# Agentic AI RFP Requirements and Acceptance Evidence

Version: 1.0  
Reviewed: 2026-08-01  
Owner: ____________________  
Procurement / legal reviewer: ____________________  
Technical reviewer: ____________________  
Security / privacy reviewer: ____________________

> Working procurement template only. Adapt it to the organization, jurisdiction, contract, risk, accessibility, records, security, and legal requirements. It is not legal advice, a certification, or a substitute for qualified review.

## 1. Business process and decision

- Business process, service, or mission outcome:
- Current-state baseline: volume, time, cost, quality, error, rework, delay, risk:
- Intended users and affected parties:
- Decisions or actions the system may recommend:
- Decisions or actions the system may execute:
- Explicitly prohibited uses and actions:
- Non-AI alternatives considered:
- Success measures and minimum acceptance thresholds:
- Scale, conditional scale, remediation, replacement, and stop criteria:

## 2. System boundary and architecture

For every response, require the supplier to distinguish **available now**, **configuration**, **custom implementation**, **third-party dependency**, and **roadmap**.

| Requirement | Supplier response | Acceptance evidence | Buyer owner | Status |
|---|---|---|---|---|
| Current architecture and data-flow diagrams | | | | |
| Agent roles, orchestration topology, state, memory, and handoffs | | | | |
| Models, prompts, tools, APIs, MCP servers, libraries, and services | | | | |
| Environments, tenancy, regions, networks, and trust boundaries | | | | |
| AI Bill of Materials with versions and suppliers | | | | |
| Model / tool substitution and portability design | | | | |

## 3. Identity, authorization, and human authority

| Requirement | Supplier response | Acceptance evidence | Buyer owner | Status |
|---|---|---|---|---|
| Unique agent and workload identity | | | | |
| Task-scoped and short-lived credentials | | | | |
| Least privilege and least-agency enforcement | | | | |
| Delegation chain and approval traceability | | | | |
| Tool allowlists, argument validation, limits, and side-effect controls | | | | |
| Human review, modification, approval, override, appeal, and stop authority | | | | |
| Emergency containment and kill procedure | | | | |

## 4. Data, context, memory, and privacy

| Requirement | Supplier response | Acceptance evidence | Buyer owner | Status |
|---|---|---|---|---|
| Data sources, provenance, quality, and permitted purpose | | | | |
| Provider training and secondary-use restrictions | | | | |
| Retrieval, context selection, and citation design | | | | |
| Memory write validation, isolation, retention, expiry, and rollback | | | | |
| Residency, transfer, encryption, backup, return, and deletion | | | | |
| Secret, regulated-data, and personal-data redaction | | | | |
| Data-subject, records, discovery, and retention support where applicable | | | | |

## 5. Security and supply chain

Require a system-specific threat model and test plan. The OWASP Agentic Top 10 may be used as one taxonomy, not as a complete assurance claim.

| Requirement | Supplier response | Acceptance evidence | Buyer owner | Status |
|---|---|---|---|---|
| Goal hijacking and indirect prompt-injection defenses | | | | |
| Tool misuse and unexpected code-execution controls | | | | |
| Agent identity and privilege-abuse controls | | | | |
| Model, tool, MCP, library, data, and supplier integrity | | | | |
| Memory and context-poisoning controls | | | | |
| Inter-agent message authenticity, integrity, schema, and semantics | | | | |
| Cascading-failure containment and recovery | | | | |
| Human-agent trust and automation-bias testing | | | | |
| Rogue or orphaned agent detection, containment, and retirement | | | | |
| Vulnerability disclosure, notification, remediation, and support | | | | |

## 6. Evaluation and acceptance

- Buyer-owned representative scenario suite:
- Edge, failure, adversarial, misuse, and recovery scenarios:
- Final-output and intermediate-step rubrics:
- Human-review method and reviewer qualifications:
- Baseline and comparison approach:
- Quality, safety, security, cost, latency, and recovery thresholds:
- Statistical treatment, sampling, confidence, known limitations:
- Regression and change-trigger testing:
- Shadow-mode requirements:
- Acceptance-test environment and data:
- Evidence ownership and portability:

## 7. Observability, evidence, and operations

| Requirement | Supplier response | Acceptance evidence | Buyer owner | Status |
|---|---|---|---|---|
| Workflow, agent, model, retrieval, memory, tool, policy, approval, and execution telemetry | | | | |
| Telemetry semantic-convention and instrumentation versions | | | | |
| Content-capture, redaction, access, retention, and sampling policy | | | | |
| Cost attribution by task, system, model, team, and business process | | | | |
| SLOs, error budgets, alert ownership, and escalation | | | | |
| Checkpoint, retry, idempotency, circuit breaker, fallback, and rollback | | | | |
| Incident classification, notification, investigation, correction, and learning | | | | |
| Release, change, suspension, retirement, and evidence-retention process | | | | |

## 8. Standards, policy, and assurance claims

For every claimed alignment, compliance, audit, or certification:

- Name the source, exact version, date, scope, organization, system, and reviewer.
- Provide the mapping and evidence rather than a logo alone.
- State gaps, exclusions, exceptions, and expiration / review date.
- Distinguish self-assessment, consultant mapping, independent audit, accredited certification, legal opinion, and government authorization.

## 9. Commercial model, ownership, and exit

- Fixed and variable price units:
- Model, token, tool, storage, network, telemetry, support, and third-party costs:
- Budget caps, alerts, and approval thresholds:
- Change-order triggers and assumptions:
- Client ownership and licenses for code, configuration, prompts, test sets, data, traces, documentation, and derived artifacts:
- Source and artifact escrow where applicable:
- Export formats and tested portability:
- Transition assistance and replacement-provider cooperation:
- Data return, verified deletion, identity revocation, and agent retirement:
- Termination rights tied to acceptance, safety, security, performance, and cost:

## 10. Decision record

- Decision: Go / Conditional go / Remediate / Rebid / Replace / Stop
- Approved scope:
- Conditions and due dates:
- Accepted residual risks:
- Economic owner:
- Technical owner:
- Security / risk owner:
- Human authority owner:
- Next evidence review:
