RRB12R004 Attachment 7 FMIS Due Diligency Checklist.rtf
RTF text file 335 KB Posted
- Attached to
- Financial Management Integrated System (FMIS) Federal contract opportunity
- Solicitation number
- RRB12R004
- Issued by
- Railroad Retirement Board
About this file
RRB12R004 Attachment 7 Due Diligence Checklist
Text of this file
Financial Management Line of Business (FMLoB) Federal Shared Service Provider (SSP) Due Diligence Checklist Version 1.0 June 2009
FMLoB Federal SSP Due Diligence Checklist – Version 1.0 (Existing SSPs)
Background A shared service provider (SSP) is a separate and distinct organization established to provide technology hosting and administration, application management services, system implementation and where appropriate, business process services to other entities. As the Managing Partner for the FMLoB, the General Services Administration (GSA) performs the project management role and is responsible for the management oversight used to achieve the vision and goals of the FMLoB.
The Due Diligence Checklist (DDC) for existing SSPs will be used by the Office of Management and Budget (OMB), the Financial Systems Integration Office (FSIO) within GSA, and customer agencies to assess SSPs’ current operating environments as well as compliance with various financial management, system security, and privacy requirements.
The Due Diligence Checklist is divided into the following parts:
| Part I – Current Operations. These questions assess current customers as well as the extent to which processes, procedures, and methodologies have been implemented, standardized and are reflective of best practices. |
| Part II – Compliance. These questions are used to determine if an SSP is in compliance with the applicable requirements designated for operating a financial management system, including security, audit controls, and privacy. During an annual review of the Due Diligence Checklist criteria, if an SSP answers “no” to any of these Demonstrated Criteria Questions, the SSP must demonstrate the issue will be resolved in a timely manner via a Corrective Action Plan. |
Responses from Federal SSPs should be submitted to OMB/FSIO annually with the Exhibit 300.
Part I: Current Operations Please answer all questions below based on the current state of your organization. If necessary, include reference or additional materials in the form of an attachment.
SSP Name
Agency
Unique Project Identifier (UPI) (Government only)
Evaluation Area I.
Response Comments SSP Customers 1.1 I.1.1 Please provide the number of CFO Act and non-CFO Act Agency customers the SSP provides services to. Please provide a listing of these customers in Attachment A, including the number of users associated with each.
N/A
Number of CFO Act Agency customers:_____ Number of non-CFO Act Agency customers:______
I.1.2 Please provide the number of new agency customers added within the past year. Please also provide the number of agency customers that have terminated SSP services within the past year.
N/A Number of new agency customers:______ Number of terminated agency customers:______ I.1.3 Has the SSP migrated any new customer agencies with the past year?
If Yes, in the Comments please provide detailed information regarding the type of customer agency services migrated, migration services offered by the SSP (e.g., project management, change management, data conversion, etc.), and any schedule or cost variances, including explanations for the variances.
Yes
No
Processes, Procedures, and Methodologies I.2
I.2.1 Does the SSP offer a repeatable set of best practices for delivering standardized services?
In the Comments, please describe the best practices used to deliver the standardized services as well as any flexibility offered by the SSP to accommodate unique business processes required by an agency to conduct its business.
Yes
No
I.2.2 Does the SSP have appropriate control techniques and audit procedures in place to ensure the completeness, accuracy, validity, confidentiality, and availability of transactional and master data as described in the Federal Information System Controls Audit Manual (FISCAM)?
If No, in the Comments, please describe any deviations from control techniques and/or audit procedures.
Yes
No
1.2.3 Does the SSP have appropriate control techniques and audit procedures in place and used consistently for Data Management System Controls as outlined in the FISCAM?
If No, in the Comments, please describe any deviations from control techniques and/or audit procedures.
Yes
No
I.2.4 Does the SSP Service Level Agreement have a performance measurement methodology in place with metrics that address system availability, performance, and costs?
In the Comments, please describe performance measures captured for customer agencies, including methods of collection, frequency, and current status.
Yes
No
I.2.5 Does the SSP account for its full costs or have a cost accounting methodology or other methodology that complies with the Federal Acquisition Regulations (FAR) and fairly allocates costs, including fixed and variable costs, to internal and external customers?
In the Comments, please provide a description of current cost accounting methodologies or describe any current efforts by the SSP to implement a cost accounting methodology.
Yes
No
N/A
I.2.6 Does the SSP provide a help desk staffed with personnel trained in the use of the specific FM systems, with regular hours of operation?
List any applicable performance standards, e.g., , number of help desk support staff, the hours of operation and any expanded hours available at a premium, etc., in the Comments.
Yes
No
I.2.7 Does the SSP provide formal procedures for communication, escalation and resolution of issues (this includes, critical issues, non-critical issues, incidents and problems)?
In the Comments, please provide a brief description of the formal communication procedures.
Yes
No
I.2.8(a) Does the SSP provide an interface to the FM-related E-Gov Initiatives including E-Travel, Central Contractor Registration (CCR), and E-Payroll? Support is defined as being capable of interfacing or integrating with one or more of the solutions provided by these initiatives.
In the Comments, please list the integration supported and interfaces supported.
Yes
No
I.2.8(b) If the response to 1.2.6(a) is “Yes,” does the SSP have appropriate control techniques and audit procedures in place and used consistently for Interface Controls as outlined in the FISCAM?
If No, in the Comments, please describe any deviations from control techniques and/or audit procedures.
Yes
No
N/A
I.2.9 Does the SSP have experience implementing agreements similar to the interconnection security agreement and Memoranda of Understanding outlined in NIST Special Publication 800-47 for agency feeder systems such as Federal ePayroll, eTravel, SmartPay credit card systems, etc ?
If No, in the Comments, please describe any efforts underway by the SSP to delineate processes, roles and responsibilities for interconnecting a customer agency’s systems to the core financial system.
Yes
No
I.2.10 Does the SSP currently have in place standards and templates for systems implementation, interface configuration, operations, and ongoing support?
If No, in the Comments, please describe any efforts underway by the SSP to develop standards and templates to support customer agency implementations and ongoing operations and support.
Yes
No
I.2.11(a) Does the SSP currently have in place a formal governance model for configuration management that communicates changes and impacts to the customer?
If No, in the Comments, please describe the SSP’s commitment or timeframe to establishing a model prior to the solution provider signing an agreement with a customer agency.
Yes
No
I.2.11(b) If the response to 1.2.9(a) is “Yes,” does the SSP have appropriate control techniques and audit procedures in place and used consistently for Configuration Management as outlined in the FISCAM?
If No, in the Comments, please describe any deviations from control techniques and/or audit procedures.
Yes
No
N/A
I.2.11(c) Are all customers involved in the SSP governance process for configuration management?
If No, in the Comments, please describe the role of customers in the SSP configuration management governance process, including any planned timeframe to include customers as part of the process.
Yes
No
I.2.12 Does the SSP capture lessons learned post-implementation of a customer agency system?
If Yes, are the lessons learned incorporated into system implementation standardized processes and templates?
Yes No
Part II: Compliance Please answer all questions below based on the current state of your organization. If necessary, include reference or additional materials in the form of an attachment.
A response of “no” to any of the questions will signify that the SSP is non-compliant with the Due Diligence Checklist. The SSP must establish a Corrective Action Plan and commit to meeting the requirement by the timeframe agreed upon (by the SSP and the Customer Agency, and by OMB). If an SSP does not meet the requirement in the agreed-upon timeframe, its OMB designation may be removed, effectively suspending the SSP from competing for new customers and renewing existing customers.
SSP Name
Agency
Unique Project Identifier (UPI)
Evaluation Area II.
Response Comments Security and Incident Response II.1 II.1.1(a) Does the SSP have Continuity of Operations Plans (COOP) for each agency it services and for which successful Disaster Recovery Testing has been performed within the last 12 months?
If No, please indicate the number of customer agencies for which either a COOP is not in place and/or successful Disaster Recovery Testing has not been performed. Please also provide details on any efforts for COOP implementation and testing.
Yes
No
II.1.1(b) Does the SSP have appropriate control techniques and audit procedures in place and used consistently for Contingency Planning as outlined in the FISCAM?
If No, in the Comments, please describe any deviations from control techniques and/or audit procedures.
Yes
No
II.1.2
Are the SSP’s customer-relevant financial systems implemented with the appropriate security controls consistent with the Federal Information Security Management Act (FISMA) and NIST Special Publication 800-53?
In the Comments, please provide information on the type of industry security standard(s) met if you currently lack a Federal customer to designate that you have achieved full FISMA compliance.
Yes
No
II.1.3(a) Does the SSP have a process for performing periodic testing and evaluation of information security controls in accordance with the FISMA and NIST Special Publication 800-37 and 800-53A?
If Yes, in the Comments, please indicate frequency of testing and evaluation and address any instances of non-compliance within the last 3 years. If No, please provide details on efforts to implement a FISMA- and NIST-compliant process.
Yes
No
II.1.3(b) If the response to II.1.3(a) is “Yes,” does the SSP have appropriate control techniques and audit procedures in place and used consistently for Security Management as outlined in the FISCAM?
If No, in the Comments, please describe any deviations from control techniques and/or audit procedures.
Yes
No
N/A
II.1.4
Have all environments and applications being used to provide SSP services been FISMA Certified and Accredited (C&A) within the last three years?
If No, in the Comments, please provide a timeline for conducting such an assessment in becoming a system of record for a customer agency.
Yes
No
Il.1.5 Has the SSP undergone a Federal Information Security Management Act (FISMA) risk assessment within the last 36 months in accordance with NIST Special Publication 800-30?
If No, in the Comments, please provide a timeline for conducting an assessment.
Yes
No
II.1.6
Does the SSP have appropriate control techniques and audit procedures in place and used consistently for Risk Assessments as outlined in the FISCAM?
If No, in the Comments, please describe any deviations from control techniques and/or audit procedures.
Yes
No
II.1.7
If conducted, did the most recent FISMA risk assessment review completed for any SSP service offering identify significant deficiencies?
If Yes, in the Comments, please describe the deficiencies and provide a timeline for correction.
Yes
No
N/A
II.1.8
Does the staff at each data center providing Federal SSP services have the appropriate security clearances as required by NIST Federal Information Processing Standard 201, PIV Part1?
If No, in the Comments, please describe any efforts to comply with the NIST standard.
Yes
No
II.1.9
Does the SSP have appropriate control techniques and audit procedures in place and used consistently to ensure proper Segregation of Duties as outlined in the FISCAM?
If No, in the Comments, please describe any deviations from control techniques and/or audit procedures.
Yes
No
II.1.10
Does the SSP have an appointed information systems security officer as required under FISMA?
If No, in the Comments, please provide a timeline for appointing a designated security officer.
Yes
No
Internal Controls II.2
II.2.1
Have the systems managed by the SSP undergone a SAS-70 Type II audit within the past year that resulted in either an unqualified opinion or findings that were not significant enough to impact the organization’s ability to serve as an SSP?
In the Comments, please provide information on any SAS-70 findings and specify if the finding impacted the services to a customer agency. If it is deemed that any finding is due to the SSP’s controls, the SSP will be deemed to be in non-compliance.
Yes
No
II.2.2
If the SSP is providing business process services to customer agencies, has the SSP undergone the necessary reviews to determine if it meets Federal A-123 compliance?
In the Comments, please identify any weaknesses and/or deficiencies identified and actions taken to correct each weakness.
Yes
No
II.2.3
Are the SSP’s customer-relevant financial management systems substantially compliant with FFMIA system requirements including USSGL and accounting standards?
In the Comments, please list the all financial systems available for customer use. List any material weakness and include supporting evidence if it is not applicable to the SSP offering.
Yes
No
II.2.4
Have the systems managed by the SSP undergone a financial audit within the past year?
If Yes, In the Comments, please provide information on the audit results (clean or qualified opinion) along with any findings.
Financial Management Line of Business (FMLoB) Federal Shared Service Provider (SSP) Due Diligence Checklist Version 1.0 June, 2009
ATTACHMENT A
SSP Customer Agency List
Customer Agency Number of Users
Other files for this federal contract opportunity
Show all 18
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
File details come from the government source that posted it. Updated .