A Request for Proposal, or RFP, is the document an organization issues to solicit competing proposals from compliance consulting firms before selecting one and signing a Statement of Work. It sits upstream of the SOW: a well-built RFP's requirements convert almost verbatim into the SOW's scope once a bidder wins. Five questions are settled before any section is drafted: why the work is needed, who the buying organization is, what the project involves, how proposals will be evaluated, and when each deadline falls. Thirteen sections carry those answers from a statement of purpose through points of contact. The section governing whether bids can be compared at all, requirements for proposal preparation, is frequently the least developed. For the bidding firm rather than the issuing organization, the RFP's own structure supplies the outline of the response.
A Request for Proposal is the pre-contract document an organization issues to solicit competing proposals from consulting firms against a described scope of work, evaluated on stated criteria before a Statement of Work is signed with the selected firm. Not every compliance-consulting engagement starts with a formal RFP. A private-sector client who already knows and trusts a firm often skips straight to a proposal, and a smaller engagement can run on a Terms of Reference the consultant drafts after a discovery call; see the guide to consulting terms of reference for that lighter path. But once more than one firm is being asked to bid, or a client's own procurement policy requires a documented, comparable process, common at regulated institutions, sponsor banks, and public-sector or donor-funded work, an RFP is the document that makes the competition fair and the eventual contract defensible.
This article covers both directions. For the organization issuing an RFP to source a compliance consulting firm, a specialist subcontractor, or an audit partner, it sets out the thirteen-section structure. For the consulting firm responding to a client's RFP, it covers the discipline that converts a set of requirements into a proposal aligned section-by-section with the RFP's own outline, and how that response becomes the basis of the SOW the winning bidder signs.
The five framing questions
An RFP drafted section by section without a settled frame produces a document bidders cannot respond to precisely, because the buying organization has not yet determined precisely what it wants. The following five questions are each answered in one sentence before Section 1 is drafted.
| Question | What it answers |
|---|---|
| Why | The reason the organization needs this work now. |
| Who | A brief, honest description of the buying organization: what it does, its relevant scale, and who handles correspondence. |
| What | The nature of the project: the services being sought and the contract's overall objective. |
| How | Contract type, what information bidders must submit, and how proposals will be evaluated and awarded. |
| When | The full timeline: deadlines, a question window, and the award date. |
Where any of the five cannot be answered in a sentence, the RFP is not ready to issue. An imprecise statement of purpose produces correspondingly imprecise responses, and bidders price risk into a proposal when the background section is incomplete or evidently promotional.
Statement of purpose and background
The statement of purpose opens the document: the products or services sought, in a sentence or two, and the contract's overall objective. The background follows in a paragraph or two, covering what the organization does, its relevant statistics or scale, and its weaknesses as well as its strengths. A background section that presents only the opportunity reads as promotional to an experienced bidder, and that gap is priced into the proposal as risk. This section also names the person handling questions and future correspondence, even though the full contact list comes later.
Scope of work
This section states the specific duties expected of the provider and the outcomes expected in return, with explicit detail on whether subcontractor involvement is anticipated or restricted. It becomes the basis of the eventual SOW's specific-requirements section: the more precisely and auditably each duty is stated here, the less renegotiation the winning bidder requires before the scope converts into contract language. A scope statement reading "assist with BSA/AML compliance" admits many interpretations and correspondingly divergent price quotes; "conduct a risk-based independent test of the transaction-monitoring, CDD, and SAR-filing components of the BSA/AML program, per the FFIEC BSA/AML Examination Manual" admits one.
Outcome and performance standards
This section names the target outcomes, the minimum performance standards, and the method by which performance will be monitored once work begins. For an ongoing or managed-service engagement, it establishes the basis of the future service-level framework. A metric stated without a monitoring method attached is not enforceable as a standard.
Deliverables and delivery schedule
This section lists the products, reports, or plans the engagement will produce, with a proposed delivery schedule. Bidders price against the list directly, so format expectations are named here where they bear on cost; a signed PDF report and an editable workbook differ materially in cost for some deliverable types. The section becomes the SOW's deliverables table, and the more precisely it is stated at this stage, the fewer open questions remain when acceptance windows and named approvers are negotiated after award.
Term, payments, and contractual terms
This section states the contract's length, start and end dates, and any renewal options, followed by payment terms, any incentive structure for superior performance, and penalties for non-compliance, in whatever combination applies to the engagement. It closes with a contractual-terms-and-conditions subsection naming the standard contracting forms, certifications, and any engagement-specific requirements bidders must accept or flag as exceptions. None of this needs to restate a master agreement's full indemnification or liability language; that belongs in the contract itself, but bidders need enough here to price the engagement's actual risk.
Requirements for proposal preparation
This section governs whether the bids received can be compared on equal terms, and it is frequently the least developed section of an RFP. It mandates a consistent structure: named sections in a fixed order, page limits where the issuer imposes them, and a precise list of what each proposal must include, covering technical approach, staffing, pricing, and references. An RFP that permits each bidder to format its own response cannot be scored on equal footing, however rigorous the stated evaluation criteria.
Evaluation and award process
This section states the procedures and criteria for evaluating proposals, and names the weighting explicitly where the evaluation is scored, for example technical approach 40%, pricing 30%, past performance 30%. An unscored, unweighted evaluation leaves an unsuccessful bidder without a stated basis for the award decision.
Process schedule and points of contact
This section sets out the full timeline: a letter-of-intent deadline where one applies, the window for bidders to submit questions, any pre-proposal conference, the proposal-submission deadline, and the target award date. It closes with a full contact list giving a named person, title, responsibility, and contact method for every category of question a bidder may raise. Listing a department rather than a named individual reproduces the failure mode a Terms of Reference exhibits when it names a department instead of a contact: correspondence has no assigned recipient.
Responding to an RFP as the bidder
For the consulting firm on the receiving side of the document, the discipline runs in reverse, and it begins before any narrative response is drafted, with a requirements traceability list. Every "shall," "must," and "will provide" statement in the RFP is numbered, with a column recording which section of the proposal answers it. That step addresses a recurring disqualifying failure in RFP response: a mandatory requirement located in the RFP's boilerplate that goes unanswered and is identified only by the evaluation committee.
| RFP asks for | Bidder's response artifact |
|---|---|
| Scope of work | A requirements-mirrored narrative, answering the RFP section by section so an evaluator can trace every requirement to a response paragraph. |
| Proposed personnel / qualifications | A named or role-placeholder staffing table: seniority, certifications, and clearance status if relevant. |
| Past performance / references | Genericized references if any work is under NDA, never fabricated. |
| Pricing | A rate card or fixed-fee breakdown matching the pricing structure the RFP requested, rather than an alternative model the bidder would prefer to quote. |
| Performance standards | Specific, measurable commitments, not "we will strive to meet the client's expectations." |
| Proposal-preparation requirements | Strict compliance with the mandated structure; a non-compliant format is disqualifying before content is even scored. |
Where the procurement runs a best-and-final-offer round, it operates as a formal re-submission rather than an informal price adjustment. The delta from the original bid, covering scope, price, and any deliverable changes, is tracked explicitly, because the eventual SOW's milestone-fee table must reconcile against it. On award, the traceability list built for the response becomes the starting draft of the SOW's specific-requirements section, and the RFP's "shall" statements convert substantially verbatim into the SOW's, with named personnel, dates, and a price attached.
How the RFP fits with the ToR and the SOW
The three documents perform three distinct functions, and the sequence is a recurring source of confusion in compliance-consulting engagements. A Terms of Reference is a lighter, often informal pre-contract scoping document, common when a client has already selected a consultant and is defining scope together rather than running a competitive process; see the guide to consulting terms of reference for that path. An RFP is the formal, competitive version of the same early-stage question, issued when more than one firm is being asked to bid, or when a buying organization's own procurement policy requires a documented process. Both precede a contract. The Statement of Work is what gets signed: the enforceable deliverable, milestone, and payment schedule that a winning proposal, whether it came through an RFP or a simpler path, converts into. For the discipline that governs that conversion, see how to write a compliance consulting Statement of Work, and for what belongs in the SOW versus the umbrella agreement it sits under, see SOW vs. MSA.
A one-page RFP skeleton
The following operates as a drafting checklist for issuing an RFP. A bounded engagement does not require every section at full depth; the discipline is that a section is omitted deliberately rather than overlooked.
- Statement of purpose: services sought, contract objective
- Background: honest overview, strengths and weaknesses, correspondence contact
- Scope of work: duties, expected outcomes, subcontractor disclosure
- Outcome and performance standards: targets, minimums, monitoring method
- Deliverables: products or reports, proposed delivery schedule
- Term of contract: length, dates, renewal options
- Payments, incentives, penalties: terms, incentive structure, penalties
- Contractual terms and conditions: forms, certifications, exceptions process
- Requirements for proposal preparation: mandated structure, page limits, required contents
- Evaluation and award process: criteria and weighting, stated explicitly
- Process schedule: question window, submission deadline, award date
- Points of contact: named individual, title, method, per question category
Where compliance-consulting RFPs go wrong
- No mandated proposal structure. Bids arrive in incompatible formats and can't be scored on equal footing.
- Background as marketing. The section sells the opportunity instead of describing it honestly, and bidders price the gap as risk.
- No stated weighting. Evaluation criteria exist but aren't weighted, so a disappointed bidder has grounds to ask what "best" actually meant.
- Duties without outcomes. Scope lists activities but never states what success looks like, so a technically compliant proposal can miss the point of the engagement.
- Departments instead of contacts. Questions go unanswered, or get answered inconsistently by different people.
- Requirements that never reach the SOW. The winning bidder's contract gets renegotiated from scratch instead of converted from what was already agreed.
Primary sources
- Federal Acquisition Regulation (FAR), Subpart 15.2: Solicitation and Receipt of Proposals and Information, the public U.S. federal source governing RFP content, evaluation-criteria disclosure, and the competitive-range process behind this guide's evaluation and award-process sections.
- U.S. Department of Homeland Security, Science and Technology Directorate: Information Assurance Compliance Support Services Statement of Work (RFQ 70RSAT22Q00000040, Attachment I, 2022), a public federal-procurement record of what a compliance-adjacent RFP process produces once a Statement of Work is issued downstream.
- Commonwealth of Virginia, Virginia Information Technologies Agency (VITA): Procurement policies, procedures, and tools, a public state procurement resource covering RFP structure and evaluation practice for services contracts.
- ISO 20700:2017: Guidelines for management consultancy services, the international standard covering the specification stage of a consulting engagement, the same stage an RFP formalizes when more than one firm is competing.
- NIGP: The Institute for Public Procurement: a professional standards body for public-sector procurement, publishing widely used guidance on RFP structure, evaluation criteria, and vendor-response comparability.