HSFE60-16-R-0004_Attachment_A.pdf

PDF 386 KB Posted

Attached to
National Flood Insurance Program (NFIP) Direct Servicing Agent (DSA) Federal contract opportunity
Solicitation number
HSFE60-16-R-0004
Issued by
Federal Emergency Management Agency Recovery Section

About this file

Attachment A DSA SOO July 15 2016

View the file

Other files for this federal contract opportunity

Show all 19

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

National Flood Insurance Program Direct Servicing Agent

Statement of Objectives – Base Task Order

July 15, 2016

PROCUREMENT SENSITIVE

2 | P a g e

STATEMENT OF OBJECTIVES

NATIONAL FLOOD INSURANCE PROGRAM

Direct Servicing Agent

1. BACKGROUND

The Department of Homeland Security (DHS), Federal Emergency Management Agency (FEMA)/Federal Insurance and Mitigation Administration (FIMA) manages the National Flood Insurance Program (NFIP) and a range of programs designed to reduce future losses to homes, businesses, schools, public buildings, and critical facilities from floods, earthquakes, tornadoes, and other natural disasters.

FEMA focuses on breaking the cycle of disaster damage, reconstruction, and repeated damage.

Mitigation efforts provide value to the American people by creating safer communities and reducing loss of life and property. Mitigation includes such activities as:

1.1 Enforcing building codes, flood-proofing requirements, seismic design standards, and wind-bracing requirements for new construction or repairing existing buildings.

1.2 Adopting zoning ordinances that steer development away from areas subject to flooding, storm surge or coastal erosion.

1.3 Retrofitting public buildings to withstand hurricane-strength winds or earthquakes.

1.4 Acquiring damaged homes or businesses in flood-prone areas, relocating the structures, and returning the property to open space, wetlands or recreational uses.

1.5 Building community shelters and tornado safe rooms to help protect people in their homes, public buildings and schools in hurricane- and tornado-prone areas.

1.6 Educating communities on how they can reduce their vulnerability to natural hazard events.

1.7 Providing flood insurance to help communities and individuals financially recover from floods.

FIMA operates the NFIP, which was created by an Act of Congress in 1968. The NFIP makes flood insurance available to residents and businesses of participating communities that commit to sound flood plain management practices.

The NFIP sells and administers Standard Flood Insurance Policies in two ways:

(1) Through an arrangement with private Write Your Own (WYO) insurance companies (under authority of 44 CFR Section 62.23); and

(2) Through a contract with an entity that directly sells and services NFIP policies, the NFIP Direct Servicing Agent (DSA).

Since 1983, the Write Your Own (WYO) Program has become the primary vehicle for delivering and servicing flood insurance with participating insurance companies, who write nearly 80% of the approximate 3.5 million NFIP’s flood insurance policies in their own names. The DSA contractor serves approximately 20%, or 688,000 of all polices. The actual number and percentage of policies written by the DSA contractor varies on a daily basis. A summary of the number of polices held by the DSA contractor over the past 5-years is provided in Table-1, Historical DSA Flood Insurance Policies. This data

3 | P a g e is provided for informational purposes only. The Government does not guarantee the number of policies to be written by the DSA contractor. The Government bears the underwriting risk for these policies, as well as for the policies issued by the DSA.

2. PROJECT AND TITLE

The DSA contractor facilitates a property owner’s insurance agent obtaining flood insurance for their client, the home owner, directly from the government rather than through a WYO company. The Offeror shall furnish all personnel, facilities, equipment, material, supplies, and services (except as may be expressly set forth in this Statement Of Objectives (SOO) as furnished by the Government) and otherwise perform all actions necessary to, or incidental to, performing and providing services for directly written Standard Flood Insurance Policies, Severe Repetitive Loss policies and Group Flood Insurance policies) in support of the FEMA’s NFIP. In addition, the DSA shall assume the policies of WYO companies that no longer chose to write NFIP policies.

FIMA’s guiding principles are:

• Emphasize integration and collaboration

• Strive for innovation where needed while building off what works

• Improve the customer experience

• Improve organizational health

3. PURPOSE

The purpose of this SOO is to obtain contract support for NFIP direct services and to obtain the outcomes described herein.

This SOO aims to improve FIMA’s responsiveness and quality of customer experience to its policyholders; respond effectively to flood events and disasters; and provide efficient and effective process administration and program performance.

FIMA requires the continuous review and improvement of existing processes and tools as the environmental, technological, and political considerations impacting the program continue to evolve.

4. PERFORMANCE OBJECTIVES, GOALS, AND OUTCOMES

FIMA requires the contractor to fully comply with all statutes and demonstrate working knowledge and understanding of applicable regulations, policies, guidelines, and specifications that affect the NFIP, FIMA, FEMA, and DHS. For the Offeror’s convenience, this SOO highlights some of these regulations, policies, guidelines, and specifications that are specific to the NFIP. The Offeror’s proposed solutions must demonstrate. The contractor shall provide services that are innovative, flexible, reflect subject matter expertise, increasingly efficient while delivering increased effectiveness given the Government’s continuing resource constraints. Details concerning the NFIP and Flood Insurance Processing can be found at http://www.fema.gov/national-flood-insurance-program.

http://www.fema.gov/national-flood-insurance-program

4 | P a g e

4.1 Performance Objectives

4.1.1 Objective 1 – Deliver quality Direct Service operations in a cost-effective and timely manner

4.1.1.1 On behalf of the Federal government, provide direct servicing activities including receipt generation, insurance applications underwriting and processing, premium revenue receipt and deposit, policy production and delivery, endorsement processing and delivery, premium adjustments, claims processing, policy cancellation, renewal notice generation and delivery, renewal premium receipt and deposit, agent commission calculation and delivery, and furnishing insurance policy forms and printed materials. There is no guarantee on the number of policy to be written and serviced under this contract. Table 1 provides the historical number or policies written by the DSA contractor. The actual amount will vary. The pricing structure allows a tired approach to pricing services under this objective depending on the active number of policies.

4.1.1.2 Achieve a marked reduction in the overall cost of direct servicing in each year of the contract.

4.1.1.3 Coordinate with the NFIP-IT Systems and Services contractor, WYO companies, Windpools and

Beach Plans, and other Federal government programs such as FEMA Individual Assistance, SBA and Federal Loan Programs as needed.

4.1.1.4 Provide a government approved approach for re-inspecting claims.

4.1.1.5 Provide FEMA online access to all open and closed claims files and reports on claim status and payments made.

4.1.1.6 Separately account for and timely deposit all funds received by the Offeror as a result of salvage or subrogation rights, or collection.

4.1.1.7 Establish, manage, and operate an Adjuster Control Office (ACO) and/or Flood Insurance Claims

Office (FICO) at disaster sites per FEMA requirements. Operate and maintain appropriate secure field-based technology to support effective adjuster assignments and prompt claims payments. Co-ordinate with the NFIP-IT Systems and Services contractor Flood Recovery Office (FRO).

4.1.1.8 Ensure adequate adjuster presence within forty-eight hours of COR notification in any given disaster area, paying particular attention to multi-site and multi-disaster conditions.

4.1.1.9 Provide FEMA a timely assessment of DSA claims exposure

4.1.1.10 Carry out the policies, operations, standards and reporting for unique requirements such as Severe Repetitive Loss (SRL) policies, Group Flood Insurance Policies (GFIP), loss history appeals, claims re-inspections, Flood Insurance Reform Act (FIRA) of 2004 Section 207, and financial reporting.

4.1.1.11 Provide a customer relationship management (CRM) solution that aligns with the solutions adopted by the Federal Insurance and Mitigation Administration and the Flood Insurance Advocate.

4.1.1.12 Provide a business intelligence solution as part of the overall systems architecture to provide FEMA personnel, and others authorized by FEMA; a means to access all data collected by the DSA as a result of its normal and disaster support operations.

4.1.2 Objective 2 – Design and Implement Effective Customer Service for NFIP Policyholders

4.1.2.1 Collaborate with FIMA to enhance the Customer Experience

5 | P a g e

4.1.2.2 Deliver robust customer service processes, tools, and reporting that leverage contact center industry best practices, support the unique needs of the NFIP and align with FIMA Customer Experience recommendations.

4.1.2.3 Support FEMA NFIP Controlled, Claims Appeal, or Uncontrolled correspondence activities that address the needs of NFIP stakeholders. This support consists of:

a. establishing documented procedures for handling all correspondence;

b. fielding correspondence;

c. drafting appropriate responses to correspondence; and

d. maintaining records of all correspondence activity,

e. including automated control and analysis tools as appropriate.

4.1.2.4 Perform these activities within FEMA approved timeframes as noted in the parameters.

4.1.2.5 Implement, document, and maintain detailed procedures for handling all of the NFIP related correspondence. Obtain FEMA approval for these procedures. Approved procedures will indicate the ability to: effectively control all incoming and outgoing correspondence; perform a high level of quality assurance; and handle all correspondence tasks in a timely manner.

4.1.2.6 Develop, operate, and maintain an IT solution with automated control and analysis for all correspondence received per FEMA timelines and reporting requirements noted in the parameters.

4.1.3 Objective 3 – Provide scalable and cost effective solutions for the processing of claims at normal and surge levels, and for the assumption of WYO company policies

4.1.3.1. Deliver a reliable, timely, and cost effective strategy for providing the quality control functions of claims processing under normal and surge conditions.

4.1.3.2. Deliver a reliable, timely and cost effective strategy for providing an appropriate number of

ACO/FICO capable disaster teams and backup teams to flood areas as required by FEMA. In particular:

a. Establish emergency strategies for distributing NFIP informational materials to adjusters and policyholders;

b. Be capable of deploying FICO back-up team(s) for four or more simultaneous flood events in separate geographic areas. Such teams must be operational within seven calendar days of Contracting Officer’s Representative (COR) notice.

c. If NFIP policies in a flooded area do not warrant opening an FICO, operate and staff to an appropriate level an In-House FICO, which may be coordinated with an ACO.

4.1.3.3. Provide strategies for efficiently and expeditiously assuming WYO policies under different policy assumption levels.

4.1.4 Objective 4 – Provide secure, government approved innovative Information Technology solutions

4.1.4.1 The Contractor shall include security as integral in the management of IT solutions that support this contract.

4.1.4.2 Securely contain Personally Identifiable Information (PII) and other sensitive information from unauthorized access and improper use in compliance with FEMA requirements. Improper use includes the use of NFIP data for commercial purposes. These details are further outlined in the SOO below.

6 | P a g e

4.1.4.3 The Contractor shall comply with the Department of Homeland Security’s (DHS) technical, management, and operational security controls to ensure that the Government’s security requirements are met. DHS 4300A policy guide will be used for Sensitive Systems and DHS 4300B policy guide will be used for National Security Systems. The contractor shall also adhere to OMB Circulars A-123 and A-130, National Institute of Standards and Technology (NIST) the Federal Information Security Management Act (FISMA) as well as all other applicable security policies, guidelines, memorandums, etc.…including The Payment Card Industry Data Security Standard (PCI DSS) regulation as mandated by the FEMA Office of Chief Information Officer and others as outlined in this objective, other sections in this SOO and as identified by the FEMA Office of the Chief Information Officer throughout the lifecycle of the technology solution.

4.1.4.4 The Contractor shall develop, complete, update and maintain accurate systems and security documentation for all systems and subsystems and applications to the level prescribed by the Government, and it shall be suitably safeguarded and available for review, and distribution upon reasonable notice, inclusive of, but not limited to:

a. Security Plan

b. Contingency Plan

c. Privacy Threshold Assessment

d. FIPS 199

e. eAuth

f. Privacy Impact Assessment

g. Contingency Plan Test Results

h. Configuration Management Plan

i. Security Assessment Plan

j. Network Diagrams

k. Architecture Diagrams

l. Build Plans

m. System & Software Inventory List(s)

n. Security Assessment Report(s)

o. Plan(s) of Action and Milestones and

p. Interconnection Security Agreement(s)

4.1.4.5 Develop and maintain a Continuity of Operations (COOP) and Disaster Recovery (DR) plan for emergency circumstances that could jeopardize FEMA systems and operations requirements.

Review and test the Disaster Recovery plan per FEMA requirements.

4.1.4.6 Maintain incident records and system overview documentation per FEMA requirements.

4.1.4.7 There is a risk for improper use of NFIP data for commercial purposes; to mitigate this risk, provide a detailed approach to ensure the NFIP data provided under this contract is not used to inform the commercial activity.

4.1.4.8 All software/management tools, which are developed or used to support the requirements of this contract, (with the exception of third party software) shall become property of the Government.

4.1.4.9 The Contractor shall secure all necessary releases to permit use of third-party software in the performance of transportable and disaster recovery tests and shall, as required, assist in coordinating the transfer of such software to the Government or a successor system operation.

7 | P a g e

4.1.5 Objective 5 – Provide a laboratory environment to test the effectiveness of new ideas that enhance customer experience as set forth in task orders

4.1.5.1 Collaborate on government initiatives to enhance customer experience, produce process efficiencies, and improve quality of direct services.

4.1.5.2 Design an organization and governance structure, to include an execution plan, time tables, and performance evaluation factors across FEMA and the DSA for capturing, testing, documenting and reporting on FEMA generated initiatives. New data elements not included within the current Transaction Record Reporting and Processing (TRRP) Plan may be identified and required to be collected as part of any initiative and possible become part of future TRRP versions.

4.1.5.3 Implement and test CX initiatives.

4.1.6 Objective 6 – Design, implement, and provide metric reporting to continuously improve the customer experience

4.1.6.1 Deliver meaningful Customer Experience reporting metrics such that quality, effectiveness, and efficiency of the customer experience can be assessed. Customer Experience includes service, product features and brand image.

4.1.6.2 Leverage subjective and objective data from the provider’s reports, and other FEMA sources, to deliver continuous improvement in customer experience.

5. PARAMETERS

5.1 Severe Repetitive Loss: The Offeror will be servicing the Severe Repetitive Loss (SRL) policies. The Offeror shall support the following in particular to SRL policies:

5.1.1 Send notification letters to policyholders, agents, and lenders once the NFIP-IT Systems and

Services contractor has identified a policy as an SRL property. Update the SRL database accordingly.

5.1.2 Operate the Special Direct Facility (SDF). The SDF sends pre-renewal letters to the SRL policyholders informing them of the special renewal process.

5.1.3 Re-underwrite all new SRL polices underwritten by the DSA with respect to rates for correct premium charges, zone information, loss history and any policy-zone grandfathering information.

Coordinate with the NFIP-IT Systems and Services contractor for SRL file updating. Provide audit trail that the policy has been re-underwritten.

5.1.4 Provide information to the insured and their agent on how to appeal an SRL designation and in the event of an appeal, follow established NFIP appeal procedures.

5.1.5 FEMA’s NFIP-IT Systems and Services Contractor maintains a historical file of all designated Repetitive Loss properties. Send all property information and updates to these SRL policy records to the historical file when a property loses its SRL-designation. Maintain all information on SRL properties and categorize this information as required by FEMA.

5.1.6 Provide status reporting that details re-underwritten SRL policies and reviews the SRL book of business per FEMA requirements.

5.1.7 Process SRL designation appeals with FIMA and the policyholder using FIMA-approved letters and procedures.

5.1.8 Coordinate with FEMA on necessary policy actions for FEMA-approved mitigation project buy-outs or demolition of SRL properties.

8 | P a g e

5.2 Group Flood Insurance Policies: The Offeror will be servicing GFIP. The Offeror shall support the following objectives in particular for GFIP:

5.2.1 GFIP are unique because coverage can be used for buildings or contents.

5.2.2 Coordinate with FIMA and the States regarding policy and policyholder information, issuance of

Certificates of Flood Insurance and mandatory purchase requirement instructions.

5.3 Loss History Appeals: The Offeror will service Loss History Appeals:

5.3.1 Process, maintain and report from a repository of all Loss History Appeals per FEMA requirements.

5.3.2 Update the SRL database, Transaction Record Reporting and Processing (TRRP) database and policy records accordingly.

5.4 Flood Insurance Reform Act of 2004: The parameters for FIRA 2004:

5.4.1 Manage communication and produce reporting of agency compliance with flood insurance training requirements.

5.4.2 Recommend ways to improve DSA agent and agency participation in training “refreshers”, advanced training or other training as deemed appropriate by the DSA.

5.5 Financial Management: Financial Management and Reporting:

5.5.1 Be fully versed in the requirements of and in compliance with all audits, operation reviews, and contract surveillance activities.

5.5.2 Safeguard, log, then timely deposit all received funds into a Treasury General Account.

5.5.3 Provide detailed deposit accounting per Generally Accepted Accounting Principles (GAAP).

5.5.4 Establish internal controls within 90 business days of contract award, approved by FEMA.

5.5.5 Operate and maintain a secure and comprehensive financial control system for NFIP business that conforms to standards set forth by the following:

a. [A] Plan to Maintain Financial Control Plan for Business Written Under the WYO Program;

b. WYO Accounting Procedures Manual;

c. Chief Financial Officers Act of 1990; and

d. U.S. Government Accountability Office.

5.5.6 The Payment Card Industry Data Security Standard (PCI DSS) regulation as mandated by the FEMA Office of Chief Information Officer. Aggressively collect and repay debts due the United States Government per the Debt Collection Act of 1982 (31 U.S.C. 3701 et seq.).

5.5.7 Prepare reporting such as Schedule 9 Accounts Receivable Statements, FEMA fiscal year-end statements and supporting schedules per FEMA requirements.

5.6 Correspondence: The Offeror will handle all correspondence in accordance with the following timelines and reporting requirements:

5.6.1 Controlled correspondence is considered VIP (congressional), White House, and DHS correspondence. Controlled correspondence is processed by FEMA’s IQ system. Only select FEMA personnel have access to the IQ system, and currently all controlled correspondence status reporting is conducted through the FEMA IQ system. FEMA’s Risk Insurance Division’s SharePoint Correspondence Tracker application supports controlled correspondence processes, provides templates and also tracks status that is reconciled with FEMA’s IQ system on a regular basis.

5.6.2 Uncontrolled correspondence (UCC) is defined as General correspondence. General correspondence is received by postal mail, and hard copies are scanned into SharePoint. Email

9 | P a g e correspondence is also classified as uncontrolled correspondence. Uncontrolled correspondence is not handled by the IQ system, however RID’s SharePoint Correspondence Tracker supports UCC workflows and reporting to assess workloads and performance by federal and contracted support personnel.

5.6.3 The following DHS mandated performance timelines apply to Controlled Correspondence:

a. Interim response dispatched by Day 4 (business days), if a final cannot be completed by day 10.

b. Final response dispatched by Day 10 (business days) if not using an Interim and for all

White House/DHS correspondence.

c. Final Response dispatched by Day 30 (calendar days) if an Interim was issued.

5.6.4 FIMA currently has additional correspondence requirements to support DHS mandates and other functional needs:

a. All types of concerns are assigned and tracked in the same manner and timeframe.

b. Interim responses are dispatched within 4 days. Interim responses are generated when a final response cannot be completed within 10 days.

c. Basic Correspondence Report numbers: Number of New Correspondence within a month, broken down by Type of Correspondence and Number of Closed Correspondence within a month, broken down by Type of Correspondence

6. CONSTRAINTS

6.1 FEMA requires the Contractor’s cloud hosting solution(s) to be FedRAMP authorized at a moderate level when proposal is submitted; certification of compliance needs to be submitted with the proposal. The contractor will provide support, services and solutions in compliance and in alignment with Federal Risk and Authorization Management Program (FedRAMP) standardized security assessment, authorization, and continuous monitoring policies as required by the scope of the project.

6.2 Perform regular back-ups of all data and/or files created or changed on as deemed appropriate for the level of risk posed by data loss.

6.3 The data acquired under these requirements is owned by FEMA and cannot be intermingled with other data unless approved by FEMA.

6.4 Identify and propose to meet business continuity objectives as described in the DHS 4300A Sensitive Systems Handbook inclusive of the long-term secure data storage of magnetic and optical media.

The storage facility shall have the capability of delivering the backed-up system to a pre-selected backup or alternate processing site within 24 hour notice. Restricted access to the back-up site shall be fully detailed in the Security Plan and be part of the Certification and Accreditation (C&A) review and process.

6.5 NFIP claim adjusters are provided through a distinct and separate contract. Fees and expenses of the adjusting companies should be paid promptly, in conformance with the NFIP Adjuster Fee Schedule. All such payments are made from the FEMA-provided Letter of Credit (LOC).

7. APPLICABLE DOCUMENTS

The following is a partial list of guidance, regulations, documents and offices related to the National Flood Insurance Program:

10 | P a g e

7.1 Regulations governing the National Flood Insurance Program set forth in Title 44 of the Code of Federal Regulations, Chapter I, Subchapter B, commencing at part 59.

7.2 Plan to Maintain Financial Control for Business Written Under the Write Your Own Program (the “Financial Control Plan”), 44 CFR, Part 62, Appendix B. (The authority for the Write Your Own (WYO) Program as set forth in 44 CFR Parts 61 and 62, Sections 61.13 and 62.63.)

7.3 Flood Insurance Manual

7.4 NFIP Adjuster Claims Manual

7.5 Standard Flood Insurance Policy (SFIP) Forms

7.6 Federal Insurance and Mitigating Administration (FIMA)

7.7 WYO Transaction Record Reporting and Processing (TRRP) Plan

7.8 Applicable NFIP statutes and regulations

7.9 Applicable FEMA-NFIP bulletins

7.10 Debt Collection Act of 1982 (31 U.S.C. 3701 et seq.)

7.11 Flood Insurance Reform Act of 2004

7.12 Flood Insurance Claims Office (FICO)

7.13 Flood Response Office (FRO)

7.14 Adjuster Control Office (ACO)

7.15 NFIP Adjuster Fee Schedule

7.16 OMB Circulars A123 and A130

7.17 DHS 4300B “National Security Systems Handbooks” January 6, 2009, Section 3.0 Management

Controls

7.18 DHS 43300A “Sensitive Systems Handbook”

7.19 Federal Information Security Management Act (FISMA)

7.20 Severe Repetitive Loss FIMA approved letters/templates and procedures

7.21 [A] Plan to Maintain Financial Control Plan for Business Written Under the WYO Program;

7.22 WYO Accounting Procedures Manual;

7.23 Chief Financial Officers Act of 1990; and

7.24 U.S. Government Accountability Office

7.25 Debt Collection Act of 1982 (31 U.S.C. 3701 et seq.)

7.26 Generally Accepted Accounting Principles (GAAP)

7.27 Biggert-Waters Flood Insurance Reform Act of 2012

7.28 Homeowners Flood Insurance Affordability Act (HFIAA)

7.29 Individual State Departments of Insurance training regulations

8. ADDITIONAL REQUIREMENTS

8.1 FORMS AND PRINTING: In cooperation with the NFIP-IT Systems and Services Contractor, develop and maintain NFIP flood insurance documents, including the SFIP, the NFIP Application Form, and other policy and data collection materials. NFIP document production must be coordinated with FEMA’s Printing Officer, Forms Management Officer, and Information Collections Management Officer.

Operate an inventory management solution to maintain adequate NFIP material inventories and track print production. This system will oversee design, graphics, and printing. The system also will obtain necessary reviews, clearances, and approval from the COR.

11 | P a g e

8.2 POSTAGE, FREIGHT, DELIVERY, and STORAGE AND SHIPPING: Manage the security and accounting for all postage, express, and storage expenses. Deliver appropriate reporting per GAAP.

Manage the storage and shipping of Government furnished materials on DSA initiative or at the request of the COR. Maintain a management and control system and account for all storage and shipping expenses.

8.3 RECORDS RETENTION AND STORAGE: All documents must be compliant with Department of Homeland Security record management requirements and guidelines. Transfer files and records from the incumbent contractor and maintain the information in accordance with FEMA Manual 5400.1, Records Management— Files Maintenance and Disposition. Record keeping systems must be in compliance with the Federal Records Act, National Archives and Records Administration regulations, and FEMA Records Officer requirements. Manage any physical and virtual storage and warehousing needed to carry out contract operations.

8.4 SPECIAL SUPPORT: At the direction of the Contracting Officer (CO) and/or the COR – support FEMA’s Office of Chief Counsel (OCC) and FEMA’s Office of the Inspector General (OIG) activities related to DSA. Such support includes:

• Claim review and litigation discovery assistance;

• Investigation assistance, and

• Appearance as witnesses and or support at hearings, depositions, and other proceedings including trial.

Upon FEMA request, furnish all files, records, data, and other information for legal proceedings or investigation. Furnish the requested files within three (3) business days and any systems data within seven (7) business days – presuming compatible and programming formats.

8.5 TRANSITION-IN OF OPERATIONS: The contractor shall collaborate with the government and existing contractors to identify and transition-in the required components of the existing supporting IT environment and/or solutions. This may be inclusive of the entirety of components, functionalities, data and capabilities. The contractor will be responsible for delivering a project plan with a comprehensive timeline for transition within 30 days of award.

12 | P a g e

9. DELIVERABLES LIST

To include but not limited to the following to enable the achievements of the objectives detailed in this Statement of Objectives.

Deliverable Frequency Due Date Quality Assurance Plan Once with annual updates 30 business days of contract award Program Management Plan Once with annual updates 30 business days of contract award

Authority to Operate Once with annual updates Timeframe determined on award date

All Documents associated with the System and the Security Certification and Accreditation Process and Continuous Monitoring activities: may be inclusive of, but not limited to:

Security Plan, Contingency Plan, Privacy Threshold Assessment, FIPS 199, eAuth, Privacy Impact Assessment, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Network Diagrams, Architecture Diagrams, System Inventory List, Security Assessment Report and Build Plans. Additional documentation support may include Plan(s) of Action and Milestones and Interconnection Security Agreement(s).

Once with updates as required

To be negotiated with the government – additional documentation may be identified as a result of initial system assessment

Approach to ensure data is not used for Commercial Purposes Once with annual updates 30 business days of contract award

Project plan to enable PIV and SSO of the technology solution

Once with updates as required 30 business days of contract award

Contingency Plan/Continuity of Operation-Disaster Recovery Plan Once with bi-annual updates 30 business days of contract award

Transition-In Plan Once 30 business day of contract award Transition Out and Migration Plan As Required As negotiated with the government Decommissioning Plan Once As requested by the CO or COR System Policy and Claims Transition Plan Once 30 business day of contract award

Transition Progress Reports Weekly Every Wednesday during transition period

Report of open claims showing the numbers reported, open, closed/paid (with payment data) for each FICO and the same data for non-FICO losses arrayed by month of loss, as well as a summary which should constitute all open/reported losses.

Monthly Due with the Monthly Technical Progress Narrative Report (MTPN)

13 | P a g e

Claims “aging” reports, which shall include open losses by policy, date of loss, date of notice of loss, IFICO number, adjuster, state, and aging in categories within 30, 45, 60, 75, and 90 calendar days or more after date of loss and from notice of loss.

Monthly Due with the Monthly Technical Progress Narrative Report (MTPN)

Files, records, data and other information in SAC possession required by the Government for the defense of any legal action or proceeding brought under policies of flood insurance issued pursuant to the Act, as well as relating to FEMA investigations of fraud.

As requested Within three (3) days of the Contracting Officer’s Representative’s request

Summary report of all salvage and subrogation files, pending and closed within the period and their status/

Monthly Due with the Monthly Technical Progress Narrative Report (MTPN)

Report of all fraud detection and prevention activities. Semi-annually October 15th and April 15th

Report of claims closed during the month with elapsed time from notice of loss to closure; policy type; SFIP, GFIP, and with building and contents payment amounts.

Monthly Due with the Monthly Technical Progress Narrative Report (MTPN)

Set of all system-generated reports produced, and a complete, up to date set of all procedures used in the performance of the SAC.

Semi-annually October 15th and April 15th

Letter of Credit (LOC) transaction report Monthly

21st of each month delivered to the System of Record contractor and as reported in the MTPN

Monthly data submissions, financial statements, and reconciliations, prescribed by the WYO Financial Control Plan and Transaction Record Reporting and Processing Plan (TRRP).

Monthly 21st of each month delivered to the System of Record contractor and as reported in the MTPN

Report showing all transactions associated with receiving credit card payments

Monthly 21st of each month delivered to the System of Record contractor and as reported in the MTPN

Detailed deposit reports Monthly 21st of each month delivered to the System of Record contractor and as reported in the MTPN

Financial Statements, Schedule 9, Accounts Receivable Statement along with all back-up and supporting

Annually Twenty one (21) calendar days after the close of the fiscal year (September 30th)

14 | P a g e schedules for all items on the monthly financial reports.

Computer Performance Report Monthly Submitted monthly with the submission of the invoice for payment

Monthly Technical Progress Narrative (MTPN) Report covering work planned, progress against plans, and program related data and costs.

Monthly Within thirty (30) business days following the close of the prior month

Report of postal and express expenditures Monthly Due with the Monthly Technical

Progress Narrative Report (MTPN) Phase-Out/Transition Plan and Migration plan to a successor contractor.

As requested As requested by the Contracting Officer

Transition plan for system policy and claim files As requested As requested by the Contracting

Officer Copies of “before and after” data files and production reports or extracts for selected processing cycles.

As requested As requested by the Contracting Officer

Mail Retention Letter to first anniversary policyholders Twice per policyholder

90 business days before their policy expires. 15 business days after the policy expires if the policy payment has not been received

Claims Processing Strategy – normal conditions

Once, with annual updates (or as COR directed)

Within 30 business days of contract award

Claims Processing Strategy – surge conditions

Once, with annual updates (or as COR directed)

Within 30 business days of contract award

15 | P a g e

10. KEY PERSONNEL AND QUALIFICATIONS

The Contractor shall provide a proper skill mix and experience to perform the contract objectives. The key personnel specified in this contract, are considered to be essential to work performance. At least 30 days prior to diverting any of the specified individuals to other programs or contracts (or as soon as possible, if an individual must be replaced, for example, as a result of leaving the employ of the Contractor), the Contractor shall notify the Contracting Officer and shall submit comprehensive justification for the diversion or replacement request (including proposed substitutions for key personnel) to permit evaluation by the Government of the impact on performance under this contract.

The Contractor shall not divert or otherwise replace any key personnel without the written consent of the Contracting Officer and the Program Management Office. Identification of key personnel is subject to approval of the PMO. The Government may modify the contract to add or delete key personnel at the request of the Contractor or Government.

The following are key personnel under this contract.

10.1 Project Director – the projector director should have at least ten years of experience managing projects of similar size and scope to this Direct Servicing Agent project.

10.2 Accounting Manager – the accounting manager should have at least seven years of experience managing a financial project of similar size and scope, as well as be a Certified Public Accountant.

10.3 Claims Manager – the claims manager should have at least seven years of experience managing a claims project of similar size and scope, at least one year of experience in property insurance claims, three years of experience in commercial insurance claims, and be an NFIP certified adjuster.

10.4 Underwriting Manager – the underwriting manager should have at least seven years of experience managing an underwriting project of similar size and scope, with a minimum of five years of experience underwriting flood insurance policies. The underwriting manager will also be CPCU (Chartered Property Casualty Underwriter) certified.

10.5 Security Manager – the security manager must have at least five years’ experience and shall have at least one security certification (including certified information Systems Security Specialist, Certified Secure Software Lifecycle Professional, Certified Information Security Auditor, Certified Information Security Manager, Information Systems Security Architecture Professional, Information System Security Management Professional and Systems Security Certified Practitioner). The security manager shall be well-versed in DHS 4300A/4300B and government certification and accreditation (C&A) processes.

10.6 System Administrator – the system administrator must have at least three years of “hands on” experience. The systems administrator must also possess a certification in the operating system platform the IT system/solution will be residing on (ie…Windows, Linux) and/or knowledgeable on the identified solution(s) to meet the objectives.

10.7 Other Personnel

At least 30 days prior to diverting any of the specified individuals to other programs or contracts (or as soon as possible, if an individual must be replaced, for example, as a result of leaving the employ of the Contractor), the Contractor shall notify the Contracting Officer and shall submit comprehensive justification for the diversion or replacement request (including proposed substitutions (with resume)

16 | P a g e for key personnel) to permit evaluation by the Government of the impact on performance under this contract. The Contractor shall not divert or otherwise replace any personnel without the written consent of the Contracting Officer and the Program Management Office.

10.8 PERSONNEL REQUIREMENTS

The contractor must that have the ability to work in a dynamic, fast-paced, and challenging environment. Contractor personnel working under this contract will be required to pass a Federal Government background check (or security clearance). The contractor personnel may interface with agency senior officers, internal staff and employees; and other supportive contracted staff, at all levels, therefore, the contractor personnel must be flexible and adaptable to changes and customer service expertise.

As prescribed in 342.302(c) (2), the Contracting Officer shall insert the following clause:

10.9 Personnel – Badging/Security Requirements

The Contractor shall comply with the Department of Homeland Security’s (DHS) technical, management, and operational security controls to ensure that the Government’s security requirements are met. DHS 4300A policy guide will be used for Sensitive Systems and DHS 4300B policy guide will be used for National Security Systems.

All contracting personnel must be US Citizens, undergo the appropriate level of FEMA background screening, be FEMA badged and obtain clearance for elevated privilege responsibilities.

10.9.1 Contractor Eligibility, Continued Eligibility and Termination:

The Contractor shall provide staff with the appropriate levels of security clearance to work in Government facilities and on Government Furnished Equipment and systems. The Contractor shall ensure that each employee and potential employee provide their name and social security number for verification. If the number is not valid, then the employee will not be authorized to work on the contract until resolved. At a minimum, the Contractor staff shall have the ability to access DHS/FEMA facilities.

Subject to existing law, regulations and/or other provisions of this contract, illegal or undocumented aliens shall not be employed by the Contractor to perform on this contract. The Contractor shall ensure this provision is expressly incorporated into any and all subcontracts or subordinate agreements issued in support of this contract.

DHS and the FEMA reserves the right to deny and/or restrict entrance to Government facilities, prohibit employees from assigned work under the contract, deny and/or restrict handling of sensitive documents/material to any Contractor employee who DHS determines to present a risk of compromising classified and/or sensitive Government information.

The Contractor shall report to the FEMA Security Office any and all adverse information brought to their attention concerning employees performing under this contract. The report shall include the employee’s name and social security number, along with the adverse information being reported. Termination of employment of an employee does not obviate the requirement to submit this report. Reports based on rumor or innuendo shall not be submitted to the DHS Security Office.

10.9.2 Release of Information:

17 | P a g e

All information relating to the items to be delivered or services to be performed under this contract may not be disclosed by any means without prior approval of the Contracting Officer. Dissemination of public disclosures includes, but is not limited to: permitting access of such information to a foreign national or any other person or entity; and, publication of technical or scientific papers, advertisements, or any other proposed public release. The Contractor shall provide adequate physical protection to such information so as to preclude access by any person or entity not authorized such access by the Government.

11. PERIOD OF PERFORMANCE

The period of performance shall consist of twelve (12) months.

12. PLACE OF PERFORMANCE

Contract objectives shall be performed at the Offeror’s site within the continental United States, the IT solution must be hosted at a FedRAMP moderate level authorized location.

13. ACCESSIBILITY REQUIREMENTS (SECTION 508)

Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-

220) requires that when Federal agencies develop, procure, maintain, or use electronic and information technology (EIT), they must ensure that it is accessible to people with disabilities. Federal employees and members of the public who have disabilities must have equal access to and use of information and data that is comparable to that enjoyed by non-disabled Federal employees and members of the public.

All EIT deliverables within this work statement shall comply with the applicable technical and functional performance criteria of Section 508 unless exempt. Specifically, the following applicable EIT accessibility standards have been identified:

13.1 SECTION 508 APPLICABLE EIT ACCESSIBILITY STANDARDS

36 CFR 1194.21 Software Applications and Operating Systems, applies to all EIT software applications and operating systems procured or developed under this work statement including but not limited to GOTS and COTS software. In addition, this standard is to be applied to Web-based applications when needed to fulfill the functional performance criteria. This standard also applies to some Web based applications as described within 36 CFR 1194.22.

36 CFR 1194.22 Web-based Intranet and Internet Information and Applications, applies to all Web-based deliverables, including documentation and reports procured or developed under this work statement.

When any Web application uses a dynamic (non-static) interface, embeds custom user control(s), embeds video or multimedia, uses proprietary or technical approaches such as, but not limited to, Flash or Asynchronous Javascript and XML (AJAX) then 1194.21 Software standards also apply to fulfill functional performance criteria.

36 CFR 1194.23 Telecommunications Products, applies to all telecommunications products including end-user interfaces such as telephones and non end-user interfaces such as switches, circuits, etc. that are procured, developed or used by the Federal Government.

36 CFR 1194.24 Video and Multimedia Products, applies to all video and multimedia products that are procured or developed under this work statement. Any video or multimedia presentation shall also

18 | P a g e comply with the software standards (1194.21) when the presentation is through the use of a Web or Software application interface having user controls available.

36 CFR 1194.31 Functional Performance Criteria, applies to all EIT deliverables regardless of delivery method. All EIT deliverable shall use technical standards, regardless of technology, to fulfill the functional performance criteria.

36 CFR 1194.41 Information Documentation and Support, applies to all documents, reports, as well as help and support services. To ensure that documents and reports fulfill the required 1194.31 Functional Performance Criteria, they shall comply with the technical standard associated with Web-based Intranet and Internet Information and Applications at a minimum. In addition, any help or support provided in this work statement that offer telephone support, such as, but not limited to, a help desk shall have the ability to transmit and receive messages using TTY.

13.2 SECTION 508 APPLICABLE EXCEPTIONS

Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the COTR and determination will be made in accordance with DHS MD 4010.2. DHS has identified the following exceptions that may apply: 36 CFR 1194.3(b) Incidental to Contract, all EIT that is exclusively owned and used by the contractor to fulfill this work statement does not require compliance with Section 508. This exception does not apply to any EIT deliverable, service or item that will be used by any Federal employee(s) or member(s) of the public. This exception only applies to those contractors assigned to fulfill the obligations of this work statement and for the purposes of this requirement, are not considered members of the public.

13.3 SECTION 508 COMPLIANCE REQUIREMENTS

36 CFR 1194.2(b) (COTS/GOTS products), When procuring a product, each agency shall procure products which comply with the provisions in this part when such products are available in the commercial marketplace or when such products are developed in response to a Government solicitation. Agencies cannot claim a product as a whole is not commercially available because no product in the marketplace meets all the standards. If products are commercially available that meet some but not all of the standards, the agency must procure the product that best meets the standards. When applying this standard, all procurements of EIT shall have documentation of market research that identify a list of products or services that first meet the agency business needs, and from that list of products or services, an analysis that the selected product met more of the accessibility requirements than the non-selected products as required by FAR 39.2. Any selection of a product or service that meets less accessibility standards due to a significant difficulty or expense shall only be permitted under an undue burden claim and requires authorization from the DHS Office of Accessible Systems and Technology (OAST) in accordance with DHS MD 4010.2.

All tasks for testing of functional and/or technical requirements must include specific testing for Section 508 compliance, and must use DHS Office of Accessible Systems and Technology approved testing methods and tools. For information about approved testing methods and tools send an email to accessibility@dhs.gov.

19 | P a g e

14. GOVERNMENT-FURNISHED EQUIPMENT AND INFORMATION

Please see list attached to RFP.

The contractor shall be responsible for maintaining all GFE in a secure manner; to ensure the highest level of protection, the GFE has to have a certified image from Department of Homeland Security.

All government furnished equipment must be imaged by and maintained with a FEMA certified image.

15. DATA RIGHTS

Under the provisions of the Rights in Data General Clause (FAR 52.227-14), the Government reserves all rights, including copyrights, distribution rights, and other rights for all documents, data or software developed in the performance of this contract.

16. SECURITY REQUIREMENTS

16.1 Comply with Security Assurance Requirements

The Contractor shall demonstrate and maintain full compliance with each of the specific controls listed below, per DHS 4300A, NIST, and Federal Information Security Management Act (FISMA) baseline controls. Additionally, Contractors will be required to develop and implement a plan to mitigate any weaknesses related to these controls. The contractor will ensure all DHS4300A and NIST configuration/hardening guidelines are within compliance and remain within compliance.

16.1.1 Implement and Maintain Access Controls

16.1.2 Implement and Maintain Awareness and Training Controls

16.1.3 Implement and Maintain Audit and Accountability Controls

16.1.4 Implement and Maintain Security Assessment and Authorization Controls

16.1.5 Implement and Maintain Configuration Management Controls

16.1.6 Implement and Maintain Contingency Planning Controls

16.1.7 Implement and Maintain Identification and Authentication Controls

16.1.8 Implement and Maintain Incident Response Controls

16.1.9 Implement and Maintain Maintenance Controls

16.1.10 Implement and Maintain Media Protection Controls

16.1.11 Implement and Maintain Physical and Environmental Protection Controls

16.1.12 Implement and Maintain Planning Controls

16.1.13 Implement and Maintain Personnel Security Controls

16.1.14 Implement and Maintain Risk Assessment Controls

20 | P a g e

16.1.15 Implement and Maintain System and Services Acquisition Controls

16.1.16 Implement and Maintain System and Communications Protection Controls

16.1.17 Implement and Maintain System and Information Integrity Controls

16.2 Provide User Authentication and Secure Connections

FEMAs OCIO is implementing PIV and single sign on solutions (SSO) solutions for all FEMA IT systems…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .