Skip to content
arcloops
Let's talk →

Guide · Global

AI RFP checklist — procurement evaluation that survives integration

Most AI RFPs copy generic IT language and produce incompatible proposals. This checklist helps procurement and sponsors scope, score, and contract AI engagements with integration, governance, and exit paths built in.

Arcloops Advisory

AI adoption practice · 26 August 2026 · 5 min read

  • Guide

Before you issue an RFP

Do not RFP what you have not scoped. Minimum internal prep: named workflow owner; baseline metric; data classification summary; integration map; build-vs-buy hypothesis—/resources/guides/build-vs-buy-ai; readiness gaps documented—/resources/guides/enterprise-ai-checklist.

Decide engagement type: assessment only, strategy, build, enablement, managed service, or combined. Mixed RFPs without lot structure produce uncomparable bids.

Confirm whether independence matters—strategy vendor separate from licence seller—or whether bundled proposals are acceptable with eyes open.

Arcloops advises procurement teams via /ai-consulting/ai-procurement-advisory before RFP release when spend is material.

Align RFP issue date with stakeholder availability—Dubai and Dhaka holiday calendars differ; Q&A windows need enough working days for security and legal review.

Require bidders to attend a mandatory data briefing where you explain sample format and classification—no surprise samples at demo day alone.

Score independence explicitly when the bidder resells a platform they implement—disclose conflict in evaluation notes even if you still award with mitigations.

Publish intended contract term and renewal caps in the RFP so bidders price honestly—surprise renewal negotiations erode year-one savings.

Name evaluation panel members in the RFP issue note—last-minute panel changes invalidate scores unless documented with rationale.

Allow at least ten business days between RFP issue and demo dates in cross-border procurements—timezone gaps compress Q&A unfairly.

Require bidders to submit integration assumptions as a separate annex—scoring integration without a written annex rewards oral promises only.

RFP scope sections to include

Context and objectives: business problem, success metrics you own, explicit out-of-scope items.

Workflow description: current process, volumes, exception types, systems of record, languages, entity boundaries.

Deliverables: named artefacts (readiness report, integration design, trained cohort, runbook)—not "AI transformation."

Delivery model: onsite vs remote cadence; primary office location; travel assumptions; language requirements.

Technical requirements: SSO, APIs, hosting regions, logging, retention, human override, performance SLAs.

Governance: policy alignment, risk tier, audit samples, model change notification.

Data handling: samples in proof; production data boundaries; subprocessors; DPA requirements.

Enablement: role-based training scope; hypercare duration; champion model.

Commercial: pricing model (fixed, T&M, licence plus services); inference cost ownership; renewal and exit.

Evaluation criteria and weights: published to bidders; include independence and integration proof scores.

Evaluation scorecard dimensions

Weight criteria to your risk profile. Suggested dimensions:

Workflow and integration fit (25–35%): proof on your stack, not sandbox only. Governance and security (20–30%): logging, override, residency answers with evidence. Delivery honesty (10–15%): primary office, onsite plan, team named in proposal. Methodology and artefacts (10–15%): sample redacted deliverables. Commercial clarity (10–15%): TCO assumptions, exit clauses. References (5–10%): similar complexity, not only logo list.

Require live demonstration on provided samples for shortlisted vendors. Disqualify proposals that refuse messy data or cannot name integration owners on their side.

Use /resources/guides/ai-vendor-due-diligence-checklist for finalist diligence after scoring.

Commercial and contract clauses

AI RFPs should request explicit terms:

Data export and format on termination; API access for migration; assistance period post-exit. Model update notification and rollback rights. Inference pricing caps or transparency mechanisms. Liability and indemnity for training data and output use—counsel to tailor. Insurance certificates; subcontractor disclosure. Acceptance criteria tied to checklist gates—not subjective "client satisfaction." IP ownership for custom prompts, workflows, and integration code. Audit rights for logging samples per policy.

Procurement guide companion: /resources/guides/ai-procurement-guide. Avoid auto-renewals on unused licence counts discovered in pilot.

Common RFP mistakes

Copy-paste cloud RFP language with no workflow section. Score price highest while integration is unproven. Let bidders redefine success metrics. Omit language and enablement requirements. Single-stage award without proof period. No lot separation when buying licences and consulting together. Reference checks only with executive sponsors who attended a workshop—not integration leads.

Another mistake: RFP timelines that assume access you cannot grant—security review, sample redaction, and stakeholder calendars need realistic weeks.

Proof-of-concept phase in the RFP

Structure two stages when risk is high:

Stage 1 — short listed response and scored demos on your samples. Stage 2 — paid fixed-scope proof (two to four weeks) with predefined pass/fail gates before master agreement.

Proof charter should include: samples provided; logging review; override test; performance threshold; deliverables; stop option with partial payment terms.

Proof failures should be documented—not hidden to protect incumbent vendor relationships. Failed proofs inform the next RFP revision.

Arcloops participates in proofs and assessments with stop recommendations when evidence does not support scale—/ai-consulting/ai-readiness-assessment.

RFP checklist summary

Pre-RFP: owner, metric, readiness, integration map, engagement type, independence decision.

RFP document: workflow, deliverables, delivery model, technical and governance requirements, data handling, enablement, commercial, evaluation weights.

Evaluation: weighted scorecard, sample-based demo, reference pattern match, diligence on finalists.

Contract: export, model updates, inference costs, acceptance gates, IP, audit.

Post-award: pilot charter uses /resources/guides/enterprise-ai-checklist pre-pilot gates; production uses pre-production section.

Store RFP, scores, and proof results for audit—not only the signed MSA.

Procurement should publish evaluation weights to bidders before Q&A closes. Changing weights after demos destroys comparability and invites challenge from excluded vendors.

RFP governance and vendor Q&A

Publish all bidder questions and anonymised answers to every participant. Silent side deals corrupt scoring. Record demo attendance and sample datasets used so finalists cannot claim they never saw messy data.

Procurement should chair evaluation; business owns workflow scores; security owns governance scores; legal reviews commercial exceptions before award—not after verbal handshake.

For AI consulting RFPs, require bidders to state primary office, subcontractors, and onsite percentage in writing. Disqualify material misrepresentation discovered in diligence—/resources/guides/ai-vendor-due-diligence-checklist.

Arcloops responds to RFPs with explicit hybrid delivery terms and will no-bid when scope requires capabilities or presence we do not offer—buyers should reward that honesty in scoring matrices.

Add a mandatory pricing scenario to every AI RFP: year-one and year-three TCO including inference, integration FTE, and enablement—vendors who refuse scenario detail should score poorly on commercial clarity.

Post-award transition from RFP to pilot charter

Winning bid is not go-live. Within two weeks of award, convert RFP scope into a pilot charter referencing /resources/guides/enterprise-ai-checklist pre-pilot gates. Name client-side integration owner, security reviewer, and workflow owner with calendar holds.

Transfer demo samples and scoring notes to the delivery team—information lost between procurement and implementation causes scope drift. If the vendor proposes staff different from RFP key personnel, trigger contract clause or re-score.

First invoice should tie to pre-pilot gate completion, not kick-off meeting attendance. Milestone acceptance protects buyers when vendors rush to "phase two" before integration proof exists.

Archive the full RFP pack—including Q&A and demo notes—for seven years or per your records policy. Future audits compare what was promised to what was delivered.

FAQ

When policy requires competitive bid, spend exceeds threshold, or independence from incumbent vendors matters. Small assessments may use direct award with shorter checklist.

Separate lots when possible. Bundled bids reduce independence unless evaluation scores methodology and exit from bundled SKU.

Paid fixed-scope proofs improve vendor seriousness and sample commitment. Free proofs often use sanitized vendor data only.

Regulated firms: governance and integration. Speed-focused teams: still weight integration—failed go-live erases speed gains.

Use the scope and evaluation sections as a skeleton. Legal and procurement must adapt to your entity and jurisdiction.

Run AI procurement with clear gates

Arcloops supports buyers drafting RFP scope, evaluation criteria, and proof charters—or responding with honest delivery terms and stop options when fit is poor.