Task_Order_One_Performance_Work_Statement_Rev_5.30.13.pdf

PDF 1 MB Posted

Attached to
Finanical & Management Support Services Federal contract opportunity
Solicitation number
ED-FSA-13-R-0017
Issued by
Department of Education Office of Federal Student Aid

About this file

Revised Task Order PWS

View the file

Other files for this federal contract opportunity

Other files attached to Finanical & Management Support Services, newest first.
File Type Posted
Amendment_1.pdf PDF
Instructions _Provisions _ _Evaluation_Rev_5.30.13.pdf PDF
RFP_ED-FSA-13-R-0017_SF1449_ _IDIQ.pdf PDF
RFP_ED-FSA-13-R-00017_Task_Order_One_PWS.pdf PDF
Attachment_A_Client_Reference_Form.doc DOC document
RFP_ED-FSA-13-R-0017_Instructions_Provisions_Evaluation.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

TASK ORDER ONE

Title IV Additional Servicers

Attestation and Management Support Services Revised Performance Work Statement

1.0 Background

Federal Student Aid (FSA), an office of the Department, plays a central and essential role in America's postsecondary education community. FSA's core mission is to ensure that all eligible individuals benefit from federal financial assistance—grants, loans and work-study programs—for education beyond high school. FSA administers the programs that comprise the nation's largest source of student aid.

In 2008, Congress enacted the Ensuring Continued Access to Student Loans Act (ECASLA), which authorized the Department to purchase or enter into forward commitments to purchase certain Federal Family Education Loan (FFEL) loans. In June 2009, FSA awarded four (4) contracts, known as the Title IV Additional Servicers (TIVAS) contracts to service and manage all Title IV aid starting September 2009. In March 2010, Congress enacted the Student Aid and Fiscal Responsibility Act (SAFRA). This legislation eliminated the authorization to originate FFEL loans. Beginning July 1, 2010, all federal student loans are originated through the William D. Ford Federal Direct Loan (DL) program. As a result, the vast majority of schools participating in the FFEL program transitioned to the DL program.

The four (4) TIVAS are as follows:

Sallie Mae (SLM) located at 12061 Bluemont Way Reston, VA 20190 Nelnet (NN) Servicing, LLC located at 121 South 13th Street, Ste.201, Lincoln, NE 68508-1904, Great Lakes (GL) Educational Loan Services located at 2401 International Lane., Madison, WI

53704-3121 Pennsylvania Higher Education Assistance (PHEAA) located at 1200 North 7th St., Harrisburg.

PA 17102-1444

2.0 Base Period of Performance

2.1 Objective

The goal of this effort is to obtain an Agreed Upon Procedure engagement under American Institute of Certified Public Accountant (AICPA) AT Section§201, reviewing each TIVAS’ invoicing and pricing practices so that FSA Contracting Officer (CO) can certify them as accurate. That is, the contractor shall ensure that their methods/practices used are accurate, complete, and within proper internal controls as to protect the taxpayer from fraud and waste.

2.2 Scope

During this period of performance, FSA requires attestation and management services to support FSA in determining the:

1) Validation and accuracy of each servicer’s invoicing system application. That is, the contractor will review servicer’s code logic and extraction queries, current internal controls in the production environment, and configuration/change management process.

a. Selection of a statistically significant sample of invoices submitted by TIVAS from January 1, 2009, through September 30, 2011 and validate their accuracy and reporting on any discrepancies found. FSA processed 112 invoices totaling $337,363,472 during this period.

RFP #ED-FSA-13-R-0017 May 30, 2013 Page 2 of 6

Title IV Additional Servicers (TIVAS) use various system/database applications to generate invoice based on borrower volume and borrower status in accordance with the contract terms. FSA will provide access to the actual code queries/extract from each servicer’s application as well as contract pricing schedule, deliverables, and change requests.

Each servicer’s invoicing system applications/database is listed below:

Sallie Mae - IBM Enterprise COBOL for z/OS PHEAA/Great Lakes - SAS/BASE NelNet - TransAct-SQL (proprietary extension to Microsoft/Sybase SQL)

3.0 Option Period(s) of Performance

3.1 Background

Health Care and Education Reconciliation Act of 2010, Section 2212 provides that: “The Secretary shall contract with each eligible not-for-profit servicer to service loans originated under this part, if the servicer (I) meets the standards for servicing Federal assets that apply to contracts awarded pursuant to paragraph (1); and (II) has the capacity to service the applicable loan volume allocation described in subparagraph (B).”

FSA has awarded contracts to the following firms:

Aspire Resource, Inc. located at 6775 Vista Dr., West Des Moines, IA 50266-9307 Missouri Higher Educational Loan Authority (MOHELA) located at 633 Spirit Dr., Chesterfield, MO 63005-1243 Utah Higher Education Assistance Authority (UUEAA) located at 60 S. 400 West, Salt Lake City, UT 84114-5112 Educational Servicers of America (ESA), Inc. located at 104 North Seven Oaks Dr., Knoxville, TN 37922-2359 New Hampshire Higher Education Loan Corp. (NHHELC) located 4 Barrell Ct., Concord, NH 0330 South Carolina Student Loan Corporation (SCSLC)/EdManage located at 8906 Two

Notch Rd., Columbia. SC 29223-6366 Oklahoma Student Loan Authority (OSLA) located at 525 Central Park Drive, Suite

600 - Oklahoma City, OK 73105 Vermont Student Assistance Corporation (VSAC) located at 10 East Allen St., Winooski, VT

05404 Kentucky Higher Education Student Loan Corporation (KHESLC) located at 10180 Linn

Station Rd., Ste. C200, Louisville, KY 40223 College Foundation, Inc. (CFI) located at 2917 Highwoods Blvd., Raleigh, NC 27604 Council for South Texas Economic Progress (COSTEP) 2540 W. Trenton Rd., McAllen, TX

78539

3.2 Objective

Based on the approved agreed-upon procedures from base period effort, the goal of this effort is to obtain objective review of each servicer’s invoicing and pricing practices so that FSA Contracting Officer (CO) can certify them as accurate. That is, the contractor shall ensure that their methods/practices used are accurate, complete, and within proper internal controls as to protect the taxpayer from fraud and waste.

RFP #ED-FSA-13-R-0017 May 30, 2013 Page 3 of 6

Furthermore, FSA may require assistance on addressing audit and/or internal control findings by improving management reporting as well as other self-disclosed statement from these servicers. Title IV Additional Servicers (TIVAS) and Not-for-Profit (NFP) are referred to as ‘servicers’ for the purposes of this effort.

3.3 Scope

FSA requires attestation and management services to support of FSA Acquisitions Group and other business unit offices in determining:

1) Adequacy of cost or pricing data in the contractor’s proposals against actual expenditures.

That is, the contractor will review and evaluate the servicers’ change request (CR) proposal pricing to determine if past CR proposals represented appropriate compensation for the actual work performed. This review will assist the government in estimating level of effort for future CR requirements.

2) Compliance with contractual invoicing/billing terms to ensure proper payments is being made to these servicers. That is, the contractor will ensure that the servicers’ invoices accurately reflect the number of borrowers to be billed and under what the status.

3) Validation and accuracy of each servicer’s invoicing system application.

4.0 Place and Period of Performance

The base period of performance shall commence on the date of award and conclude six (6) months thereafter with two (2) option periods lasting six months each.

Task order term will not exceed 18 months, unless an extension of services is required.

The majority of the work will be performed at the contractor’s facility except for occasional meetings at FSA’s headquarters located at 830 First St., NE, Washington, DC 20202.

However, the contractor may need to travel to the servicers’ facilities. All such costs require documentation support to accompany all invoices in accordance with FSA 31-1 Contractor Travel Expenses (April 2013). Local travel is not subject to reimbursement.

5.0 Contract Type

Work under this Task Order shall be performed on a Time and Material (T&M) basis.

6.0 Deliverable Schedule

Contractor shall produce, maintain, and deliver the following:

Title/Format Brief Description Due Date Updated Master Schedule/ MS Project

Task activities, duration, start/end dates, and assigned resources (by name/labor category) with a work breakdown structure (WBS) at level 3 identifying critical path task and milestones.

Five (5) business days after post-award conference/project kickoff meeting.

Changes shall be incorporated and submitted with the monthly status report unless immediate notification to the government is deemed necessary by the contractor.

RFP #ED-FSA-13-R-0017 May 30, 2013 Page 4 of 6

Title/Format Brief Description Due Date Monthly Status Report/ MS Word 2010

Activities completed and planned along with key risks and issues.

Summary of labor cost incurred including non-local travel expenditures as well as invoiced amount and remaining balance of funding.

Third (3rd) Thursday of each month

Preliminary Finding Report/ MS Word 2010 with line numbering

Summary identifying all results/conclusions reached on the subject matter or the assertion being reported on and state the character of the engagement.

Complete and accurate working papers that document all work performed, support conclusions reached and are consistent with American Institute of Certified Public Accountants (AICPA) and Defense Contract Audit Agency (DCAA) standards and in accordance with GAGAS.

TBD

Final Findings Report/ Adobe Acrobat

Incorporation of the government’s comments and proposed recommendation to address all findings.

Five (5) business days after receipt of the government

7.0 Acceptance Criteria

All deliverables shall be delivered electronically to the Contracting Officer and his/her representative and shall adhere to the industry and government standards.

The government shall review the deliverable to determine that:

It addresses the government’s requirement as stated in this PWS;

It is organized appropriately and written clearly;

The information incorporated is accurate, complete, and relevant;

It is formatted in either MS Word or Adobe Acrobat; and It adheres to industry (e.g., AICPA AT §201), government (e.g., DCAA), and FSA standards, guidance, and regulations (e.g., Management’s Program Reviews from FSA Program Compliance or Management’s IT assessments as a function of security authorization, formerly certification and accreditation from FSA Technology Office), as applicable and related with regard to documentation content, format, quality, and contractual terms.

Note: Non-conforming services/deliverables will be corrected at no additional cost to the government.

8.0 Performance Measures/Quality Assurance Surveillance Plan (QASP)

Desired Outcomes Reports/Plans Work Products/ Assignments Performance Standard The Contractor must submit these reports/plans in accordance with the deliverable schedule and acceptance criteria.

The Contractor must submit these documents or perform these assignments in timely manner as directed in advance by the Contracting Officer and/or Contracting Officer’s Representative

(COR).

RFP #ED-FSA-13-R-0017 May 30, 2013 Page 5 of 6

Desired Outcomes Reports/Plans Work Products/ Assignments Performance Indicator Quality and Timeliness Quality and Timeliness Place of inspection Destination – FSA headquarters Destination – FSA headquarters Due Date of Deliverable/ Performance of Service

In accordance to the deliverables schedule.

As required by CO or COR throughout the contract period.

Acceptable Quality Level

(AQL)

95% 95%

Monitoring Method Review of the initial or revised report.

Review of documents or observation of performance of the work outlined in the

PWS.

Notification of Conformance

Written/Conditional Acceptance or Rejection with Supporting Rationale.

Written/Conditional Acceptance or Rejection with Supporting Rationale.

No. of Days Provided to Correct Non-conforming Service/Deliverable after Rejection

Five (5) business days (unless an extension is authorized by the CO or COR in writing (including e-mail).

Five (5) business days (unless an extension is authorized by the CO or COR in writing (including e-mail).

Total Number of Corrections Authorized After Rejection

One (1) - unless an exception is authorized by CO in writing.

One (1) - unless an exception is authorized by CO in writing.

9.0 Constraints

The contractor shall perform services in accordance with applicable laws, regulations, and policies, and guides as outlined in the Indefinite Delivery/Indefinite Quantity (IDIQ) Paragraph H.1: Applicable Laws, Regulations, Policies, and Guides.

For contractor employees and subcontractor employees who will perform under this effort are required to have or obtain Moderate Risk (5C) security clearances in accordance with the Department’s Directive OM 5-101, Contractor Employee Personnel Security Screening (see embedded document below).

Security screening forms and paperwork may be obtained from the Contracting Officer’s Representative (COR). These forms must be completed and submitted to the COR a minimum of twelve (12) business days prior to the expected employees’ arrival/work start date.

10.0 Staffing and Responsibilities

10.1 Government Staffing and Responsibilities

FSA shall provide a COR who will serve as the primary point of contact on technical matter and perform the following activities:

Define, monitor, and assess Contractor activities and deliverables Provide clarification on business requirements and technical design issues Review and approve the Contractor’s project plans and proposed technical solutions Recommend acceptance or rejection of submitted deliverables to the Contracting Officer who is the sole individual responsible for issuing final inspection and acceptance notice to the contractor.

dega.hussen Sticky Note Unmarked set by dega.hussen dega.hussen Typewritten Text dega.hussen Typewritten Text Directive is enclosed as an attachment.

dega.hussen Typewritten Text

RFP #ED-FSA-13-R-0017 May 30, 2013 Page 6 of 6

10.2 Contractor Staffing and Responsibilities

Any access to necessary facilities, IT systems, and/or data will be based on the contractor’s personnel ability to obtain the requisite security clearance stated in paragraph 9.

Ownership of information and documents prepared in accordance with this contract shall become and remain property of the Federal Student Aid. It is the contractor’s responsibility to ensure system and data security as well as all individual personal data security.

11.0 Key Personnel Requirement

The Contractor shall provide key personnel who are committed to this project and available as needed.

Key personnel are defined as personnel assigned to the labor categories that the Federal Student Aid has designated as essential to the work to be performed. Federal Student Aid retains the right to review qualifications for all staff assigned or proposed to be assigned to this agreement.

Key personnel identified in the Contractor’s proposal must perform the work defined unless the Contracting Officer has approved any substitutions in writing. Any proposed substitutions shall possess qualifications equal or superior to those of the key person being replaced. Before removing, replacing, or diverting, any of the proposed key personnel, the Contractor shall:

Notify the Contracting Officer and Contracting Officer’s Representative (COR) a minimum of thirty (30) calendar days in advance Submit justification in sufficient detail to permit evaluation of the impact on this replacement Provide a resume and qualification’s statement for the proposed substitute Ensure that the replacement is fully aware of the status of work in progress and is briefed on key decisions and upcoming deadlines Demonstrate that the replacement has been sufficiently prepared so that work may continue without interruption or delay

11.1 Qualifications by Position Type

a) Audit Manager

Minimal qualifications: a bachelor's or graduate degree with at least ten (10) years of auditing experience and is a Certified Public Accountant. Three (3) or more years in managerial positions.

b) Supervising Senior Auditor/ Senior Auditor

Minimal qualifications: a bachelor's or graduate degree in area of accounting, finance, or related discipline with at least 5 years of auditing experience. Certified Public Accountant certification is preferable but not required.

c) Senior Information Technology (IT) Analyst (Only for Base Period)

Minimal qualifications: a bachelor's in computer science or related area with at least 4 years of programming, development, and analysis experience. Expertise in programming Extract Transform and load (ETL) processes for Microsoft SQL Server, developing/maintaining websites utilizing Java, SAS, and CICS COBOL is desired.

1.0 Background
2.0 Base Period of Performance
2.1 Objective
2.2 Scope
3.0 Option Period(s) of Performance
3.1 Background
3.2 Objective
3.3 Scope
4.0 Place and Period of Performance
5.0 Contract Type
6.0 Deliverable Schedule
7.0 Acceptance Criteria
8.0 Performance Measures/Quality Assurance Surveillance Plan (QASP)
9.0 Constraints
10.0 Staffing and Responsibilities
10.1 Government Staffing and Responsibilities
10.2 Contractor Staffing and Responsibilities
11.0 Key Personnel Requirement
11.1 Qualifications by Position Type

Untitled

DEPARTMENTAL DIRECTIVE

OM:5-101 Page 1 of 17 (07/16/2010)

Distribution: Approved by: _____/s/______________________ All Department of Education employees Winona H. Varnon

Principal Deputy Assistant Secretary for Management

Contractor Employee Personnel Security Screenings

Table of Contents

I. Purpose II. Policy III. Authorization IV. Applicability V. Definitions VI. Procedures and Responsibilities

A. Principal Office (PO) B. Senior Procurement Executive C. Department Requirements for Contractor/Contractor Employees D. Chief of Personnel Security E. Chief Information Officer (CIO) F. Senior Agency Official for Privacy (SAOP)

Appendix I: Position Risk Designation for Contractor Positions Position Risk Level and Required Investigation and Forms Summary of Investigative Types and Coverage

Appendix II: Position Designation Record for all Applicable Contractor Positions

For technical questions regarding this Administrative Communications System (ACS) document, please contact the Chief of Personnel Security on 202-260-7727.

This ACS document supersedes OM:5-101 “Contractor Employee Personnel Security Screenings” dated 01/29/2008.

ADMINISTRATIVE

COMMUNICATIONS SYSTEM

U.S. DEPARTMENT OF EDUCATION

OM:5-101______________________________________________Page 2 of 17 (07/16/2010)

I. Purpose

The purpose of this Directive is to establish the U.S. Department of Education’s (ED) policy regarding the personnel security screening requirements for all contractor and subcontractor employees (referred to as ‘contractor employees’) assigned to positions that require personnel security screenings. These contractor and subcontractor employees will not have access to classified national security information.

If a contractor or subcontractor employee will require access to classified national security information in order to provide a contractual service at ED, the Security Services, Office of Management, must be contacted for guidance.

II. Policy

It is the policy of ED to ensure that all contractor and subcontractor employees undergo personnel security screenings if required for performance under a contract (see Part IV, Applicability).

III. Authorization

A. Executive Order 13467, Reforming Processes Related to Suitability, Fitness for Contractor Employees, and Eligibility for Access to Classified Information, July 17, 2008.

B. Homeland Security Presidential Directive Number 12 (HSPD-12), “Policy for Common Identification Standard for Federal Employees and Contractors.”

C. Privacy Act of 1974, 5 U.S.C. 552a, as amended.

D. U.S. Code Title 42, The Public Health and Welfare, Chapter 132, Subchapter V –

Child Care Worker Employee Background Checks, Section 13041

E. Appendix III to OMB Circular No. A-130 – Security of Federal Automated

Information Resources.

F. NIST FIPS 201-1, Personal Identity Verification (PIV) of Federal Employees and

Contractors, NIST, March 2006.

G. Federal Information Security Management Act (FISMA), Title III of the E-

Government Act (Public Law 107-347).

IV. Applicability

A. All ED contractor and subcontractor employees must undergo personnel security screenings if, during the performance of the contract, they will:

1. Require an ID badge granting unescorted access to ED facilities;

OM:5-101______________________________________________Page 3 of 17 (07/16/2010)

2. Require ED IT system access;

3. Require access to unclassified sensitive information, such as Privacy Act-protected, personally identifiable, proprietary or other sensitive information and data; or

4. Perform duties in a school or location where children are present.

V. Definitions

Chief of Personnel Security

A management official within OM Security Services responsible for making personnel security adjudication determinations on the access of contractor employees to ED facilities, unclassified sensitive information, and IT systems, or to schools or locations at which they perform duties where children are present.

Computer Security Officer

An individual formally designated by the head of a PO to be responsible for the implementation and management of the Information Technology (IT) Security Program within his or her organization.

Contractor Employee

For the purpose of this Directive, a non-Federal employee working on an ED contract, including a subcontractor employee, who (1) requires an ID badge granting unescorted access to ED facilities; (2) requires ED IT system access; (3) requires access to unclassified sensitive information, such as Privacy Act-protected, personally identifiable, proprietary or other sensitive information and data; or

(4) performs duties in a school or location where children are present.

Contracting

An individual with the authority to enter into, administer, or terminate contracts and execute related determinations and findings within the limits of the authority delegated. Only a contracting officer has the authority to contractually bind the government.

Contracting Officer’s Represen-tative (COR)

A program office representative responsible for monitoring the programmatic or technical requirements of a particular contract, and performing all contract management duties as assigned. The COR serves as the technical liaison between the contracting officer and the contractor, and provides technical advice to the contracting officer for necessary contract administration actions. An individual is appointed as a COR on a particular contract by written delegation of authority from the contracting officer.

e-QIP

Electronic Questionnaires for Investigations Processing (e-QIP) – A web-based automated system that has been developed by the Office of Personnel Management (OPM), Center for Federal Investigative Services, and approved by the Office of Management and Budget (OMB) for public use, to provide a means to facilitate the processing of the questionnaires for background investigations commonly known as Standard Forms (SF) SF 86, SF 85P, or SF 85.

OM:5-101______________________________________________Page 4 of 17 (07/16/2010)

Escort Access Requires the contractor employee to be escorted and supervised at all times by an authorized ED employee or by a cleared contractor employee who has been authorized by an ED manager.

Information Technology (IT)

The hardware and software operated by a Federal agency or by a contractor of a Federal agency or other organization that processes information for the use of the Federal government to accomplish a Federal function, regardless of the technology involved, whether computers, telecommunications, or others. IT is used synonymously with Automated Data Processing (ADP), Federal Information Processing (FIP) resources, and Automated Information Systems

(AIS).

Lawful Permanent Resident

Any person not a citizen of the United States who is residing in the United States under legally recognized and lawfully recorded permanent residence as an immigrant. Also known as “Permanent Resident Alien,” “Resident Alien Permit Holder,” and “Green Card Holder.”

Personnel Security Adjudication Determination

A decision made about whether a person is an acceptable security risk after examining a sufficient period of his or her life following a Personnel Security Screening.

Screening

The process of conducting a background investigation through written, electronic, telephone, or personal contact to determine the suitability, eligibility, or qualifications of a person for Federal employment, work on Federal contracts, or for National Security purposes.

Position Risk and/or Sensitivity Level Designation

Evaluating and assigning sensitivity and/or a risk designation commensurate with the duties and responsibilities of a position related to national security and/or to the efficiency of the service.

Preliminary

Screening

A review of completed security forms, a credit check, fingerprint check, record checks, and file reviews. A preliminary personnel security screening is conducted before a contractor employee can be assigned to a High Risk level IT position.

Senior Agency Official for Privacy (SAOP)

An individual who oversees ED activities related to the development, implementation, maintenance, and adherence to ED policies and procedures covering the privacy of and access to personally identifiable information, in compliance with Federal laws and ED information privacy practices.

System Security

Refers to an individual responsible for the security of a particular IT system; with responsibility to report problems to the Computer Security Officer if there are incidents with that IT system.

OM:5-101______________________________________________Page 5 of 17 (07/16/2010)

Unclassified Sensitive Information

Includes such information as relates to the privacy of US citizens, payroll and financial transactions, and proprietary information.

Unfavorable Adjudication Determination

The final determination that results in adverse action relative to a person’s employment acceptability or suitability, retention in a sensitive or public trust position, access to National Security Information, materials, or areas, or incumbency in a sensitive position.

Up-To-Date Investigative Forms

Forms that are received by Chief of Personnel Security within 30 days of signature by contractor employee.

VI. Procedures and Responsibilities

A. Principal Office (PO)

The PO is responsible for performing the functions described below to implement this Directive. Each PO Contracting Officer’s Representative (COR) is expected to play a key role in tracking the personnel security adjudication determinations of contractor employees as a supplemental responsibility in monitoring the contract, without altering the primary duties as specifically noted in this Directive or in ED's Handbook for Information Assurance Security Policy.

A PO has the option to deny contractor employees access to their controlled facilities, unclassified sensitive information, or IT systems, until the Chief of Personnel Security has made personnel security adjudication determinations. The Chief of Personnel Security must approve in advance exceptions to this policy.

A PO also has the option to modify research and data collection contracts and require those contractors whose employees will have direct access to minors and/or access to sensitive personal information other than publicly available directory information, e.g., social security numbers, to conduct criminal background checks on those individuals prior to those personnel being permitted access to such minors or personal information; this would be in lieu of ED conducting the criminal background checks. The contract must specify that the contractor will maintain records of all checks conducted on such personnel and certify to ED that these checks have been conducted. Contracts should also require contractors to assure that they have engaged in additional screening appropriate to the responsibilities of the individuals employed under the contract.

The Executive Officer of each PO is that Office's liaison and key point of contact with the Chief of Personnel Security, Security Services, Office of Management, for all personnel security matters.

1. Each PO must establish and maintain on file with the Chief of Personnel Security, its own procedural document for complying with this Directive. The document will identify the responsible officials; e.g., CORs, Computer Security Officers, or

OM:5-101______________________________________________Page 6 of 17 (07/16/2010)

System Security Officers, with the PO who will be performing key duties. All modifications to the PO Procedures Document must be forwarded to the Chief of Personnel Security for review. Each PO must include in its procedures the requirements for screening contractor employees serving 30 calendar days or more on an ED contract or project, if they will:

a. Have an ID badge granting unescorted access to ED facilities;

b. Have ED IT system access;

c. Access to unclassified sensitive information, such as Privacy Act-protected, personally identifiable, proprietary or other sensitive information and data; or,

d. Perform duties in a school or location where children are present.

2. The PO must coordinate with the Contracting Officer during the preparation phase of the contract solicitation and acquisition process to implement these procedures.

3. Each PO must determine the risk levels for each contractor position. This process requires coordination with the Computer Security Officers of each PO and the Chief of Personnel Security. Each PO must maintain a current position risk level designation record for each contractor position to which this Directive applies.

The three position risk levels and their investigative requirements are:

HIGH RISK (HR) Positions with the potential for exceptionally serious impact on the efficiency of ED. This includes access to ED IT systems that allows the bypass of security controls or access that, if taken advantage of, could cause serious harm to the IT system or data. A Background Investigation (BI) is the type of investigation required.

MODERATE RISK

(MR)

Positions with the potential for moderate to serious impact on the efficiency of ED, including all positions that require access to unclassified sensitive information, such as Privacy Act-protected, personally identifiable, proprietary or other sensitive information and data. A National Agency Check with Written Inquiries (NACI), and a credit check, is the type of investigation required. The investigation will be expanded to a Minimum Background Investigation (MBI) or a Limited Background Investigation (LBI) if the NACI plus credit check investigation develops information that the Chief of Personnel Security considers potentially actionable.

LOW RISK (LR) Includes all other positions to which this policy applies (see applicability in Section IV). A National Agency Check with Written Inquiries (NACI) is the type of investigation required.

4. Each PO must assign a position risk level to each applicable contractor employee position, before the solicitation is released, consistent with Appendix I of this document. This information will be recorded on the Position Designation Record for Contractor Positions form (see Appendix II). These records can be maintained on file with either the COR or Contracting Officer for that PO. The PO's Computer Security Officer must concur in writing with the designated risk level.

If the duties of a position involve more than one risk level, the higher of the two risk levels will be assigned to the position. The PO must maintain status update on contractor duties as they change – say from Moderate Risk to High Risk, and is

OM:5-101______________________________________________Page 7 of 17 (07/16/2010) responsible for commensurate paperwork and elevation of position risk level and commensurate background investigation requirement.

5. High Risk Level Positions: For High Risk level positions, each PO must have the

COR submit completed contractor employee investigative forms, and a “Request for Security Officer Action” form for each individual, on a pre-appointment basis.

The PO must deny the contractor employee High Risk level access to IT systems, or ED sensitive or Privacy Act-protected information, until the Chief of Personnel Security notifies the COR that the preliminary security screening was completed favorably.

Additional considerations for High Risk Level Positions Regarding:

Citizenship

ED may grant a non-U.S. Citizen High Risk IT (6C) system access. In those circumstances where a non-U.S. Citizen possesses a unique or unusual skill or expertise urgently needed by ED, but a suitable U.S. Citizen is not available, a non-U.S. Citizen may be assigned to a High Risk IT (6C) level position, provided:

he/she is a Lawful Permanent Resident of the United States; has resided continuously in the United States for a minimum of three (3) years; the head of the PO, or his/her designee that owns the IT system, information, or network, approves the assignment in writing; and the written approval is filed with the Contracting Officer before requesting a preliminary personnel security screening and/or investigation.

Preliminary Personnel Security Screening (Required for High Risk IT (6C) Level System Access)

All Contractor employees assigned or transferred into positions determined to be at the High Risk IT (6C) level must undergo a preliminary personnel security screening before:

• They are authorized to bypass significant technical and operational security controls of general support IT systems, or major applications; or

• They are authorized to access applications where controls such as separation of duties, least privilege, and individual accountability cannot adequately protect the application or the information in it.

The preliminary personnel security screening may include a review of completed security forms, credit check, record checks, and file reviews. The PO must deny the contractor employee High Risk level access to IT systems until the Chief of Personnel Security notifies the PO that the preliminary personnel security screening was completed favorably. The inquiries for the preliminary personnel security screening will be initiated within 5 working days after receipt of the completed security forms. Within 5 working days after receiving the results of those inquiries, a determination will be made regarding a contractor employee’s

OM:5-101______________________________________________Page 8 of 17 (07/16/2010) acceptability. As necessary, a Background Investigation (BI) will be conducted following the completion of the preliminary personnel security screening.

While awaiting a preliminary personnel security adjudication determination for High Risk level IT (6C) positions, you may request an exception to the policy from the Chief, Personnel Security, for contractor employees who require immediate physical access to ED controlled sensitive areas or facilities, or to High Risk sensitive information or IT systems, must be escorted and supervised by an authorized ED employee or authorized cleared contractor employee at all times.

Escort access may not be used for contractor employees after notification of an unfavorable personnel security adjudication determination about the contractor employee from the Chief of Personnel Security.

An ED manager must authorize the escort access. Contractor employees who will have physical access to ED controlled facilities, sensitive information or IT systems (excluding any actual log-on access to ED IT systems), for less than 30 days (e.g. a one or two week project), or have infrequent access (e.g. three times a month), do not require investigation provided they are escorted. Escort access requires the contractor employee to be escorted and supervised by an authorized ED employee or authorized cleared contractor employee at all times.

Reinvestigations for High Risk (IT) (6C) Level Positions

Contractor employees occupying High Risk level IT positions must undergo reinvestigation every 5 years for the duration of their contract at ED, or if there is a break-in-service to an ED contract of 365 days or more. Each PO must ensure a complete investigative forms package is submitted within 14 days of the Chief of Personnel Security’s direct request.

6. All Other Positions: As necessary, each PO must have the COR submit completed contractor employee investigative forms for each individual required to submit forms, and a "Request for Personnel Security Officer Action" form for each individual, to the Chief of Personnel Security, within 14 days of the date the contractor employee is placed in a position, except for contractor employees in High Risk IT (6C) Level positions who require preliminary personnel security screenings. No contractor employees are permitted unescorted/unsupervised access to ED facilities, unclassified sensitive information or IT systems, until they have submitted applicable investigative forms.

7. Each PO COR must ensure that the Contracting Officer, and if necessary the

Computer Security Officer, is kept informed during the contractor employee screening process, including notification of the screening determination.

8. Each PO COR must notify the contractor of the personnel security adjudication determination and maintain a copy for its records. If any attributes of the position change, including the need for a higher risk level, the PO will send a new "Request for Personnel Security Officer Action" form, showing the new position risk level, to the Chief of Personnel Security. The Chief of Personnel Security

OM:5-101______________________________________________Page 9 of 17 (07/16/2010) will promptly notify the PO if the contractor employee has not met the investigative requirements for the higher position risk level.

9. Each PO must maintain an up-to-date list of all contract positions and risk level designations covered by these policies and procedures. The list must include the name of the employing firm, the risk level designation of each position, the name of each contractor employee currently in that position, the date the contractor employee investigative forms or previous screening information were submitted, and the date of the final personnel security screening determination. The PO COR must also ensure that a contractor employee is not placed in a more sensitive position than that for which he or she was previously approved, without the approval of the Chief of Personnel Security and the PO’s Computer Security Officer.

10. Performance-Based Contract: The risk level associated with the contract requirement shall be designated within the Performance Work Statement (PWS) or Statement of Work (SOW), prior to the Request for Proposal (RFP) being released. All position risk levels must be assigned prior to contract award.

11. Each PO COR must notify the Chief of Personnel Security within three business days of the departure of a contractor employee, either voluntary or involuntary, and furnish the reason(s) and the date of the departure, unless the departure resulted from action by the Chief of Personnel Security.

12. Each PO will have the COR inform the Contracting Officer that a contractor employee is deemed not acceptable for reasonable cause, upon notification by the Chief of Personnel Security, and such finding(s) makes the individual ineligible for access to ED facilities or IT systems. The Contracting Officer will make the official notification to the contractor. A final determination cannot be appealed.

13. Each PO must immediately deny a contractor employee access to all ED IT systems, facilities and information, when notified by the Chief of Personnel Security that a contractor employee is deemed not acceptable for reasonable cause.

14. The PO must contact the Chief of Personnel Security if the PO chooses to require screening for contractor employees who will require access for less than 30 days, rather than have to provide escort access.

15. POs are permitted to develop more stringent contractor personnel security screening policies if they determine that their organization or offices require it.

However, the PO must clear any such policy with the Chief of Personnel Security prior to implementation.

B. Senior Procurement Executive

1. The Senior Procurement Executive (SPE) in the Office of the Chief Financial

Officer must ensure that personnel security screening requirements for contractor employees (as defined by this Directive) are included in all solicitations and

OM:5-101______________________________________________Page 10 of 17 (07/16/2010) contracts issued by ED. The SPE must ensure that potential offerors and contractors are aware of all personnel security requirements for contractor employees at the earliest stages of the acquisition. Except for performance-based contracts, the SPE, in coordination with the Contracting Officer, the PO, and others, as needed, must ensure that each contractor employee position is assigned an appropriate risk level during the acquisition process and that this information is included in the solicitation.

2. Performance-Based Contracts: The SPE, in coordination with the Contracting

Officer, the PO and others, as needed, must ensure that contractor employee positions are assigned risk designation levels at the earliest possible time during the acquisition and that this information is communicated to the contractor for performance-based contracts.

3. All active solicitations and contracts meeting the requirements of this Directive will include personnel security screening requirements for ED contractor employees.

4. The SPE, in coordination with the Contracting Officer, must ensure that all contractor employees are screened in a timely manner and that procedures of this Directive are fully implemented throughout the performance of the contract. The SPE will ensure that annual reviews of contracts are conducted to ensure continued compliance with this Directive, and that the SPE and the Contracting Officer act upon instances of non-compliance. The Contracting Officer may take official action against a contractor for non-compliance, including, but not limited to, withholding of payment, or termination of the contract.

5. The SPE will ensure that the Contracting Officer requires each contractor to timely submit completed forms to the PO. Contracts that do not currently have this requirement must be modified to require the timely and complete submission of forms to the COR within two business days of a contractor employee’s assignment to an ED contract.

6. The SPE, through the Contracting Officer, must officially notify a contractor if a contractor employee is deemed not acceptable for reasonable cause and such finding(s) makes the contractor employee ineligible to render service(s) or otherwise perform under the contract. A final determination cannot be appealed.

C. ED Requirements for Contractor/Contractor Employees

As contained in each solicitation or contract meeting the requirements of this Directive, contractors and/or their employees at ED have the following responsibilities:

1. Each contractor must ensure that all non-U.S. citizen contractor employees are

Lawful Permanent Residents of the United States or have the appropriate work authorization documents required by the Department of Homeland Security, Bureau of Immigration and Appeals, to work in the United States. Non-US

OM:5-101______________________________________________Page 11 of 17 (07/16/2010) citizen contractors living and working outside the U.S., and not legally authorized to work in the U.S., will not be granted access to ED IT systems or unclassified sensitive information, such as Privacy Act-protected, personally identifiable, proprietary, or other sensitive information and data.

2. Contractor employees who have undergone appropriate personnel security screening for another Federal agency will be required to submit proof of that personnel security screening for validation, or otherwise be subject to ED personnel security screening requirements as stated in this policy. Contractor employees requiring access to ED facilities or IT systems as part of a contract managed by another Federal Agency such as the General Services Administration (GSA), Federal Protective Service (FPS), or the Department of Homeland Security (DHS), will be required to show proof of personnel security screening for validation to allow for such access. All contractors must comply with the Principal Office (PO) Executive Office or Computer Security Officer’s pre-processing requirements for personnel security screening and granting access privileges.

3. Each contractor must ensure that its contractor employees submit all required personnel security forms to the COR within two business days of an assignment to an ED contract and ensure that the forms are complete. In the event that forms are not complete, the contractor must resubmit the forms to the COR within 7 business days or the contractor employee must be removed from the contract.

4. Each contractor must ensure that a contractor employee is not placed in a higher risk position than that for which he or she was previously approved, unless approved by the Contracting Officer, the COR, the Chief of Personnel Security and the Computer Security Officer.

5. Each contractor must report to the COR all instances of individuals seeking to obtain unauthorized access to any ED IT system, or unclassified sensitive and/or Privacy Act-protected information.

6. Each contractor must report to the COR any information that would raise a concern about whether a contractor employee’s continued employment would promote the efficiency of the service or violate the public trust.

7. Each contractor must report to the COR within two business days any removal of a contractor employee from a contract; within one business day if removed for cause. The contractor is responsible for returning an ED ID badge to the COR within 7 business days of the contractor employee’s departure. Also, the contractor must report to the COR, within two business days, any instance of a contract employee being moved into, or out of, an ED facility.

8. Each contractor will officially notify its contractor employee if he or she will no longer work on an ED contract.

9. Each contractor is responsible for the protection of sensitive or Privacy Act-protected information from unauthorized use or misuse by its employees, OM:5-101______________________________________________Page 12 of 17 (07/16/2010) subcontractors, or temporary workers, and for preventing access to others, who are not authorized and have no need to know such information.

10. Contractors may be required to conduct criminal background checks (for a period of not less than 10 years) of their personnel who will have direct access to minors and/or access to sensitive personal information other than publicly available directory information, e.g., social security numbers, before their personnel are permitted access to such minors or personal information if they will be employed on a research and data collection contract. These contractor employees will not require routine physical access to federally controlled facilities or logical access. In such instances, contractors must keep records of all checks conducted, and provide certification to ED that they have conducted the checks. Contractors must also assure that they have engaged in any additional screening appropriate to the responsibilities of the individuals employed under the contract.

D. Chief of Personnel Security

1. The Chief of Personnel Security, an employee of the Office of Management, provides oversight and guidance for all matters relative to these policies and procedures.

2. The Chief of Personnel Security will receive, process, and forward contractor employees' forms to the investigating agency as necessary. The investigating agency may be a Federal agency or individual contractor.

3. The Chief of Personnel Security shall promptly return incomplete forms to a PO for proper completion by the contractor employee.

4. The Chief of Personnel Security must notify the PO COR promptly of the results of a contractor employee’s preliminary personnel security screening for High Risk IT (6C) Level positions. The preliminary personnel security screening may include a review of completed security forms, credit check, record checks, and file reviews. The inquiries for the preliminary personnel security screening must be initiated within 5 working days after receipt of the completed security forms.

Within 5 working days after receiving the results of those inquiries, a determination must be made regarding a contractor employee’s preliminary acceptability. As necessary, a Background Investigation (BI) must be conducted following completion of the preliminary personnel security screening.

5. The Chief of Personnel Security will request the expansion of background investigations to obtain additional information to the extent necessary to make personnel acceptability or suitability determinations. These determinations will be made using criteria established by the OPM for the purpose of determining suitability for employment in the Federal competitive service, as described in 5 CFR 731.202, and other OPM guidance. The Chief of Personnel Security determines whether a contractor employee is acceptable for the position from a personnel security standpoint.

OM:5-101______________________________________________Page 13 of 17 (07/16/2010)

6. The Chief of Personnel Security will usually provide the contractor employee with an opportunity to refute, explain, clarify, or mitigate information in question.

7. The Chief of Personnel Security will inform the PO COR when he or she determines that a contractor employee is not acceptable to render service(s) or, if appropriate, to otherwise perform under a contract. If, after final determination by the Chief of Personnel Security, a decision is made that the contractor employee is not acceptable to render services on a contract and access is denied, the COR will inform the Contracting Officer. The Contracting Officer must inform the contractor (i.e. employing firm) that the contractor employee is not acceptable to render services in this particular position, or, if appropriate, to otherwise perform under the contract.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .