II_01_2032H325Q00063_Attachment 1_SOW.pdf

PDF 270 KB Posted

Attached to
U. S. Department of Treasury_ Artificial Intelligence (AI) Tools Federal contract opportunity
Solicitation number
2032H325Q00063
Issued by
Department of the Treasury Departmental Offices

About this file

This document is a Statement of Work (SOW) for the U.S. Department of the Treasury seeking AI-powered tools for coding assistance and chat functionality. The SOW requires vendors to provide FedRAMP-authorized AI tools with advanced capabilities, including multi-language code generation, automated code reviews, contextual search, and natural language interaction across various domains like IT, finance, and cybersecurity. Key requirements include usage-based pricing (per-token or per-query), support for multiple programming languages, and strict security compliance with federal standards like FISMA and NIST 800-53.

The SOW specifies detailed technical and operational requirements, such as 99.9% system uptime, rapid incident response, U.S.-based data processing, and robust data usage restrictions. Vendors must ensure their AI tools have built-in bias mitigation, explainability features, and human-in-the-loop oversight. The tools must support integration with development environments like Visual Studio Code and collaboration platforms, and comply with IPv6 requirements. The contract will allow for on-ramp and off-ramp procedures to maintain a competitive and capable contractor pool, with potential periodic re-evaluations of the AI solutions.

View the file

Other files for this federal contract opportunity

Other files attached to U. S. Department of Treasury_ Artificial Intelligence (AI) Tools, newest first.
File Type Posted
2032H325Q00063_Amendment 0004_.pdf PDF
Amendment 0004_ 2032H325Q00063_Revised Terms and Conditions.pdf PDF
II_01_2032H325Q00063_Attachment 2_Price Matrix_Amendment 0004.xlsx XLSX spreadsheet
Amendment 0003_2032H325Q00063.pdf PDF
Amendment 0003_Attachment 1_Tool Threshold Assessment.docx DOCX document
2032H325Q00063_Amendment 0002_Final.pdf PDF
II_01_2032H325Q00063_Attachment 1_SOW_Amend 1.pdf PDF
II_QA_2032H325Q00063.xlsx XLSX spreadsheet
II_01_2032H325Q00063__Amendment 1.pdf PDF
II_01_2032H325Q00063_Attachment 2_Price Matrix_Amend1_20250709.xlsx XLSX spreadsheet
DRAFT RFQ_Questions and Answers_AI Tools.xlsx XLSX spreadsheet
II_01_2032H325Q00063_Attachment 2_Price Matrix.xlsx XLSX spreadsheet
II_01_2032H325Q00063_TCs.pdf PDF
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Request for Quote (RFQ): 2032H325Q00063 Attachment 1: Statement of Work

STATEMENT OF WORK (SOW)

AI Tools for Treasury

1 OVERVIEW

The U.S. Department of the Treasury (Treasury), Office of the Chief Information Officer (OCIO), is seeking qualified providers of state-of-the-art Artificial Intelligence (AI)-powered coding assistant tools (similar to GitHub Copilot, AWS CodeWhisperer, Cursor, etc.) and AI-based chat tools (similar to ChatGPT) that can be delivered as a shared service across the Department and its bureaus.

The intent is to provide developers and IT staff within Treasury with flexible, secure and modern AI-driven coding solutions tailored to their specific development workflows. Selected solutions must operate exclusively on a usage-based pricing model (e.g., per-token, per-completion, or per-query usage). Per-seat licensing or fixed monthly user fees will not be accepted.

2 DEFINITIONS

AI-based coding assistant tools refer to tools that support software development through features such as code generation, completion, debugging, and refactoring.

AI-based chat tools refer to interactive AI-driven platforms designed to assist users via natural language dialogue, including tasks such as research, drafting, summarization, or technical troubleshooting.

3 SCOPE

The requirement covers the procurement of secure, reliable, FedRAMP-authorized AI-based coding assistant tools and AI-based chat tools. These tools are intended to support Treasury’s operations across a range of environments and use cases, while meeting stringent federal security and compliance mandates.

AI-based coding assistant tools are expected to support the software development lifecycle by enhancing developer productivity, improving code quality, and accelerating delivery through features such as code generation, completion, debugging, and refactoring.

AI-based chat tools are intended to support Treasury’s general business functions by enabling secure, natural language interaction to assist with tasks such as information retrieval, content drafting, summarization, and technical troubleshooting. These tools should be suitable for use by both technical and non-technical personnel in daily mission and administrative activities.

4 OBJECTIVES

A. General Requirements

The vendor shall provide tools that can meet the following requirements:

1. AI Powered AI Code Assistant Tool

1.1 AI Coding Assistant Capabilities

The vendor shall provide an AI coding assistant capable of delivering real-time, context-aware code suggestions, completions, and generation. The solution must support natural language prompts for code creation, editing, and explanation, allowing developers to engage with the tool in a conversational manner. It shall assist with common development tasks, including code review, documentation, refactoring, optimization, and automated test case generation, and must support a wide range of programming languages such as TypeScript, JavaScript, Python, Java, C#, C++, Go, SQL, Bash, PowerShell, COBOL, and PeopleCode.

At a minimum, the tool shall provide the following capabilities:

• Multi-language code generation

• Automated code reviews

• Code documentation generation

• Security issue detection (e.g., similar to CAST for PeopleSoft)

• Unit test and code coverage recommendations

• Performance tuning suggestions

• Troubleshooting assistance

• General technical guidance

• Contextual search and summarization of defects, requirements, and service tickets

1.2 Advanced Model Capabilities

The vendor shall provide access to advanced AI models with capabilities comparable to leading large language models such as GPT-4, AWS CodeWhisperer, Claude, or similar state-of-the-art technologies. The solution must offer a conversational generative AI service powered by large language models, enabling natural and effective interactions. It should demonstrate proven accuracy and measurable productivity gains in both public and private sector development environments.

1.3 Model Bias and Explainability

Vendors shall provide models that include built-in mechanisms to mitigate bias and support explainability of outputs in accordance with applicable AI governance and ethical use principles. The solution shall provide transparency into how recommendations are generated, including visibility into model reasoning, contributing inputs, or decision logic, where available.

The system shall also offer user-level controls that allow individuals to accept, reject, or customize AI-generated outputs, enabling human-in-the-loop oversight and appropriate application of results.

The system shall offer interactive explanations, allowing users to explore the reasoning behind AI outputs. Users must be able to flag incorrect or problematic outputs for review and provide feedback to improve system performance. The system should track these corrections to prevent recurring issues.

1.4 FedRAMP Compliance

Vendors shall ensure their software is authorized at a FedRAMP Moderate or High impact level, as required by Treasury’s security and data classification needs. The required FedRAMP level will be determined by Treasury based on risk assessments and the intended use of the software.

The software must be fully compatible with deployment in FedRAMP-authorized environments and support secure configuration, deployment, and operation in a manner that does not compromise the compliance posture of Treasury’s cloud infrastructure.

Vendors shall provide documentation as needed to support Treasury’s security assessment and Authorization to Operate (ATO) processes, and shall notify the Government of any known risks, limitations, or dependencies that could impact FedRAMP compliance.

Vendors shall maintain the applicable FedRAMP authorization throughout the period of performance and notify the Government of any change in status, delay in authorization efforts, or revocation of authorization.

1.5 Deployment and Integration

Vendors shall provide software that is deployable within a FedRAMP-authorized Government cloud environment, such as Azure GovCloud, AWS GovCloud, Google Cloud Assured Workloads, or IBM Cloud for Government, in accordance with Treasury’s security and hosting requirements.

The software shall support seamless integration with commonly used Integrated Development Environments (IDEs), including but not limited to Visual Studio Code, JetBrains IDEs, Visual Studio, and Eclipse.

Additionally, the solution shall be compatible with major source control and DevOps platforms, including GitHub, Azure DevOps, GitLab, and Bitbucket, to enable integration with Treasury’s existing development workflows.

1.6 Security, Privacy, and Compliance

The vendor shall ensure full compliance with all applicable federal security standards, including FISMA Moderate or High, NIST 800-53, and any Treasury-specific information assurance requirements. The solution must be capable of operating within a secure environment that aligns with the cybersecurity and risk management expectations of the federal government.

The solution must also meet U.S. data sovereignty requirements. All data processing and storage must take place within data centers physically located in the United States and managed exclusively by U.S. persons to ensure full jurisdictional and operational control.

Additionally, the vendor must guarantee that no Treasury data—including source code, prompts, metadata, or other user-generated content—will be used to train, fine-tune, or otherwise enhance any AI models without the explicit, written authorization of a designated Treasury Executive.

Token revalidation within the system shall occur at minimum every 30 minutes of active use. Idle timeout must be configurable, with a default maximum of 15 minutes of inactivity before requiring reauthentication. These parameters should be adjustable through administrative controls to accommodate different sensitivity levels.

Session tokens within the system must have a maximum lifetime of 12 hours, with sliding expiration supported for active sessions. Refresh tokens should be limited to 24 hours maximum. All tokens must be securely stored, transmitted, and revocable through administrative action. Token validation should occur with each significant action, not just at session initiation.

The system must integrate seamlessly with one of the following: Visual Studio Code, JetBrains IDEs (particularly IntelliJ IDEA and PyCharm), Visual Studio, and Eclipse.

These represent Treasury's primary development environments. Support for web-based IDEs is also desirable as the agency continues its modernization efforts.

The system shall allow for data to be logically segregated by bureau and configurable down to the user group level. Both encryption-at-rest and in-transit are mandatory, using FIPS 140-2 (or newer) validated cryptographic modules. Key management processes must support Treasury's security requirements and allow for integration with existing key management systems.

The solution must support IP-based restrictions to limit access to Treasury network ranges, device fingerprinting to prevent unauthorized device usage, and basic behavioral anomaly detection to identify suspicious patterns.

The solution must provide administrative override capabilities. Including forced logout and session termination for individual users or groups. Real-time alerts must be generated for suspicious activities such as multiple failed authentication attempts, access from unusual locations, or attempted session hijacking.

1.7 Reliability, Support, and Availability

The vendor shall provide a reliable and continuously available service in accordance with the service levels defined in the attached SLA table. These commitments include system uptime, support availability, response times, incident management, and data handling practices.

Vendors must ensure all system changes that may impact availability are communicated in advance and support a well-documented incident escalation path. Treasury may request regular reporting on system performance, service disruptions, or response metrics.

The system shall be optimized for operation across network connections with bandwidth as low as 10 Mbps and latency up to 100ms. Degraded but functional operation should be maintained even in suboptimal network conditions, with appropriate client-side caching to enhance user experience.

See Service Level Agreement (SLA) Table for detailed service expectations and remedies for non-compliance.

1.8 Training, Onboarding, and Change Management

To support Treasury’s ability to independently adopt and operationalize the tools, vendors shall provide standard, commercially available training and onboarding resources that accompany the licensed product. No customization or tailored content is required or expected.

Vendors shall provide access to publicly available training materials such as user guides, tutorials, FAQs, and technical documentation. This should also include standard video tutorials, webinars, or onboarding modules that are typically included with the license at no additional cost.

Onboarding support must include general resources for new users, such as platform navigation instructions, setup guidance, and publicly available content for account provisioning, role management, and feature overviews. These materials should be designed to help users become self-sufficient with minimal external assistance.

For change management, vendors shall offer any enablement strategies or adoption guides that are typically part of their off-the-shelf solution. Treasury should also be granted access to any public-facing online communities, forums, or self-service support portals the vendor makes available to all customers. These resources must be sufficient to support a Treasury-led rollout without the need for customized vendor services.

1.9 Vendor Viability and Roadmap Alignment

Vendors shall maintain organizational capacity and product continuity necessary to support Treasury’s use of the licensed AI tools throughout the contract period of performance. This includes continued availability of the offered solution, ongoing maintenance, and access to standard product enhancements and updates.

Vendors shall provide Treasury with access to product roadmap information to inform internal planning and ensure awareness of upcoming features, deprecations, or changes that may affect integration, security, or usability. Roadmap visibility is intended to support proactive Treasury adoption planning and does not require development of custom roadmaps or deliverables.

2. AI Powered Chat Assistant Tool

2.1 AI Chat Assistant Capabilities

The vendor shall provide an AI chat assistant capable of natural language understanding and generation to support a wide range of knowledge work and user interactions. The solution must enable users to engage conversationally using plain language prompts to receive contextually relevant responses. It should support tasks such as summarization, content drafting, question answering, policy interpretation, process explanation, and knowledge retrieval. The assistant must be capable of operating across a variety of subject domains, including IT, finance, human resources, cybersecurity, and procurement.

2.2 Advanced Model Capabilities

Same as paragraph 1.2.

2.3 Model Behavior and Explainability

Vendors shall provide models that include built-in mechanisms to mitigate bias and support explainability of outputs in accordance with applicable AI governance and ethical use principles. The solution shall offer transparency into how responses are generated, including citations, source tracing, or explanation of reasoning where available.

The system shall also offer user-level controls that allow individuals to accept, discard, or refine AI-generated responses, ensuring human-in-the-loop oversight for responsible use of the technology.

2.4 FedRAMP Compliance

Same as paragraph 1.4.

2.5 Deployment and Integration

The vendor shall provide software deployable within a FedRAMP-authorized Government cloud environment, such as Azure GovCloud, AWS GovCloud, Google Cloud Assured Workloads, or IBM Cloud for Government, in accordance with Treasury’s security and hosting requirements.

The solution shall be accessible through a web-based interface and optionally provide integrations with collaboration platforms such as Microsoft Teams, Slack, or

ServiceNow. If available, integration with enterprise search systems or content repositories is preferred to enhance retrieval-augmented generation (RAG) capabilities.

2.6 Security, Privacy, and Compliance

The solution must comply with applicable federal security standards, including FISMA Moderate or High, NIST 800-53, and Treasury-specific requirements. All processing of Treasury prompts, responses, and metadata must occur within U.S.-based, FedRAMP-authorized environments.

Vendors shall guarantee that no user-generated content—including questions, prompts, summaries, or any conversational data—will be used to train or fine-tune models without explicit, written authorization from Treasury. The system must support administrative controls for prompt retention, logging, auditability, and user role management to ensure secure and compliant use.

2.7 Reliability, Support, and Availability

The vendor shall provide a reliable and continuously available AI chat service in accordance with the service levels defined in the attached SLA table. Treasury must be notified of planned outages, updates, or known issues that may impact user access or performance.

2.8 Training, Onboarding, and Change Management

The vendor shall provide standard training and onboarding materials to help users effectively adopt the AI chat assistant. Materials should include publicly available user guides, usage examples, FAQs, and best practices for effective prompt writing and use of the assistant. These resources should require no customization and be sufficient for Treasury-led rollout.

2.9 Vendor Viability and Roadmap Alignment

Same as paragraph 1.9.

3. Miscellaneous

3.1 This requirement is for code accelerators and chat generative response capabilities. It does NOT include any service requirements outside of standard labor provided as a part of the price of licensing, e.g., basic provisioning and activation, access to standard support, routine software updates, self-service resource, license management assistance. In addition, this requirement does not include use cases for model access beyond developed integrated development environments.

3.2 Vendors shall provide a sandbox or test environment upon contract award to facilitate information sharing, configuration, and setup activities necessary to support smooth integration and implementation.

3.3 Treasury has a robust cyber security infrastructure, to include Security Technical Implementation Guides (STIGs).

3.4 Rollout of licensing may not follow a standard adoption model, and Vendors must be prepared to support the Treasury in a phased, non-linear, or decentralized deployment approach.

This includes the ability to provision licenses incrementally, accommodate staggered onboarding across bureaus, and provide responsive support during varying levels of user adoption and system integration.

3.5 Treasury standards, frameworks and protocols will be provided post-award.

3.6 Vendors must configure, or assist Treasury in configuring, their tools to prevent users from replicating authenticated sessions for access outside the Treasury network.

Items to be included in the solicitation and resulting award:

Condition of Award and Continued Performance – Software Updates and Upgrade Path - As a condition of award and continued contract performance, the Contractor shall provide all updates, upgrades, and new versions of the proposed software that are made generally available during the period of performance. This includes security patches, performance improvements, and feature enhancements. The Contractor must also ensure a clear and supported glide path to newer versions, with no degradation in functionality or disruption to government operations.

License and Usage Reporting – The vendor shall provide quarterly reports detailing active licenses, user activity – to include a highlight of licenses that have been inactive for 30 days or more, and feature utilization for all Treasury-authorized users. Reports shall include metrics on adoption, usage volume, and any inactive licenses. These reports are intended to support program oversight, license optimization, and ensure contract compliance. Treasury reserves the right to request additional data as needed to verify billing accuracy and support planning efforts.

The solution must support for SCIM or equivalent provisioning standards is required.

Onboarding of new users should be completed within 24 hours of approval, while offboarding/deprovisioning must occur within 1 hour of request to maintain security. The system should support automated workflows that integrate with Treasury's approval processes.

The solution must support containerized deployments (Docker) and virtual machine installations.

Bare-metal support is not required but would be considered advantageous. The primary deployment model will be within Treasury's FedRAMP-authorized cloud environments.

Pricing – Prices are established on a usage-based pricing model, such as per-token, per-query, or per-completion charges. No other pricing models are allowable under this contract.

Ordering – It is permissible for orders placed under this IDIQ to be issued with Not-To-Exceed (NTE) values. Although orders will be structured as Firm-Fixed-Price (FFP), the Government may elect to incrementally fund up to the NTE value. Additionally, vendors shall return any unused licenses to the open license pool if they have not been activated or in use for 90 consecutive days and shall adjust billing accordingly to reflect actual usage only.

IPv6 Compliance – The Contractor shall:

• Ensure all proposed tools—whether hosted on-premises or delivered as cloud services (SaaS)—support operation in IPv6-only environments.

• Ensure that all networking interfaces used for communication with end users, APIs, or integration points support IPv6 natively, without reliance on IPv4.

• Ensure the tools interoperate with Treasury’s IPv6-enabled enterprise infrastructure, including but not limited to identity providers, endpoint protection platforms, and supporting systems.

• Ensure tools are capable of sending, receiving, and processing data over IPv6 networks independently of IPv4.

• Maintain compliance with OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol Version 6 (IPv6),” and other applicable federal IPv6 requirements, including relevant NIST guidance, for the duration of the period of performance.

• If any tool, feature, or service is determined to be non-compliant, provide an update or alternative solution at no additional cost to the Government.

o If full IPv6 compliance is not immediately achievable, provide a roadmap with milestones and expected timelines for achieving full support.

• Support periodic Government reviews to verify IPv6 compatibility and cooperate fully with any related assessments or testing activities.

On Ramp Procedures for IDIQ Holders - To maintain a competitive and capable contractor pool that meets evolving mission requirements, the Government reserves the right to conduct on-ramp procedures to add new contractors to this IDIQ contract throughout the period of performance. On-ramping may occur at the Government’s discretion under the following circumstances:

1. Mission Need: A determination that additional capacity, capabilities, or competition is required to meet evolving program demands or address contractor performance issues.

2. Technology Evolution: Emergence of new technologies or capabilities not represented in the current awardee pool.

3. Market Conditions: Identification of qualified vendors outside the original awardee pool through market research or industry outreach.

4. Programmatic Changes: Expansion of scope, funding availability, or the addition of new task areas not previously anticipated.

The Government may issue a Request for Proposal (RFP) or limited on-ramp solicitation, which will mirror the original evaluation criteria or include updated criteria as needed to reflect current mission priorities. Interested offerors will be evaluated competitively and fairly in accordance with the procedures outlined in the solicitation.

Contractors selected through an on-ramp process will be awarded an IDIQ contract under the same terms and conditions (unless otherwise stated) as the original pool. The on-ramp process may occur periodically or as-needed, at the Government’s sole discretion.

This clause enables the Government to maintain flexibility, promote innovation, and ensure that the contractor base continues to meet programmatic and performance requirements over the life of the contract.

Off-Ramp Procedures for IDIQ Holders – The Government reserves the right to off-ramp IDIQ contract holders based on performance, responsiveness, or other objective criteria to maintain a pool of responsible, responsive contractors. Off-ramping may be initiated at the Government’s discretion under any of the following conditions:

1. Proposal Responsiveness: Failure to submit proposals in response to at least 75 percent of order requests issued during any rolling 12-month period.

2. Award Activity: Failure to receive at least one task order award within any defined ordering period (e.g., base period or option year).

3. Performance: Receipt of two or more CPARS ratings of less than “Satisfactory” for orders performed under this IDIQ contract.

4. Technical Noncompliance: Repeated failure to meet Statement of Work (SOW) requirements or to deliver order outcomes on time, within budget, or at the required quality.

5. Administrative Deficiencies: Ongoing issues related to invoicing, reporting, or failure to meet contract deliverable schedules or documentation requirements.

Prior to removal, the contractor will receive written notice outlining the Government’s intent to off-ramp, along with an opportunity to respond. Off-ramping may be executed through one or more of the following actions:

• Non-exercise of future ordering period options;

• Administrative modification to remove the contractor from the IDIQ award pool;

• Contract termination in accordance with FAR Part 49.

These procedures are intended to ensure high-performing contractors remain available to meet mission needs, while enabling the Government to manage contract risk effectively.

Initiation of off-ramping actions is at the Government’s discretion, based on the criteria outlined above. Prior to final disposition, the contractor will be provided written notice and an opportunity to respond. Final off-ramping actions will be executed using one or more of the methods identified above and documented in the contract file in accordance with applicable regulations.

Service Level Agreements (SLAs):

Service Component SLA Commitment Measurement

Method Remedy for Non-

Compliance

System Uptime Minimum 99.9% monthly uptime

Monitored via vendor-provided availability logs

Service credit of 5% per 0.1% below target

Prompt Response Time

≤ 2s (Simple), ≤ 4s (Moderate), ≤ 7s (Complex)

Measured from prompt receipt to first response byte, averaged over a rolling 7-day period, per prompt category

Service credit of 2% per 1s above target, per category

Prompt Response Time Reporting Requirement

Vendor-provided log and weekly statistical summary

Must include timestamp, category, and response time for each request

Right to audit or independently test performance

Support Availability 24/7 support via ticketing/email; business hours phone support

Support logs and availability reports

Service credit for missed coverage

Support Framework

Vendor must provide documented support hours, escalation procedures, and named contacts

Submission of support documentation and account contacts

Withholding of approval until criteria are met

Incident Acknowledgment (Severity 1)

Within 1 hour of report Incident tracking system

Escalation to executive contact after 2 hours

Incident Resolution (Severity 1)

Within 4 hours Incident ticket closure time

Service credit of 10% if unresolved in 8 hours

Model/Service Updates

Minimum 14 days’ advance notice for major changes or updates

Written/email notice from vendor

Delay of update until agency review is complete

Data Residency 100% U.S.-based data storage and processing

Compliance audit and documentation

Contract breach and possible termination

Data Usage Restrictions

No use of Treasury data for model training without written Treasury Executive consent

Policy review and system controls audit

Right to audit or terminate

Model Downgrade/Failure Recovery

Failover to backup model within 15 minutes of outage

System recovery logs and uptime reporting

Service credit of 5% per 15-minute delay

SSO Availability (if applicable)

99.9% uptime for authentication services

Authentication service logs

Service credit of 2% per 0.1% below threshold

Self-Service Resources

Vendor must provide access to documentation, knowledge bases, FAQs, and developer guides

Review of vendor resource portal

Required prior to deployment acceptance

Special Requirements for AI-Based Tools – To ensure responsible, secure, and legally compliant use of AI-based tools, the Contractor shall adhere to the following requirements in addition to the general and functional requirements described elsewhere in this SOW:

1. Data Ownership and Rights

• The U.S. Government shall retain unlimited rights to all data entered into, processed by, or generated through the use of any AI tools provided under this contract. This includes, but is not limited to:

o Input data (e.g., prompts, source code, queries) o Output data (e.g., generated content, responses, code suggestions) o Metadata, logs, interaction histories, and audit trails

• No data collected, processed, or generated under this contract may be used by the Contractor for any purpose other than performance of the contract, unless explicitly authorized in writing by the Contracting Officer.

2. Restrictions on Model Training or Enhancement

• The Contractor shall not use any Government-provided or Government-generated data— including prompts, outputs, source code, metadata, or usage logs—for the purpose of training, fine-tuning, or otherwise enhancing any AI models, algorithms, or commercial services, unless explicitly authorized in writing by the Government.

3. Audit and Inspection Rights

• The Government reserves the right to audit the AI system’s behavior, performance, and data handling practices. This includes access to:

o Usage logs o Prompt and completion histories o System-level metadata relevant to security, performance, or compliance

• The Contractor shall cooperate fully with any Government-requested audit or review.

• SAML 2.0 with ADFS compatibility is the minimum requirement, additional support for

OAuth2 and OpenID Connect is highly desirable. Integration with Treasury's identity providers is not required at award but must be implemented within the first 30 days of the base period. Vendors should describe their experience with similar federal identity management integrations.

4. Model Updates and Notification

• The Contractor shall notify the Government in advance of any substantial changes to the

AI models, including:

o Model upgrades o Retraining or tuning events o Functional or performance-impacting updates

• The Government reserves the right to re-evaluate the solution following such updates to ensure continued compliance and suitability.

5. Transparency and Disclosure

• The Contractor shall provide documentation describing:

o The general architecture and behavior of the AI model o How outputs are generated (e.g., general algorithmic approach or logic, where feasible) o Any known limitations, risks, or failure modes

• The AI tool must disclose to end users when they are interacting with an AI system and allow for human-in-the-loop oversight.

6. Responsible and Ethical Use

• The Contractor shall ensure the AI tools are aligned with applicable federal guidance on responsible and ethical AI use, including but not limited to:

o OMB M-21-07 (IPv6 and modernization) o NIST AI Risk Management Framework o Treasury-specific AI policies, if provided

• The solution must include safeguards to detect and mitigate biased, harmful, or misleading outputs and support human review and correction where applicable.

1. Data Ownership and Rights
2. Restrictions on Model Training or Enhancement
3. Audit and Inspection Rights
4. Model Updates and Notification
5. Transparency and Disclosure
6. Responsible and Ethical Use

File details come from the government source that posted it. Updated .