Compliance requirements
The exclusion grounds include at least participation in a criminal organisation, corruption and fraud. The bidder must confirm whether it or members of its management, representation or supervisory bodies have been finally convicted of such offences within the last five years, or whether an exclusion period is still in force. If an exclusion ground applies, the bidder may submit evidence of self-cleaning measures where this is permitted. The machine-readable notice did not include precise other exclusion grounds; these must be checked in the tender documents.
Qualification criteria and exclusion grounds
The lead auditor must hold at least one valid certificate during the audit: CISA (ISACA), an ISO 27001 lead auditor certificate issued by IRCA, or an ISO 27001 lead auditor certificate issued by PECB. The bidder must have a valid information security certificate, such as an E-ITS conclusion decision or an ISO certificate. The independence of audit team members must be confirmed by a signed declaration. The bidder must submit CVs for the lead auditor, the auditors included in the audit team and the technical experts, and they must meet the requirements set out in the tender document ‘Requirements for the team’. If the bid is a joint bid, a power of attorney for the joint bidders must be submitted. The bidder must also submit the indicative audit cost in the required Excel table and complete the fields and confirmations required by the tender documents. The machine-readable notice did not include precise other qualification or compliance requirements; these must be checked in the tender documents.