per FSA instructions. Communications under this contract to customers being transferred cannot start until after Authority to Operate has been granted.

· Contractor(s) shall convert Loan Consolidation Origination and Disbursement data. Contractor(s) shall convert all underlying loan detail and payoff information including all loan verification detail, loan summary statements, initial payoff information (including all financial and non‐financial transactions), and under and over payment detail from active Consolidation loan origination and disbursement systems. Contractor(s) shall ensure the solution is able to process all under and over payment adjustments regardless of performing the actual origination of the consolidation loan.

· Contractor(s) shall also have the capability to migrate customer accounts effectively and efficiently off their servicing solution with no degradation in servicing of the accounts.

b. Interim Servicing Solution

· Contractor(s) shall ensure the solution can execute the full range of servicing functions as proposed in the Offerors’ proposal in response to “Business Operations Requirements” and associated attachments for the ISS portfolio. Attachment “Business Operations Requirements ISS” will be used by FSA to evaluate Offeror’s approach and understand the requirements being met by the Contractor(s) along with timelines for those requirements which are not currently met. This includes, but is not limited to:

· Contractor(s) shall provide staff, either in-house or through subcontracting, who perform front-end contact center agent and back-office agent work necessary to deliver all servicing requirements.

· Loan statuses (e.g., in-school, in-grace, repayment, delinquency, default (270-360 delinquency), suspense, forbearance, and deferment) and tracking.

· Traditional repayment plans (e.g., Standard, Graduated, and Extended) across Federal Family Education Loan (FFEL), Direct Loans, etc.

· Eligibility determination, annual recertification, and payment recalculation for Income‐driven repayment plans (IDR) tied to a customer’s income, family situation, and other characteristics that may fluctuate. IDR plans include Income‐Contingent, Income‐Based, Pay‐As‐You‐Earn, and Revised‐Pay‐As‐You‐Earn.

· Loan consolidation origination and disbursement, including application, pay off, booking new loans, maintaining account histories, performing all reconciliation and financial reporting, among other activities.

· This includes the processing of under/over payment adjustments for Legacy consolidation loans and any future decommissioned consolidation origination systems.

· Switching between repayment plans

· Retroactive processing (e.g., retroactive application of deferments, forbearances, payments, manual adjustments etc.)

· Contractor(s) shall perform all financial and portfolio level functions as outlined in “Financial Requirements” and the associated attachments including manual intervention; if necessary. This includes, but is not limited to:

· Payment processing, including receipt and applications of cash and non‐cash payments accounts, as well as research and resolution of lost or misapplied payments.

· Interface support, including tracking Work in Process (WIP) and resolving rejected transactions from other FSA systems (e.g., NSLDS, Financial Management System (FMS), Origination & Disbursement System).

· Financial reporting, reconciliation, and variance research

· As needed support of audits {e.g., annual audit reports such as the Service Organization Controls Type II Statements on Standards for Attestation Engagements (SSAE18)}.

· Research and resolution of Treasury issues

· Comprehensive cash management including retroactive processing of manual adjustments and late disbursement and adjustments from the origination & disbursement system, other servicing systems and FSA.

· Dynamic loan portfolio management

· Effective internal financial controls

· Contractor(s) shall ensure and maintain compliance with federal consumer protection laws and regulations (e.g., the Fair Credit Reporting Act, the Fair Debt Collections Practices Act, the Truth in Lending Act, etc.), including the timely completion of processes related to these laws and regulations. Contractor(s) shall review, investigate, and process error and dispute resolutions, including but not limited to:

· Direct Disputes and disputes that the customer initiated/filed with Credit Reporting Agencies (CRAs) for accounts assigned to the Contractor(s).

· Contractor(s) shall receive and process all disputes.

· Contractor(s) shall conduct error and dispute resolution investigation and processing, including, but not limited to:

· Account maintenance, including manual correction of errors identified through data integrity scans and manual adjustments as identified by FSA.

· Payment and refund processing, including researching lost or misapplied payments and payment reapplication at the request of customers or FSA.

· Contractor(s) shall maintain data history, including retroactive processing (e.g., “as‐was” vs “as‐is”), and tracing loans through consolidation payoff (initial payoff, under and over payments) transactions. This data shall be available and shared with other solutions and systems as directed by FSA.

c. Imaging, Printing, and Mailing:

· Contractor(s) shall receive, image, index, and process physical mail. Contractor(s) shall also provide tracking of and reporting on outbound mail items. Contractor(s) shall identify cost efficiency opportunities and work with FSA to implement changes to processes and practices (e.g., statement or envelope design).

· Contractor(s) shall generate and send all servicing communications (physical and electronic). For all specialty programs not currently supported, the Contractor(s) shall create draft communications and provide to FSA for review and approval.

· Contractor(s) shall enable customers, partners, and other relevant third parties to be able to fax materials to and tag the faxes upon receipt for tracking.

· Contractor(s) shall image and index inbound correspondence, including physical checks, as well as materials received via fax. Contractor(s) shall then provide access or visibility to the images.

· Contractor(s) shall provide Skip Tracing tools to identify updated contact information for bad postal mail and bad phone numbers.

· Contractor(s)’s solution shall be integrated with Workflow Management, imaging, Digital Platform, and CRM, among other solutions.

d. Digital Engagement Layer:

· Contractor(s) shall provide a digital engagement (website and/or mobile application) solution for customers and partners to be able to interact with FSA and complete customer (e.g., view statements, and make payments) and partner tasks (e.g., view student loan history and download resources for students).

· Contractor(s) shall ensure a seamless transition of customers and partners to digital engagement layer (e.g., customer payment and communication channel preferences).

· Contractor(s) shall provide an access portal to Title IV partners (e.g. schools, FSA, etc.) as described below:

· The access shall provide customer account access to FSA, Schools, and other trading partners as approved by FSA. The portal shall display, at a minimum, customer demographic detail, loan and grant detail, loan and grant disbursement detail, and access to images (bills, repayment plans, applications, communications etc.).

· The portal shall include a Loan Holder Services website that Guarantee Agencies (GA) and Lenders will use for loan consolidation application processing.

· The portal shall be updated to include TPD, TEACH, and PSLF loan and grant data that will be accessed by FSA, Schools, and other trading partners

· The portal shall allow FSA and other trading partners (Schools will not access this data) access to the FSA Image Repository, Decommissioned Servicer data, and Legacy Consolidation Support data as outlined in Optional Tasks 2, 3, and 4 below.

C.3.4 Optional Tasks FSA reserves the right to award Optional Tasks to one or both Contractor(s).

· Optional Task 1: FSA Image Repository - The Contractor(s) shall transfer in, maintain, and provide access to an FSA image repository. The repository maintains all historical images from previously decommissioned servicing systems and ancillary systems. All images shall be accessed via the partner portal. See “Business Operations Requirements – Series 11000”.

· Optional Task 2: Decommissioned Servicer Data Support and Payment Support Servicing Functions - This includes archived data that is stored for decommissioned servicers (ACS Education Servicing System (ACES), Direct Loan Servicing System (DLSS), and other decommissioned servicer data as identified). Contractor(s) shall provide FSA the ability to access pre‐defined queries, which will be provided after award, as well as perform ad‐hoc queries of the data.

· Contractor(s) shall provide FSA the ability to access pre‐defined queries, which will be provided after award, as well as perform ad‐hoc queries of the data.

· The contract shall provide payment support services such as processing refunds, researching missing payments, providing check copies, etc.

· See “Business Operations” for more information.

· Optional Task 3: Legacy Loan Consolidation Origination and Disbursement Support Functions - This includes performing all manual adjustments received for underlying loans held by FFEL, GA, DMCS, and Direct Loans that were consolidated by a Legacy Loan Consolidation Vendor.

· Contractor(s) shall process all under/over payments received on Legacy Consolidation Loans.

· Contractor(s) shall convert all data for all under/over payment adjustments that have been processed since the Legacy vendor was decommissioned.

· Contractor(s) shall create updated Consolidation Origination Loan History Record’s for each adjustment processed and upload them to the FSA Image Repository.

· See Attachment “Business Operations Requirements – Series 29000 for additional information regarding the creation of adjustment spreadsheets needed to complete the adjustment processing.

· Optional Task 4: Specialty Program PSLF-

· Contractor(s) shall perform all requirements for the PSLF program as outlined in the regulations, “Financial Requirements” and associated attachments, and “Business Operations Requirements” and associated attachments.

· Optional Task 5: Specialty Program TPD-

· Contractor(s) shall perform all requirements for the TPD program as outlined in the regulations, “Financial Requirements” and associated attachments, and “Business Operations Requirements” and associated attachments.

· Optional Task 6: Specialty Program TEACH-

· Contractor(s) shall perform all requirements for the TEACH program as outlined in the regulations, “Financial Requirements” and associated attachments, and “Business Operations Requirements” and associated attachments.

C.3.5 Deliverables

C.3.5.1 Format Deliverables shall be provided electronically whenever possible. Electronic delivery via e-mail shall be acceptable, with the files delivered in both Acrobat (.pdf) and a current Microsoft Office format suitable for the report (Word or Excel) unless FSA requests a different format.

Delivery Points of Contact Deliverables shall be submitted to the Contracting Officer, the Contracting Officer Representative (COR), Program Manager, and Project Manager.

Review Period The Government shall review each deliverable and provide written notice of acceptance or rejection within ten (10) Business Days upon receipt.

Upon notice of formal written rejection from FSA’s CO, the Contractor(s) shall address all comments/changes and submit a revised deliverable within five (5) Business Days if the changes can be easily addressed and understood by both the Government and Contractor(s). If the deliverable is rejected and/or must be altered to significantly change the deliverable, the Contractor(s) will have seven (7) Business Days to resubmit from date of the Government’s notice. The Contractor(s) shall furnish deliverables specified herein in accordance with the delivery schedule and requirements, to the Delivery Point(s) specified above and in the table below. If a deliverable is due on a calendar day that falls on a weekend day or a Government holiday, the deliverable or report is due the following Business Day.

C.3.5.2 The Contractor(s) shall furnish deliverables specified herein in accordance with the delivery schedule and requirements, to the delivery point(s) specified in the table below.

For all IRPE requirements, which the Contractor(s) listed as met in their proposal, FSA and the Contractor(s) will create deliverable schedules and acceptance criteria within forty (40) Business Days of contract award date.

For those IRPE requirements that are listed as NOT MET, the vendor and FSA shall work together to established deliverable schedules and acceptance criteria once the requirements are met.

FSA Deliverable Table

Deliverable
Description
Due Date and Frequency
Acceptance Criteria
Project Kick‐Off Meeting
Kick‐off meeting to begin discussions on detailed requirements and the project schedule.

· Presentation

· Meeting Minutes Within five Business Days after award

Project Management Plan
Detailed project management plan and project schedule for the complete contract scope. Includes:

· Scope Management Plan

· Cost Management Plan

· Risk Management Plan

· Quality Management Plan

· Resource Management Plan

· Schedule Management Plan

· Communication Management Plan

· Performance Management Plan

· Performance Monitoring Plan Three weeks after award

Status Meetings and Status Reports
Status report on progress, performance metrics, schedule, incidents, action and issue log, and risk log/risk register.
Weekly
Integrated Master Project Schedule
Planned dates to start and complete tasks and milestones, including work to be done by FSA, as well as any vendors participating in the project.
Updated weekly
Requirements Management Plan
Defines:

· How requirements will be elicited, structured, and prioritized

· How requirements will be recorded

· How requirements will be modified

· How requirements will be traced and reconciled.

· Initial plan to cover all system functionality at least five days prior to Requirements Stage Gate and annually thereafter

· Updated for each release

· Final version for each release delivered prior to Requirements Stage Gate

Requirements Documents
· High Level Requirements

· Detailed Requirements

· Product backlog

· Requirements Traceability Matrix (RTM) – requirements mapped to test cases

· Initial documents to cover full system functionality at least five days prior to Requirements Stage gate and annually thereafter

Data Migration Plan
Defines processes associated with completion of data migration effort, including conversion/migration strategies, data mapping requirements, data clean up, and testing.
· Updated for each release
Quality Assurance Quality Control Plan
Defines the processes associated with Quality Assurance across the deliverables.
· Within 40 Business Days of contract award
Staffing Plan
Explains the details to the number of staff needed and how the Contractor(s) will meet that number while the migration of borrowers is happening. The staffing plan should relate to the migration plan based on total borrower transferred per month
· Within 20 Business Days of contract award
Transfer Plan
Defines processes associated with completion of data migration efforts, including conversion strategies, data mapping requirements, data clean‐up,

and testing.

· Within 10 Business Days of contract award

Solution Architecture and Detailed Design Document
Combines both a high‐level and detailed view of the solution architecture

· Includes description and diagrams of infrastructure, network, security, data, and application architectures

· Addresses all Technical Quality Control (TQC) factors and sub‐ factors identified as applicable and in scope

· Includes mitigation strategies for all risks identified in the Technical Quality Control reviews

· Includes Interface Control Documents (ICDs) to document all interfaces between systems and subsystems, including APIs, data required, data returned, error handling, and communications, etc.

Conveys detail necessary to allow coders to develop the system, and to support critical design reviews before beginning development

· Initial documents to cover full system functionality, at least 5 Business Days prior to Design Stage Gate Attachment “11 ‐ Information Resources Program Elements (IRPE) Supplement” Lifecycle Management Methodology (LMM) section and annually thereafter

· Final version for each release delivered at least 5 Business Days prior to Design Stage Gate

Developers’ Integration Guide
Documents how internal and external parties will integrate with and consume the APIs/services that are exposed.
· Initial document to cover full integrations at least five business days prior to Design Stage Gate and annually thereafter

· Final version for each release delivered at least five business days prior to Design Stage Gate

Configuration Management Plan
An overview of the organization, activities, overall tasks, and objectives of configuration management. Addresses: baseline work products, describes the mechanism to track and control changes/change requests, and the mechanism to establish and maintain baseline integrity
· Initial plan to cover full system functionality at least five business days prior to Test Readiness Review as outlined in Attachment “11 ‐ Information Resources Program Elements (IRPE) Supplement” Lifecycle Management Methodology (LMM) section and annually thereafter.

· Final version for each release delivered prior to Test Readiness Review

Master Test Plan
Details high level and overall test planning and test management

· Includes System, User Acceptance, Performance, Inter‐system, etc. test plans

· Master Test Plan includes objectives for the security control assessment and procedures for testing each

· security control

· Initial test plan to cover full system functionality at least five business days prior to Test Readiness Review

Testing Documentation
· Release Test Plan – includes all the testing that will be performed for the release, the timelines, and participants

· Test Suites ‐ test scenarios, test cases and test scripts for a component or system under test

· User Acceptance Test Summary Report

· System Test Summary Report

· Defect Management Report

· QA and QC records

· Post Implementation Validation Plan – identifies the testing that will be completed during go‐live or after go‐live to validate that the functions of the system or changes to it are

· correctly working

· Initial testing documentation to cover full system functionality at least five business days prior to Test Readiness Review for the system testing and then again for User Acceptance Testing (UAT)

Database detail
· Data Dictionary: Field name, field definition (in simple to understand terms), valid values for the content, field format/length for data stored in the servicing system (i.e., databases, access databases, tables, and spreadsheets)

· Dictionary includes: Historical transactional data for all actions (financial and non‐financial) taken on an account including but not limited to payments, refunds, schedule histories, credit reporting, and communication (Paper, email, fax, etc.) data

· Volume of Data

· Procedures and Training Materials (Catalog and actual documents.

· Data dictionary/ documentation thirty calendar days after award and yearly thereafter to include volume of data or Upon Request

· Procedures and training materials prior to Initial Test Readiness Review, prior to each release Test readiness review, annually thereafter

Implementation Documentation
· Release Version Description Document

· Solution User Manual

· Implementation Plan: includes an hour‐by‐hour schedule for all tasks to accomplish implementation and possible roll‐back

· Transition Management Plan

· Training Plan

· Operations and Maintenance Plan: includes a full description of how the system will be monitored, maintained, and managed if incidents occur. Also includes capacity management, incident and problem management, and daily production reporting.

· Standard Operating Procedures

· Production Readiness Review (PRR) Prior to receiving Authorization to Operate and a review and possible revision for each release

Lessons Learned Reports
All aspects of the project or project stage are analyzed, and results and opportunities for improvement are

· documented Within 10 Business days after each release

System Security and Privacy Documentation
Privacy Artifacts:

· Privacy Threshold Analysis (PTA)

· Privacy Impact Assessment (PIA)

· System of Records Notice (SORN) External Data Exchange Artifacts:

· Memorandum(s) of Understanding

· (MOUs)

· Computer Matching Agreement(s)

· Interconnection Security Agreement(s) (ISA) Continuity of Services Artifacts:

· Business Impact Assessment (BIA)

· IT Contingency Plan (Includes Test Plan)

· Disaster Recovery Plan System Security Documentation Artifacts:

· Data Sensitivity Worksheet

· System Authorization Boundary

· System Security Plan (SSP)

· Incident Response Plan (IRP)

· Breach Notification Policy and Response Plan Security Risk Assessment Artifacts:

· Security Assessment Plan

· System Security Documentation Checklists

· Security Assessment Report

· Plans of Actions and Milestones (POAMs)

· Data Retention Schedule Prior to receiving Authority to Operate. Then revised annually or when changes to the security posture of the system requires it.

Security Documentation Post‐ATO
Property Management Plan

· FISMA Metrics Report

· Annual Self‐Assessment (if not in OSA program)

· Incident Response Test Plan and Test Report

· Contingency Test Plan and Test Report

· Standard Operation Procedures

· System Retirement Plan System Disposal Plan Updated as changes occur or directed by FSA

Continuous Monitoring Plan
Includes continuous monitoring of all security requirements and delineates all the ATO deliverables.
At initial ATO, for each release, and annually
Transition Support (Phase‐Out)
Phase‐Out Plan
40 Business Days prior to the completion of this contract (to include option periods)
Security Reports
· CyberScope Report

· Clearance and Suitability Report

· Application Access Report

· Staffing Change Report

· Recertification of User Access and Authenticator Activation Monthly

Contractor(s) PIV and PIV‐I Card Deliverable
· Monthly Vendor Employee Report (FAR 35‐9 deliverable)
First Business Day after the close of each month
Contractor(s) Solution Development Processes
· Contractor(s)’ System Development Life cycle

· Contractor(s)’ Software Development Life cycle

· Contractor(s)’ Software Engineering Handbook Upon request

Technology Business Management (TBM) Data Report
Completed TBM Data Report Template in accordance with the instructions in the annual A‐11 OMB Circular on the Budget Submission Requirement, specifically in the section containing the Capital Planning and Investment Control (CPIC) for IT Investments.
Quarterly
Operational and Financial Reports
Completed reports delivered as outlined

in the Business and Financial Requirements Daily, weekly, monthly as required for each individual report

Metrics and Invoice Reports
Completed reports to support performance metrics and invoicing
Monthly
Labor Category Worksheet
Excel worksheet to include the following:

· List of direct, indirect, and overhead labor categories,

· Labor rates by category for the 10‐ year period of performance

· Labor category descriptions

· Security Designations

· Work performed by labor category Annually ‐ Updated with any changes or additions to labor categories, rates, descriptions, and type of work performed

NIST Cost Capabilities Report
Completed NIST Cost Capabilities Report Template. Percentage of total cost associated with each selected NIST Capabilities Cost. The total of the percentages must be 100% of the Security and Compliance Cost Tower in the TBM Data Report deliverables.
10 Business Days after award. Twice a year in August and February

C.6 EXPECTED VOLUMES (For Informational Purposes)

FSA expects that many of the customer and partner engagement figures will significantly change in the future as new solutions are implemented (e.g., a digital platform with greater self‐service functionality will create less need for inbound calls and outbound postal mailings). The volumes presented below are illustrative and not comprehensive of all activities across the full life cycle of student financing. This information does not guarantee the level of work or volume in the future.

Overall size of business:

· Approximately 33 million non-default customers being serviced in the FSA environment

· Customer base projected to grow approximately 21% between 2019 and 2028

· Lending portfolio that exceeds $1 trillion in outstanding principal

· Over 18 million loans assigned to servicers last year with a significant portion (58%) assigned between August and October

· ~43 million online accounts accessed each month, of which 30 million access via desktop and 12 million via mobile or tablet

· ~6,000 Partners plus state agencies, accreditors, States Attorneys General, and other relevant entities that support Title IV disbursement, administration, and compliance/enforcement

Student aid servicing:

· >200 million payment transactions are processed annually

· >5 million annual re‐certifications for an income‐driven repayment plan submitted annually

· ~4 million loans closed or discharged annually due to death, disability, payment in full, or other reasons (not including consolidation)

· ~840,000 loans consolidated annually, impacting an average of five loans per borrower

· ~3 million repayment plan changes annually, impacting the status of ~16 million loans

· >4 million loans transferred from servicers to FSA’s Debt Management and Collection System (DMCS) each month

· ~900,000 TEACH grant certifications submitted annually

· ~420,000 PSLF certifications submitted annually

· ~178,000 TPD certifications submitted annually

Page | 2 image1.png image2.png image3.png

File details come from the government source that posted it. Updated .