This tender invites proposals for the supply, support, and maintenance of an audit management system to streamline internal audit processes, compliance, and risk management at airports company south africa (acsa). The contract spans a maximum of 60 months and is open to bidders who can demonstrate oem accreditation and meet strict technical, financial, and compliance requirements.
Key Requirements
Submit bids by hand delivery to Tender Box C at ACSA, OR Tambo International Airport, by 12:00 on 10 July 2026. Late submissions are disqualified.
Mandatory requirements: OEM accreditation/certification, completed Annexure D (Self Scoring), Annexure E (Business Requirements), Pricing Schedule, and attendance at the compulsory briefing session on 12 June 2026.
Achieve a minimum of 80/100 points in the functionality evaluation (Bidders Experience: 30, Business Requirements: 50, Solution Delivery Timelines: 20).
Provide valid Tax Compliance Status (TCS) PIN or Central Supplier Database (CSD) number, B-BBEE certificate (SANAS-accredited), and other mandatory documents (e.g., Declaration of Interest, SBD forms).
Prices must remain valid for 120 business days post-submission.
Preference points (20 max) awarded for B-BBEE status, black youth/women ownership, or disability ownership—proof required.
Strict adherence to ACSA’s terms, including security vetting and confidentiality agreements.
Request for proposal for the supply, support and maintenance of the audit management system for a maximum period of 60 months at airports company south africa.
Briefing SessionCompulsory
Date & Time
Friday, 10 July 2026 - 12:00
Venue
Microsoft Teams
Important: Attendance at this briefing session is mandatory. Bids from suppliers who do not attend may be disqualified.
Review in progress · 1 of 9 document being finalised
AI Document Analysis Stages
Document read. The full tender notice and its supporting documents are read end-to-end. Key sections, requirements, dates, and contact details are identified and pulled into a working summary you can act on.
Compliance review. The working summary is checked against South African procurement standards — PFMA, PPPFA, B-BBEE, CIDB, local content, and preferential procurement — so nothing critical is missed before you start your bid response.
Review in progress
The information shown on this card is preliminary. Our procurement team is currently finalising the submission guidelines, evaluation criteria, technical specifications, financial requirements, and compliance sections so you have a clean, bid-ready summary to work from. Document being finalised: Annexure C Pricing Schedule.docx. You don’t need to refresh — this page will pick up the updated review automatically.
DocumentService Management and Maintenance.pdfReview complete
Important Dates
03 Jun
2026
PUBLICATION
Tender Published
Tender was published
10 Jul
2026
DEADLINE
Closing Date
Tender closing date
Procurement Rules & Compliance ContextThis tender may be governed by South African public procurement rules covering fairness, transparency, preferential procurement, anti-corruption, administrative justice and access to information.
7 rules
These references help suppliers understand the public-procurement framework around this opportunity. They are generated from the tender category, issuing organisation type and procurement context.
Core procurement rules
These rules commonly apply to South African public-sector procurement.
7
Broad-Based Black Economic Empowerment Act (B-BBEE Act)
Act 53 of 2003
high
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Constitution of the Republic of South Africa, 1996 – Section 217
Act 108 of 1996 (s217)
high
This is general procurement context, not legal advice. Always verify requirements in the official tender documents and issuing authority notices.
The tender is a Request for Proposal (RFP) issued by Airports Company South Africa (ACSA) for the supply, support, and maintenance of an Audit Management System over a maximum period of 60 months. The document, titled 'Annexure A – IT Standards,' outlines detailed technical and operational standards that potential service providers must adhere to, including IT infrastructure, security, connectivity, resilience, and maintenance requirements. The solution must integrate with ACSA's existing hybrid Active Directory, comply with specified hardware/software standards (e.g., Dell VXRail, VMware, Cisco networking), and ensure high availability, redundancy, and security. All proposals must align with ACSA’s IT architecture and obtain prior approval for deviations.
Airports Company South Africa seeks a supplier for an Audit Management System including implementation, support, and maintenance for up to 60 months. Evaluation is based on experience (30%), business requirements (50%), and delivery timelines (20%), with a mandatory demo for shortlisted bidders.
The Airports Company South Africa (ACSA) invites bids for the supply, support, and maintenance of an Audit Management System for a maximum period of 60 months. The system aims to streamline internal audit processes, including planning, risk assessment, execution, reporting, compliance management, and analytics. The tender follows a structured evaluation process with mandatory requirements, functionality/technical assessment, and price/preference evaluation under the Preferential Procurement Policy Framework Act, 2000.
The Airports Company South Africa (ACSA) is seeking proposals for the supply, support, and maintenance of an Audit Management System (AMS) for a maximum period of 60 months. The system must support internal audit functions, including audit planning, scheduling, execution, reporting, compliance management, and risk assessment, while adhering to IIA standards. The solution must be scalable, secure, and integrate seamlessly with ACSA’s existing IT infrastructure, with 24/7/365 availability and robust disaster recovery capabilities. The project includes implementation, data migration, training, and post-go-live support.
The tender is a Request for Proposal (RFP) issued by Airports Company South Africa (ACSA) for the supply, support, and maintenance of an Audit Management System over a maximum period of 60 months. The document includes detailed web application security procedures, outlining strict security standards for authentication, session management, access control, cryptography, error handling, data protection, and more. The RFP emphasizes compliance with these security protocols to ensure the safe and secure operation of the Audit Management System.
The tender is a Request for Proposal (RFP) from Airports Company South Africa (ACSA) for the supply, support, and maintenance of an Audit Management System over a maximum period of 60 months. The scope includes service management, preventative/corrective maintenance, roles/responsibilities (RASCI model), service credits, reporting, and compliance with ACSA's operational and security standards across key airports (OR Tambo, Cape Town, King Shaka). The contract requires 24/7 support, onsite/offsite resources, spares management, and adherence to strict SLAs, including after-hours and weekend coverage.
Annexure D - Audit Management Response Sheet (Self Scoring).xlsx
The tender is a Request for Proposal (RFP) issued by Airports Company South Africa for the supply, support, and maintenance of an Audit Management System over a maximum period of 60 months. The system must cover functionalities such as Risk Identification & Assessment, Audit Planning, Audit Execution, Reporting & Finalization, Stakeholder Relations Management, Tenant Relationship Management, Traffic Development Unit, Training Academy, and Data Migration. Bidders are required to self-score their proposals based on predefined criteria, with points allocated for functionality availability or development feasibility.
The tender is a Request for Proposal (RFP) issued by Airports Company South Africa for the supply, support, and maintenance of an Audit Management System over a maximum period of 60 months (5 years). The proposal requires detailed pricing schedules for both Capital Expenditure (CAPEX) and Operational Expenditure (OPEX), including costs for analysis, development, testing, hosting, training, documentation, and project management. The total cost of ownership must be provided, including VAT.
Annexure E - Business Requirements compliance response document.docx
The Airports Company of South Africa (ACSA) is seeking proposals for the supply, support, and maintenance of an Audit Management System (AMS) for a maximum period of 60 months. The system must support end-to-end audit lifecycle management, including risk identification, assessment, prioritization, audit planning, execution, reporting, and follow-up. Key functionalities include risk registers, heat maps, audit checklists, real-time collaboration, mobile access, reporting templates, and secure document storage. All requirements are categorized by priority (P1/P2/P3), with most marked as P1 (high priority).
Win ACSA tenders with AI Matching Engine, airport-infrastructure intelligence, compliance analysis, and application support for aviation operations.
Similar Tenders
Matched by category & region
Supplier Readiness Hub
Free guidance to prepare before you bid
Not sure if your business is ready for this tender? Check CSD, CIDB, and B-BBEE requirements, run a readiness assessment, and move from opportunity to submission.
Bid-ready summary. The submission guidelines, evaluation criteria, technical, financial, and compliance sections are refined into professional, easy-to-scan prose. This is the final version you can rely on when preparing your bid or briefing your team.
We refine every tender document through these stages so you can brief your team and prepare your bid with confidence. Anything marked as "in progress" will be upgraded automatically — no action required from you.
Document read
Compliance review
Bid-ready summary
Description
Source: Service Management and Maintenance.pdf
The tender is for the supply, support, and maintenance of an Audit Management System for Airports Company South Africa (ACSA) over a maximum period of 60 months. The scope includes preventative, corrective, and break/fix maintenance, as well as service management and infrastructure support to meet defined SLAs.
Evaluation Criteria
Source: Service Management and Maintenance.pdf (unknown)
Mandatory criteria:
Certified and experienced personnel (e.g., Senior Engineers, ITIL/PMBOK certified).
Proven track record in supplying/maintaining Audit Management Systems or similar IT infrastructure for large enterprises/airports.
Ability to meet 24/7 support and after-hours SLA requirements.
Financial and operational capacity to establish spares warehouses and manage loan stock.
Compliance with South African labor laws, security vetting, and ACSA’s access control policies.
Valid insurance coverage for equipment and liabilities.
Preferred criteria:
Experience working with airport or aviation industry IT systems.
Familiarity with ACSA’s existing infrastructure (e.g., self-service systems, network connectivity).
Existing partnerships with OEMs for hardware/software support.
Local presence in Gauteng (or ability to deploy resources quickly).
Evaluation focus:
Compliance with ACSA’s security and IT architecture policies for new equipment implementation.
Ability to meet cost, performance, and quality objectives for infrastructure and system functionality.
Demonstration of risk mitigation and quality improvement to support business advantage.
Technical Specifications
Source: Service Management and Maintenance.pdf (unknown)
Scope: Supply, support, and maintenance of an Audit Management System for a maximum period of 60 months at Airports Company South Africa (ACSA).
Key technical requirements:
Preventative Maintenance: Includes planned overhauls, replacements, inspections, tests, software/firmware upgrades, patch management, and activities to prevent failures.
Corrective Maintenance: Activities following preventative maintenance inspections to restore infrastructure functionality.
Break/Fix Maintenance: Unforeseen maintenance to restore serviceability, including after-hours, weekends, and public holidays. No additional costs will be entertained.
Service Coverage Windows:
Standard: 06:00–18:00, Monday–Friday (excluding public holidays).
Weekday After Hours: 18:00–06:00, Monday–Friday (excluding public holidays).
Weekends/Public Holidays: 24 hours.
Project & IMACD: Generally 23:30–05:00 (varies by airport).
On-Site Support Hours:
OR Tambo International: 24 hours.
Cape Town International: 04:00–01:00.
King Shaka International: 05:00–22:00.
Minimum Resource Requirements per Airport:
Senior Engineer (JNB, DUR, CPT): Provides 3rd-level support for complex issues (network, connectivity, hardware, software). Coverage: 24x7 for JNB; 2 hours prior and after airport operational hours for DUR and CPT.
Engineers (JNB, DUR, CPT): Provide 1st and 2nd line technical support, IMACD tasks, floor dispatch, and monitoring. Coverage: 24x7 for JNB; +2/-2 hours for CPT and DUR.
Preventative Maintenance Tasks: Must include inspections, syslog analysis, health checks, configuration backups, log analysis, device performance monitoring, software upgrades, capacity management, user management, redundancy testing, firmware upgrades, and risk identification.
Equipment and Spares: Provider must ensure technicians have appropriate toolkits, critical spares are available, and a warehouse is established within 60 days of award to store parts for SLA compliance.
Replacement Parts: Must use original or higher-grade manufacturer-certified parts.
Service Level Agreements (SLAs): Provider must meet defined SLAs for response, resolution, and availability. Detailed preventative and corrective maintenance plans must be submitted as part of the proposal.
Roles and Responsibilities: Defined using the RASCI model (Responsible, Accountable, Supporting, Consulted, Informed). Provider must align with ACSA’s standards for service management, monitoring, and reporting.
Methodology
Source: Service Management and Maintenance.pdf
Methodology and resourcing:
Provider must adapt their resourcing model to meet the Service Level Agreement (SLA), including permanent onsite and/or variable offsite resources for preventative and corrective maintenance.
Dedicated onsite resources must be proposed by the provider to meet stipulated SLAs.
All resources must sign ACSA’s Non-Disclosure Agreement (NDA). Security vetting and background checks are mandatory for access permits.
Provider must follow internationally recognized project management practices (e.g., PMBOK or PRINCE2).
Provider must periodically review and update Technology Refresh and Replenishment (TR&R) plans to support ACSA business requirements.
Provider must manage all infrastructure changes (standard, low, medium, high risk) within airport operations and projects, including initiating and closing change requests.
Quality Management
Source: Service Management and Maintenance.pdf
Quality and maintenance requirements:
Preventative Maintenance: Planned overhauls, replacements, inspections, tests, software/firmware upgrades, patch management, and activities to prevent failures.
Corrective Maintenance: Activities following preventative inspections to restore infrastructure functionality.
Break/Fix Maintenance: Unforeseen maintenance to restore serviceability, including after-hours, weekends, and public holidays. No additional costs will be accepted.
Provider must respond to all faults and provide after-hours telephone numbers for support personnel. Changes to contact numbers must be communicated to ACSA.
Preventative Maintenance Schedule: Must include inspections, syslog analysis, health checks, configuration backups, log analysis, device performance monitoring, software upgrades, capacity management, user management, redundancy testing, firmware upgrades, and risk identification for the Self-Service infrastructure.
Pricing Schedule
Source: Service Management and Maintenance.pdf
Pricing and cost responsibilities:
Provider is liable for office rental space for onsite resources at ACSA premises. Rates must be agreed with ACSA Property Department.
Provider is responsible for all costs associated with onsite or contract-related work, including parking fees and security/access permit training.
Financial Requirements
Source: Service Management and Maintenance.pdf (unknown)
Cost responsibilities for the bidder:
Provider is liable for office rental space for onsite resources at ACSA premises. Rates must be agreed with ACSA Property Department.
Provider is liable for parking fees for onsite or contract-related work at ACSA premises.
Provider is liable for fees and training for ACSA Security and Access Permits for onsite resources.
No additional costs will be entertained for after-hours, weekend, or public holiday support.
Provider must establish a warehouse within 60 days of award to store parts for SLA compliance.
Provider must cover costs for backup/loan stock to restore service within SLA timeframes.
Compliance Requirements
Source: Service Management and Maintenance.pdf (unknown)
Compliance and operational requirements:
All resources must sign ACSA’s Non-Disclosure Agreement (NDA). Security vetting and background checks are mandatory for access permits.
Provider must complete a safety file in accordance with ACSA standards within the first month of service commencement. The file must be kept up to date.
Provider must ensure proactive monitoring to limit infrastructure outages and comply with ACSA’s security, change management, and oversight policies.
Provider must manage subcontractors and third parties to meet SLAs and service requirements.
Provider must adhere to ACSA’s IT Service Management (ITSM) best practices and Key Performance Indicators (KPIs).
Availability Management: Provider must establish criteria and Service Level Requirements (SLRs) for availability, develop policies and procedures, and ensure ongoing measurement and reporting.
Capacity Management: Provider must monitor performance, forecast future demands, develop capacity plans, and conduct risk assessments to meet SLRs.
Provider must ensure all service technicians are equipped with appropriate toolkits and testing equipment.
Provider must maintain adequate inventory levels of critical spares and backup/loan stock to meet SLAs.
Health & Safety
Source: Service Management and Maintenance.pdf
Health and safety requirements:
Provider must ensure a resourcing model is in place to achieve SLAs and deliver service during defined coverage windows.
Provider must maintain a full complement of resources and replace absent personnel with equally qualified staff (including required access permits, training, and site knowledge).
Provider must dedicate resources solely to service management and maintenance activities for the passenger self-service program.
Provider must complete a safety file in accordance with ACSA standards within the first month of service commencement. The file must be kept up to date at all times.
Contractual Terms
Source: Service Management and Maintenance.pdf
Contractual obligations for the provider:
Provider must ensure technicians are equipped with appropriate toolkits and testing equipment.
Provider must maintain adequate critical spares to meet SLAs at all locations.
Provider must honor SLAs and maintain backup/loan stock to restore service within specified timeframes.
Replacement parts must be original or higher-grade manufacturer-certified components.
Provider must establish a warehouse within 60 days of award to store parts for SLA compliance.
Provider must manage parts and maintenance during warranty and off-warranty periods according to manufacturer’s mean-time-between-failure rates.
Provider must conduct maintenance and parts management in coordination with third-party vendors where applicable.
DocumentIT Standards.pdfReview complete
Description
Source: IT Standards.pdf
The tender is for the supply, support, and maintenance of an Audit Management System for Airports Company South Africa (ACSA) over a maximum period of 60 months. Key requirements:
Integration with ACSA’s existing IT infrastructure, including Microsoft Active Directory (hybrid) for authentication.
Compliance with ACSA’s IT standards for servers, storage, networking, and security.
Adherence to ACSA’s resilience, maintenance, and data-sharing requirements.
All designs and configurations must be approved by ACSA prior to implementation.
Evaluation Criteria
Source: IT Standards.pdf (unknown)
Evaluation will focus on two key areas:
General:
Demonstrable experience in supplying, supporting, and maintaining enterprise-grade Audit Management Systems.
Compliance with ACSA’s IT standards and proven ability to integrate with existing infrastructure (e.g., Active Directory, VMware, Cisco).
Capacity to provide 24x7 support, OEM warranties, and maintenance for a minimum of 5 years.
Financial and technical capability to meet the scope, including scalability for ACSA’s multi-site environment (ORTIA, CTIA, KSIA, etc.).
Adherence to South African regulatory and security requirements.
Technical:
Proven expertise in virtualized environments (VMware ESXi), HCI (Dell VXRail), and SAN/storage solutions (Dell EMC Unity).
Experience with Cisco networking (LAN/WAN), wireless (Cisco Unified Wireless), and firewall (Check Point/Cisco) technologies.
Ability to deploy solutions meeting ACSA’s resilience, redundancy, and security standards (e.g., dual fabrics, multi-path connectivity, encryption).
Familiarity with ACSA’s data center and physical infrastructure standards (TIA-942, Uptime Institute).
Technical Specifications
Source: IT Standards.pdf (unknown)
Scope: Supply, support, and maintenance of an Audit Management System for ACSA for a maximum of 60 months.
System Requirements:
Must integrate with ACSA's Microsoft Active Directory (hybrid: on-premise + Microsoft EntraID) for authentication. Single identity per user required.
Must support Site-to-Site or Point-to-Site VPN connectivity:
Point-to-Site: Checkpoint Mobile client (laptops), Checkpoint Capsule (mobile devices), Version 88.10.
Site-to-Site: IKEv2, AES-256 (or higher) encryption, SHA255 (or higher) data integrity, DHG Group 14 (or higher).
Must adhere to ACSA’s IT security standards: ACSA IT personnel must receive master system passwords and login details. ACSA IT administrators must have access to operating systems and servers (not the system itself).
Must comply with ACSA’s existing IT standards and architecture. Deviations require approval during the RFP clarification phase.
Resilience must be built-in to meet SLA/availability requirements per the Scope of Work.
Maintenance plans must be included for new IT systems/software/infrastructure. Existing systems are covered by current contractors; new expansions must engage these contractors for handover. Maintenance costs must be included in the bid unless otherwise specified.
Data sharing must use industry-standard formats (e.g., JPEG, PNG, TIFF, BMP for images; MS Word, PDF for documents; Microsoft Excel for spreadsheets; MP4, AVI for video; MP3, FLAC for audio).
Infrastructure Standards:
Virtualization: VMware v8 (preferred). Hyperconverged (HCI) platforms with Dell VXRail hardware are standard. Multiple VXRail nodes required for N+1 redundancy.
Servers: Dell PowerEdge (R660/R670 for dual CPU, R860/R960 for quad CPU). All hardware must have a minimum 5-year extended OEM warranty and 24x7x4 Dell ProSupport Plus.
Operating Systems: Backend (servers) - Red Hat RHEL 8.10+, Ubuntu 22.x LTS+, Windows Server 2022 64-bit+. Frontend (end-user) - Windows 11 Latest Current Branch.
Messaging: Microsoft Exchange Online/Hybrid Architecture.
Storage: DELL/EMC SAN (Unity range) or vSAN for virtual servers. External storage may be required in certain cases.
Backup & Replication: DELL/EMC Avamar with DataDomain appliances. Replication via VMware Replication or DELL/EMC RecoverPoint.
Network: Cisco Systems (core routers, data centre switches, LAN access switches, wireless controllers, access points). Industrial Ethernet switches: Cisco or Rockwell Stratix.
Firewall: Checkpoint 6600/5400/7000 Security Gateway Appliances (perimeter), Cisco ASA 5545X HA (ORTIA Data Centre). Firewall management: Checkpoint Smart-1 600 M. Required functionalities: Mobile Access Blade, User Directory Blade, Endpoint Security, IPv6, Anti-bot, Identity Awareness, IPS, URL Filtering, Application Control, Site-to-Site VPN.
Cabling: Cat7 SFTP for copper, OS2 Orange Sleeve for single-mode fibre, OM4 Purple/Aqua Blue for multimode fibre. Adhere to TIA/EIA568-B standards. Warning labels required every 15m for indoor/outdoor fibre.
Physical Infrastructure:
IT facilities categorized into 3 types: Wire Centre (low heat), Core Centre (high heat), Data Centre (high heat).
Availability ratings: Data Centre (99.999%), Core Centre (99.98%), Wire Centre (99.67%).
Cabling schema: Campus distributor, building distributor, floor distributor, horizontal cable, consolidation points, etc. Consolidation points must be passive and accessible (not public).
Design & Approval:
All designs and Bills of Materials must be approved by ACSA prior to ordering equipment/software.
Network device configurations will be supplied by ACSA IT. No independent configuration by service providers.
Network Design:
Preferred topology for large campuses (ORTIA, CTIA, KSIA): Three-tier hierarchical model (Core, Distribution, Access layers).
Preferred topology for small campuses (PLZ, ELS, GRJ, BFN, KIM, UTN): Two-tier/Collapsed Core model (Collapsed/Core layer + Access layer).
Collapsed Core: Distribution and Core layer functions implemented by a single device to reduce costs while retaining hierarchical benefits.
Redundancy: High availability built into design using HSRP, Port Channels, Switch Stacking, Power Stacking, Redundant Power Supplies, and Dual Fibre Uplinks.
Methodology
Source: IT Standards.pdf
Network design must follow ACSA’s standards:
Large campuses (ORTIA, CTIA, KSIA): Three-tier hierarchical model (Core, Distribution, Access layers).
Small campuses (PLZ, ELS, GRJ, BFN, KIM, UTN): Two-tier/Collapsed Core model (Collapsed/Core layer + Access layer).
Collapsed Core: Single device implements both Distribution and Core layer functions to reduce costs while retaining hierarchical benefits.
Redundancy: High availability must be built into the design using HSRP, Port Channels, Switch Stacking, Power Stacking, Redundant Power Supplies, and Dual Fibre Uplinks.
Financial Requirements
Source: IT Standards.pdf (unknown)
Pricing must include:
Cost of all software licenses (operating systems, database systems, productivity software like Microsoft Office). ACSA will advise post-award on procurement methods (some enterprise agreements may apply).
Maintenance and warranty costs for new hardware/software, including handover to existing ACSA maintenance contractors where applicable.
Extended OEM warranties (minimum 5 years) and support services (e.g., 24x7x4 Dell ProSupport Plus, 4-Hour Mission Critical On-site Response for storage/network devices).
DocumentAnnexure A - Audit Management System SOW.pdfReview complete
Description
Source: Annexure A - Audit Management System SOW.pdf
General scope:
ACSA invites proposals for the implementation, support, and maintenance of an Audit Management System (AMS) to support Internal Audit functions.
The system will aid in audit planning, scheduling, documenting findings, and initiating investigations.
It will manage compliance, facilitate walkthroughs, perform data analysis, identify weaknesses, inefficiencies, and non-compliance issues, and enable corrective actions.
The system must comply with the latest global IIA standards.
Project milestones include:
Software license procurement, installation of the new solution, hardware & software.
Configuration and customization of the new solution to suit ACSA environment.
Data migration.
Integration.
Solution Testing.
User Training.
Deploying solution to production environment.
System’s post go-live support.
Handing over the solution to Operations.
Evaluation Criteria
Source: Annexure A - Audit Management System SOW.pdf (unknown)
General criteria:
Bidders must be legally registered entities capable of entering into a contract with ACSA.
Experience in implementing and supporting Audit Management Systems (AMS) or similar solutions for large organizations, preferably in aviation or public sector.
Demonstrated ability to comply with international audit standards (IIA).
Financial stability and capacity to deliver the project within the 60-month timeframe.
Compliance with South African legal and regulatory requirements (e.g., B-BBEE certification may be advantageous).
Technical criteria:
Proven expertise in system integration, data migration, and customization.
Ability to provide 24/7/365 support and meet SLAs (e.g., 99.9% uptime, RTO/RPO targets).
Experience with secure hosting solutions (on-prem or cloud) and disaster recovery planning.
Familiarity with ACSA’s IT infrastructure or willingness to align with ACSA’s standards (e.g., SSO, encryption).
Capability to provide comprehensive training and change management support.
Project management criteria:
Certified project managers (e.g., PMP, PRINCE2) with experience in large-scale IT deployments.
Ability to adhere to ACSA’s project governance frameworks and reporting requirements.
Track record of delivering projects on time, within budget, and with minimal disruption.
Additional system criteria:
The system must comply with ISO/IEC 27001 for information security management.
The system must be able to operate under partial system failures without losing overall functionality.
Technical Specifications
Source: Annexure A - Audit Management System SOW.pdf (unknown)
Purpose and objectives:
ACSA seeks an Audit Management System (AMS) to support Internal Audit functions, complying with the latest global IIA standards.
The system must aid in audit planning, scheduling, documenting findings, and initiating investigations.
It must manage compliance, facilitate walkthroughs, perform data analysis, identify weaknesses, inefficiencies, and non-compliance issues, and enable corrective actions.
Scope of work:
Software license procurement, installation, hardware, and software setup.
Configuration and customization to suit ACSA’s environment.
Ensure security aligns with business requirements.
Meet legal/conformance requirements, including privacy.
Deliver adequate performance/responsiveness.
Scale for 5 years without redevelopment.
Ensure reliability and recoverability.
Validate input data and maintain data integrity.
Provide APIs conforming to ACSA’s industry standards (e.g., REST, SOAP).
Avoid hard-coding; externalize variables to databases/parameter files.
Trap and report errors meaningfully.
Design intuitive, standards-based user interfaces to reduce training needs.
Referenced standards:
The system must adhere to ACSA’s prescribed IT Standards (refer to Annexure A).
The system must meet ACSA’s Service Level Agreement Standards for Service Management, Preventative, and Corrective Maintenance (refer to Annexure B).
The system must comply with ACSA’s Web Application Security Standards for information security (refer to Information Security: Web Application Security Standards document).
Methodology
Source: Annexure A - Audit Management System SOW.pdf
Project management requirements:
Utilize project management methodologies consistent with leading internationally recognized practices (e.g., PMBOK or PRINCE2).
Perform project management review and oversight, attend scheduled meetings, ensure key milestones are achieved.
Define the project team responsible for executing tasks and producing deliverables.
Plan resources, allocate and schedule work based on team capacity.
Baseline the project schedule within the first four weeks of project kick-off; any changes require project board approval.
Track project activities to avoid delays, ensure project management activities are carried out, and provide updated communication to stakeholders.
Report on project progress, budget, risk, and issues; escalate issues as required.
Manage total projected costs.
Ensure all assets are tagged and documented prior to installation.
Conduct stakeholder identification, analysis, and management.
Enforce project governance to ensure adherence to procedures and policies.
Draft project charter for sign-off, complete all required project artifacts, and save all documentation in ACSA’s central repository.
Minute all meetings within 48 hours and list actions in the RAID log.
Include end-to-end asset management requirements aligned to ACSA policy.
Provide weekly project reports and monthly Steerco reports in ACSA format.
Ensure all close-out activities are completed for proper handover to operations.
Training requirements:
Ensure all relevant stakeholders (internal staff, end-users, administrators) are proficient in using the system.
Equip users with skills to utilize full functionality, perform tasks efficiently, and minimize errors or security breaches.
Enable administrators to manage configurations, user access, and ongoing maintenance.
Provide end-user training (basic navigation, task execution, troubleshooting), system administrator training (setup, user management, integrations, backup/recovery), and super user training (advanced features, customization, troubleshooting).
Deliver training materials (documentation, guides, manuals with step-by-step instructions and screenshots).
Conduct online and in-person training sessions, ensure effective knowledge transfer, and offer hands-on sessions.
Provide post-training support through Q&A sessions, refresher courses, or a dedicated helpdesk.
Schedule training in phases (administrators and super users first, then end-users) with minimal disruption.
Conduct post-training assessments, gather feedback, and provide certificates of completion.
Offer refresher training periodically and ongoing support through helpdesk services.
Change management requirements:
Identify and analyze key stakeholders (auditors, compliance officers, IT support, managers, end-users).
Develop clear messaging explaining the change, benefits, and impact; use multiple communication channels (emails, meetings, intranet).
Engage stakeholders early through feedback, focus groups, or pilot testing.
Assess impact on user roles, workflows, and responsibilities; identify and address potential resistance.
Provide tailored training sessions and materials (manuals, guides, tutorials) for different user groups.
Offer ongoing support via helpdesk, user forums, and peer-to-peer support.
Involve end-users in design, implementation, and User Acceptance Testing (UAT).
Set up feedback channels (surveys, suggestion boxes, focus groups).
Implement a phased rollout (e.g., pilot department), appoint super-users/champions, and monitor adoption rates.
Address concerns proactively, incentivize adoption, and offer personal support/coaching.
Evaluate change impact post-implementation, document lessons learned, and maintain a continuous feedback loop.
Reinforce adoption by emphasizing benefits, sharing success stories, providing refresher training, and celebrating success.
Environmental
Source: Annexure A - Audit Management System SOW.pdf
Environmental requirements:
Design and operation must minimize environmental impact and promote energy efficiency.
Use environmentally friendly materials wherever possible.
System components must be robust enough to withstand the physical conditions of the airport environment, including variations in temperature, humidity, and handling.
Section
Source: Annexure A - Audit Management System SOW.pdf (unknown)
Functional Requirements The following are functional requirements that need to be delivered by the system. The Audit Management System (AMS) is expected to help streamline the audit process, improve efficiency, and ensure better compliance and reporting. Below are the internal audit requirements that shall be delivered by the system. BR # Requirement Description Available Not available, Priority but can be developed P1/P2/P3 BR 2.1 Risk Identification, Assessment & Prioritization BR 2.1.1 Risk Identification & Assessment BR 2.1.1.1 The system shall enable the user or auditor to define risk categories, criteria, and thresholds. P1 BR 2.1.1.2 The system shall be capable of collecting historical, current, and external data relevant to a risk. P1 BR 2.1.1.3 The system shall include templates, checklists, and collaboration features to assist in identifying potential risks. P1 BR 2.1.1.4 The system shall enable the user to assign likelihood, impact, and exposure scores to each risk and calculate a total risk score. P1 BR 2.1.1.5 The system shall be able to utilize risk matrices or heat maps to prioritize high-risk areas for attention. P1 BR 2.1.1.6 The system shall enable the user to assign mitigation actions, responsible parties, and timelines. P1 BR 2.1.1.7 The system shall enable the user to continuously track and reassess risks, adjusting mitigation strategies as needed. P1 BR 2.1.1.8 The system shall maintain a risk register and generate risk reports for stakeholders. P1 BR 2.1.2 Risk Prioritization BR 2.1.2.1 The system shall enable the user to define P1 risk assessment criteria for likelihood, impact, and risk appetite. BR 2.1.2.2 The system shall enable the user to identify P1 and list all risks in a centralized Risk Register. BR 2.1.2.3 The system shall enable the user to evaluate each risk’s likelihood and impact using predefined scoring systems. P1 BR 2.1.2.4 The system shall generate a risk heat map or risk matrix to visually prioritize risks based on their likelihood and impact. P1 BR 2.1.2.5 The system shall enable the user to rank risks by risk exposure to identify high, medium, and low-priority risks. P1 BR 2.1.2.6 The system shall incorporate organizational risk appetite to flag risks that exceed acceptable thresholds P1 BR 2.1.2.7 The system shall enable the user to assign owners and mitigate actions for high-priority risks, ensuring accountability. P1 BR 2.1.2.8 The system shall enable the user to regularly review and adjust priorities as the risk landscape evolves. P1 BR 2.2 Audit Planning BR 2.2.1 Defining audit objectives BR 2.2.1.1 The system shall enable the user to set objectives, goals, outcomes and boundaries for the audit. P1 BR 2.2.1.2 The system shall enable the user to track the objectives and scope throughout the audit lifecycle. P1 BR 2.2.1.3 The system shall enable the user to link the objectives to specific audit tasks. P1 BR 2.2.1.4 The system shall enable the user to specify departments, processes, or systems to be audited. P1 BR 2.2.1.5 The system shall enable the user to define what is not part of the audit scope. P1 BR 2.2.2 Audit Checklist: The system shall enable the user to create checklists based on audit standards or guidelines. These will serve as the audit framework. P1 BR 2.2.3 Assigning Auditors The system shall enable the user to assign roles and responsibilities to auditors to track team members, timelines, and milestones. P1 BR 2.2.4 Scheduling an Audit: BR 2.2.4.1 The system shall enable the user to schedule audit tasks P1 BR 2.2.4.2 The system shall be able to send reminders or notifications to auditors about upcoming deadlines. P1 BR 2.2.5 Audit Preparation (Pre-Audit Activities) BR 2.2.5.1 The system shall enable the user to create an audit checklist that specifies the steps, procedures, and tests that need to be followed during the audit. P1 BR 2.2.5.2 The system shall enable the user to upload and organize all relevant documentation (e.g., financial statements, compliance reports, policies, procedures, prior audit reports) for auditors to review. P1 BR 2.2.5.3 The system shall enable the user to access documents remotely and securely. P1 BR 2.2.5.4 The system shall enable the user to notify stakeholders (such as department heads or relevant teams) about the audit, including preparation requirements. P2 BR 2.3 Audit Execution BR 2.3.1 The system shall enable the user to log their observations, findings, and evidence in real- time, ensuring all information is captured electronically. P1 BR 2.3.2 The system shall support mobile access, allowing auditors to update findings on the go. P1 BR 2.3.3 The system shall enable the user to communicate with management, department heads, and other stakeholders P1 BR 2.3.4 The system shall enable the user to track and manage queries or follow-up requests P1 BR 2.3.5 The system shall provide audit trails, allowing for easy tracking and retrieval of supporting documents, comments, and observations P1 BR 2.3.6 The system shall enable the user to log non- compliance, discrepancies, or risks identified for further investigation or resolution. P1 BR 2.3.7 The system shall enable the user to track the status of the findings and ensure corrective actions are planned and implemented. P1 BR 2.3.8 The system shall enable auditors to categorize and rank findings based on their severity. P1 BR 2.3.9 The system shall enable the user to track meeting notes, actions, and outcomes. P2 BR 2.3.10 The system shall enable collaboration between auditors, management, and other relevant stakeholders. Documents, findings, and comments can be shared, discussed, and reviewed in real time. P1 BR 2.4 Reporting and Finalization BR 2.4.1 The system shall enable the user to generate comprehensive audit reports that detail the findings, issues, recommendations, and overall audit conclusions. P1 BR 2.4.2 The system shall provide templates for generating consistent and professional audit reports P1 BR 2.4.3 The system shall track the approval process and allow for comments or edits to be made before finalizing the audit report. P1 BR 2.4.4 The system shall enable the user to share audit reports with stakeholders, management, and other relevant parties P2 BR 2.4.5 The system shall enable the user to track corrective actions P2 BR 2.4.6 The system shall track the progress of corrective actions, ensuring that issues identified in the audit are addressed. P1 BR 2.4.7 The system shall send alerts to managers and auditors about the status of the actions P1 BR 2.4.8 The system shall enable the user to schedule follow-up audits or reviews to verify whether corrective actions have been effectively implemented and whether the issues have been resolved. P2 BR 2.4.9 The system shall enable the user to formally close the audit once all findings have been reviewed, corrective actions implemented, and any follow-up audits completed P1 BR 2.4.10 The system shall ensure that all documentation, reports, and audit records are archived for future reference and compliance requirements P1 BR 2.4.11 The system shall ensure that the records are securely stored and easily retrievable when needed. P1
DocumentAnnexure C Pricing Schedule.docxCompliance review in progress
Evaluation Criteria
Source: Annexure C Pricing Schedule.docx (unknown)
General: Applicants must be legally registered entities capable of entering into a contract. Experience in supplying, supporting, and maintaining Audit Management Systems is likely required. Financial stability and ability to fulfill a 5-year contract may be assessed. Specific: Prior experience with airport or large-scale enterprise systems may be advantageous. Compliance with South African Broad-Based Black Economic Empowerment (B-BBEE) policies may be required. Technical and operational capacity to deliver the system and support must be demonstrated.
Technical Specifications
Source: Annexure C Pricing Schedule.docx (unknown)
Scope: Supply, support, and maintenance of an Audit Management System for up to 60 months. Deliverables: Analysis and Design (Technical Specifications, Architecture Design, Functional Requirement Specification), Build/Development/Configuration, Testing (Functional and Performance Tests), Subscriptions, Hosting Environments (Development, Test, Production), Change Management (Training), Manuals (User and Operational), Project Management, Documentation, and Other related items.
Financial Requirements
Source: Annexure C Pricing Schedule.docx (unknown)
Pricing structure: Section A (Capex Cost Schedule), Section B (Opex Costs Schedule), Section C (Total Cost of Ownership). Itemized costs required for: Analysis and Design, Build/Development/Configuration, Testing, Subscriptions, Hosting Environments, Change Management, Manuals, Project Management, Documentation, and Other. Provide totals excluding and including VAT. OPEX costs must be broken down annually for 5 years. Final totals must include combined CAPEX + OPEX costs, excluding and including VAT.
The tender is for the supply, support, and maintenance of an Audit Management System for Airports Company South Africa (ACSA) over a maximum period of 60 months.
The system must align with ACSA’s Web Application Security Standards.
The system must cover all web applications used by ACSA, including off-the-shelf, customized, bespoke, and mobile applications (tablets/smartphones), as well as internal and public-facing applications, including those hosted by external providers.
Evaluation Criteria
Source: Web Application Security Standard.pdf (unknown)
Applicants must be legally registered entities capable of entering into a contract with ACSA.
Applicants must demonstrate experience in supplying, supporting, and maintaining Audit Management Systems or similar enterprise-level software.
Applicants must have a proven track record in implementing secure web applications compliant with international security standards.
Applicants must provide references or case studies of similar projects completed successfully.
Demonstrated expertise in web application security, including authentication, cryptography, and secure data handling.
Experience with mobile application security for enterprise systems.
Familiarity with compliance frameworks such as ISO 27001, NIST, or OWASP standards.
Ability to integrate with existing IT infrastructure and adhere to ACSA’s security policies.
Applicants must provide proof of financial stability to fulfill the 60-month contract.
Applicants may be required to provide financial statements or bank guarantees.
Compliance with South African labor laws and B-BBEE (Broad-Based Black Economic Empowerment) requirements, if applicable.
Applicants must agree to ACSA’s terms and conditions, including confidentiality and data protection clauses.
Technical Specifications
Source: Web Application Security Standard.pdf (unknown)
Scope: Supply, support, and maintenance of an Audit Management System for Airports Company South Africa (ACSA) for a maximum of 60 months. The system must cover all web applications used by ACSA, including off-the-shelf, customized, bespoke, and mobile applications (tablets/smartphones), as well as internal and public-facing applications, including those hosted by external providers.
Technical Requirements:
Architecture and Design: Only necessary components must be used. A high-level architecture must be defined and adhered to. No sensitive business logic, secret keys, or proprietary information may be exposed in client-side code.
Authentication: Must verify digital identity, ensure only authorized users can authenticate, and transport credentials securely. Key requirements include:
All pages/resources must require authentication by default unless public.
Credentials must not be pre-filled by the application.
Authentication controls must be server-side enforced and fail securely.
Password fields must support secure, complex passwords (e.g., passphrases).
Password recovery must not reveal current passwords or send new passwords in clear text.
No default passwords (e.g., "admin/password") may be used.
Anti-automation must prevent brute force and account lockout attacks.
Administrative interfaces must be protected by secure encrypted channels.
Session Management: Sessions must be unique, invalidated on logout, and timed out after inactivity. Session IDs must never be disclosed in URLs, error messages, or logs. Cookies must use "HttpOnly" and "secure" attributes.
Access Control: Principle of least privilege must apply. Access to sensitive records must be protected. Directory browsing must be disabled. Access controls must fail securely and be enforced server-side.
Input Validation: All input must be validated and sanitized. The system must protect against SQL injection, LDAP injection, OS command injection, XSS, XML attacks, and HTTP parameter pollution.
Cryptography: Cryptographic modules must fail securely. Random number generators must be cryptographically approved. Keys must be managed securely and be replaceable.
Error Handling and Logging: Logs must be high-quality, protected from unauthorized access, and not store sensitive data. Audit logs must support non-repudiation. Logs must be stored separately from the application with proper rotation.
Data Protection: Sensitive data must be encrypted, not cached client-side, and not sent via URL parameters. Client-side storage (e.g., local storage, cookies) must not contain sensitive data.
Communications Security: TLS must be used for all sensitive data transmissions. Strong algorithms and ciphers must be enforced. Certificate paths must be verified, and revocation checks (e.g., OCSP Stapling) must be enabled.
HTTP Security: Application server must be hardened. HTTP responses must specify safe character sets. Unnecessary HTTP methods (e.g., TRACE, PUT, DELETE) must be blocked. Security headers (e.g., CSP, X-FRAME-OPTIONS, X-XSS-Protection) must be implemented.
File Handling: Untrusted files must be stored outside the webroot with limited permissions. Uploaded files must be scanned for malware. Untrusted data must not be executed or embedded directly.
Mobile Security: Mobile apps must enforce the same security controls as the server. Sensitive data must be stored securely on devices. TLS must be used for all sensitive data transmissions. Device identifiers (e.g., UDID, IMEI) must not be used as authentication tokens. Sensitive data must not be stored unencrypted or in shared resources.
Classification of Controls:
All Applications: Compulsory for all web applications. Protects against easily discoverable/exploitable vulnerabilities.
Medium Criticality Applications: Compulsory for applications handling sensitive data (e.g., internal info, employee data, intellectual property). Standard controls for modern web applications.
High Criticality Applications: Compulsory for applications performing high-value transactions or storing highly sensitive data (e.g., trade secrets, critical organizational data). Advanced controls for highest security assurance.
Quality Management System: Compliance with ISO 9001 is required.
Related Procedures:
Document Control Procedure (Z001 006M).
Record Keeping Requirements Procedure (Z001 008M).
Monitoring and Review:
Monthly reports and reviews by the IT Service Desk to ensure adherence to the procedure.
Annual management review by the Senior Manager: Digital Infrastructure and Operations to measure implementation and adherence.
The procedure is subject to a 3-year review cycle or earlier if necessary due to legal, business, or operational changes.
Compliance Requirements
Source: Web Application Security Standard.pdf (unknown)
Compliance with ACSA Web Application Security Standards (G010 011M) is mandatory.
Adherence to ISO 9001 Quality Management System.
Compliance with ACSA’s Document Control Procedure (Z001 006M) and Record Keeping Requirements Procedure (Z001 008M).
Non-conformance must be reported and addressed via Corrective and Preventative Measures (Non-Conformance and Non-Compliance Procedure Document - Z001 001M).
Accountability for adherence lies with the Senior Manager: Information Security, Chief Information Officer, and Chief Executive Officer.
Internal audits will be conducted to verify compliance.
Records must be maintained for a minimum of 5 years, as per ACSA’s retention schedule.
Contract Duration: Maximum of 60 months.
Security Control Levels:
All Applications: Mandatory baseline controls for all web applications to mitigate easily exploitable vulnerabilities.
Medium Criticality Applications: Mandatory for applications handling sensitive data (e.g., internal info, employee data, intellectual property). Standard controls for modern web applications.
High Criticality Applications: Mandatory for applications processing high-value transactions or storing highly sensitive data (e.g., trade secrets, critical organizational data). Advanced controls for highest security assurance.
The contract will be monitored through executive committee oversight and internal audits.
The procedure will be reviewed every 3 years or earlier if required by legal changes, business needs, or updates to practices.
Contractual Terms
Source: Web Application Security Standard.pdf
Contract Duration: Maximum of 60 months.
Security Control Levels:
All Applications: Mandatory baseline controls for all web applications to mitigate easily exploitable vulnerabilities.
Medium Criticality Applications: Mandatory for applications handling sensitive data (e.g., internal info, employee data, intellectual property). Standard controls for modern web applications.
High Criticality Applications: Mandatory for applications processing high-value transactions or storing highly sensitive data (e.g., trade secrets, critical organizational data). Advanced controls for highest security assurance.
The contract will be monitored through executive committee oversight and internal audits.
Non-conformance must be reported and addressed via ACSA’s Non-Conformance and Non-Compliance Procedure (Z001 001M).
The procedure will be reviewed every 3 years or earlier if required by legal changes, business needs, or updates to practices.
DocumentAnnexure D - Audit Management Response Sheet (Self Scoring).xlsxReview complete
Description
Source: Annexure D - Audit Management Response Sheet (Self Scoring).xlsx
Supply, support, and maintenance of an Audit Management System for Airports Company South Africa over a maximum period of 60 months. The system must cover modules including risk management, audit planning/execution, stakeholder relations, tenant management, traffic development, training academy, and data migration.
Bidders must be legally registered entities with compliance to South African procurement laws and ACSA policies. Financial and technical capacity to deliver over 60 months is required. Scoring: Minimum threshold of 1296 points (out of 1728) qualifies for evaluation points (30, 14, 8, or 0). For functional categories: ≥90% of total score (428/475) earns 50 points; 80–89% earns 30 points; 70–79% earns 20 points; <70% earns 0 points.
Supply, support, and maintenance of an Audit Management System for ACSA over 60 months. Key modules: Risk Identification, Assessment & Prioritization; Audit Planning; Audit Execution; Reporting and Finalization; Stakeholder Relations Management; Tenant Relationship Management; Traffic Development Unit; Training Academy; Data Migration. Each module has detailed business requirements (BR) with sub-requirements. Bidders must confirm for each BR whether functionality is available or can be developed.
DocumentAnnexure E - Business Requirements compliance response document.docxReview complete
Description
Source: Annexure E - Business Requirements compliance response document.docx
Bidders must complete Annexure E (Business Requirements Compliance Response Document) by indicating for each listed business requirement (BR) whether the functionality is: - Available, or - Not available but can be developed. Requirements are prioritized as P1 (Mandatory) or P2 (Highly Desirable).
Submission Guidelines
Source: Annexure E - Business Requirements compliance response document.docx (unknown)
Bidders must complete Annexure E (Business Requirements Compliance Response Document) by indicating for each business requirement (BR) whether the functionality is: - Available, or - Not available but can be developed. This is a mandatory returnable document.
Evaluation Criteria
Source: Annexure E - Business Requirements compliance response document.docx (unknown)
Evaluation will consider the following: - Legal registration in South Africa or local presence. - Compliance with South African procurement laws and ACSA vendor requirements. - Demonstrated experience in supplying, supporting, and maintaining Audit Management Systems for large organizations (preferably aviation or public sector). - Financial and technical capability to fulfill the 60-month contract. Technical criteria include: - Proven track record of delivering systems with P1-priority functionalities (e.g., risk assessment, audit planning, real-time logging). - Ability to customize or develop missing functionalities as proposed. - Compliance with data security and confidentiality standards (e.g., ISO 27001, POPIA). - Support for multi-user collaboration, mobile access, and secure document management. Documentation requirements: - Detailed proposal addressing all BR requirements (available/not available but can be developed). - Case studies or references from similar projects. - Project implementation plan with timelines and milestones. - Proof of technical support and maintenance capabilities for the 60-month period.
Technical Specifications
Source: Annexure E - Business Requirements compliance response document.docx (unknown)
The Audit Management System must support the following core functionalities, categorized by priority (P1 = Mandatory, P2 = Highly Desirable): - Risk Identification, Assessment & Prioritization: Define risk categories, criteria, and thresholds; collect historical/current/external risk data; use templates/checklists/collaboration tools; assign likelihood/impact/exposure scores; calculate total risk scores; utilize risk matrices/heat maps; assign mitigation actions/responsible parties/timelines; track/reassess risks; maintain risk register; generate risk reports; define risk assessment criteria; rank risks by exposure; flag risks exceeding risk appetite; review/adjust priorities. - Audit Planning: Set audit objectives/goals/outcomes/boundaries; track objectives/scope; link objectives to tasks; specify departments/processes/systems to audit (and exclusions); create checklists based on audit standards; assign roles/responsibilities to auditors; schedule audit tasks; send deadline reminders/notifications; upload/organize/securely access audit documentation; notify stakeholders of preparation requirements. - Audit Execution: Log observations/findings/evidence in real-time; support mobile access; communicate with management/stakeholders; track/manage queries/follow-ups; provide audit trails; log non-compliance/discrepancies/risks; track status of findings/corrective actions; categorize/rank findings by severity; track meeting notes/actions/outcomes; enable real-time collaboration. - Reporting and Finalization: Generate comprehensive audit reports; use templates for consistency; track approval processes/allow edits; share reports with stakeholders; track/monitor corrective actions; send alerts on action status; schedule follow-up audits; formally close audits; archive all documentation securely for compliance/retrieval.
DocumentAudit Management System RFP.pdfReview complete
Description
Source: Audit Management System RFP.pdf
Request for Proposal for the supply, support, and maintenance of an Audit Management System for up to 60 months at Airports Company South Africa.
The system aims to implement a solution streamlining internal audit processes, aiding planning, scheduling, findings documentation, investigations, compliance management, inspections, data analysis, and corrective actions.
Important Dates
Source: Audit Management System RFP.pdf (RFP)
Bid Closing Date and Time: 10 July 2026 at 12:00.
Compulsory Briefing Session: 12 June 2026 at 10:00 via Microsoft Teams (link: https://teams.microsoft.com/meet/361395049765900?p=o1juTAuPEkvh07MRqu, Meeting ID: 361 395 049 765 900, Passcode: et3d9Bd9). Dial-in: +27 21 834 0841, conference ID: 525 637 91#. Attendance is mandatory; register online by providing your name, email, and telephone number in the chat.
Query Closing Date: 29 June 2026.
Clarification Deadline: Requests for clarity must be submitted by 19 June 2026 at 17:00.
Contact Information
Source: Audit Management System RFP.pdf (RFP)
For bidding procedure enquiries: Contact Sydney Mfeka, SCM Category Specialist. Email: [email protected]. Telephone: 011 723 1483.
Physical address for submission: Airports Company South Africa, Western Precinct, Aviation Park, O.R. Tambo International Airport, 1 Jones Road, Kempton Park, Gauteng, 1632.
Postal address: P O Box 75480, Gardenview, Gauteng, 2047.
Clarifications: Strictly via email to [email protected] until 19 June 2026 at 17:00. Do not contact other ACSA employees.
Fraud and corruption hotline: Tip-offs Anonymous at 0800 00 80 80 or 086 726 1681, email: [email protected].
Submission Guidelines
Source: Audit Management System RFP.pdf (RFP)
Submit your bid by hand delivery only to Tender Box C at Airports Company South Africa, 3rd Floor, North Wing, OR Tambo International Airport, Kempton Park, by 12:00 on 10 July 2026.
The bid must include an original printed copy and a USB, with the Bid Offer in a separate sealed envelope.
The original document is legally binding; in case of discrepancies, the original takes precedence.
Clearly label the outside of your submission with your return address, bid description, bid number, and SCM department details.
Ensure the Tender Deposit Register is completed and signed by the person depositing the bid.
Late submissions will not be accepted.
Do not alter the bid document; any changes may lead to disqualification.
ACSA may subject bidders to security vetting due to National Key Point regulations; non-compliance may result in disqualification.
Alternative bids are generally not accepted unless specifically requested by the Accounting Officer.
Returnable Documents
Source: Audit Management System RFP.pdf (RFP)
BID RESPONSE DOCUMENTS MAY BE DEPOSITED IN THE BID BOX SITUATED AT (STREET ADDRESS) Tender box: C The Tender box is located at: Airports Company South Africa 3rd Floor, North Wing OR Tambo International Airports Kempton Park (NB: Tender Deposit Register must be completed and signed by person depositing the bid documents)
Evaluation Criteria
Source: Audit Management System RFP.pdf (RFP)
Evaluation follows a staged approach: Mandatory Requirements, Functionality/Technical, Price and Preference.
Stage 1 Mandatory Requirements: Must provide OEM accreditation/certification proving partnership with the OEM for the Audit Management System, complete Annexure D (Self Scoring), Annexure E (Business Requirements), the Pricing Schedule, and attend the compulsory briefing session. Failure to meet these leads to disqualification.
Stage 2 Functionality: Scored out of 100 points with a minimum threshold of 80 points. Weighting: Bidders Experience (30), Business Requirements (50), Solution Delivery Timelines (20).
Stage 3 Price and Preference: Uses the 80/20 preference point system (80 points for price, 20 for specific goals). Price points calculated using formula Ps = 80(1 - (Pt - Pmin)/Pmin).
Preference Points: Up to 20 points for specific goals: B-BBEE status level (Level 1: 5 points, Level 2: 4.5, Level 3: 4, Level 4: 3, Level 5: 2, Level 6: 0.5, Level 7: 0.3, Level 8: 0.1, Non-compliant: 0), Black youth majority-owned entities (5), Black women majority-owned entities (5), Company majority owned by people with disabilities (5).
Provide proof for preference claims: valid sworn affidavit or SANAS-accredited B-BBEE certificate (consolidated for JVs).
Technical Specifications
Source: Audit Management System RFP.pdf (RFP)
Scope: Supply, support, and maintenance of an Audit Management System for a maximum period of 60 months at Airports Company South Africa.
The system aims to streamline internal audit processes, including audit planning, scheduling, risk assessment, fieldwork, findings management, reporting, workflow controls, document management, compliance alignment, analytics, and user security.
The solution must assist with audit execution, compliance management, walkthrough inspections, data analysis, and identifying weaknesses to implement corrective actions.
The contract will be for 60 months, with ACSA retaining the right to terminate, postpone, or delay upon written notice.
Detailed scope is provided in Annexure A (Scope of Work).
Methodology
Source: Audit Management System RFP.pdf
Evaluation uses a staged approach: check documents, evaluate functionality/technical aspects, evaluate price and preference, conduct post-tender negotiations, and perform security vetting.
Stages must be completed sequentially; ACSA may allow reasonable time for submitting required information.
Experience & Qualifications
Source: Audit Management System RFP.pdf
Bidders’ experience is weighted at 30 points out of 100 in the functionality evaluation.
No further details on specific experience or personnel qualifications are provided in the extracted text.
Pricing Schedule
Source: Audit Management System RFP.pdf
Submit a completed Pricing Schedule (Annexure C) as a mandatory requirement.
No further details on pricing format, rates, or payment schedules are provided in the extracted text.
Financial Requirements
Source: Audit Management System RFP.pdf (RFP)
Submit a completed Pricing Schedule (Annexure C) as part of mandatory requirements.
Prices must remain firm and valid for a validity period of 120 business/working days from submission.
The evaluation includes a price scoring component using the 80/20 preference point system.
No specific payment terms, bonds, or guarantees are detailed in the extracted text.
Compliance Requirements
Source: Audit Management System RFP.pdf (RFP)
Tax Compliance: Submit a valid Tax Compliance Status (TCS) PIN from SARS or a Central Supplier Database (CSD) number. Foreign bidders must declare if they have a branch, permanent establishment, or income source in RSA; if not, TCS PIN registration may not be required.
B-BBEE: Provide a B-BBEE certificate from a SANAS-accredited rating agency or a sworn affidavit for QSE/EME. Joint ventures must submit a consolidated certificate.
Company Registration: Provide a certificate of incorporation showing ownership split.
Central Supplier Database: Submit a CSD report.
VAT: Complete a VAT questionnaire if applicable.
Other Documents: Declaration of Interest and Politically Exposed Persons form, SBD 4 Bidder’s Disclosure Form, SBD 6.1 Preference Points Claim Form, Confidentiality and Non-Disclosure Agreement, Information Security Standards Framework, ACSA Terms and Conditions, and a letter of good standing.
Ensure all submitted documents remain valid for the contract duration; update ACSA if any expire.
Contractual Terms
Source: Audit Management System RFP.pdf
Contract Duration: 60 months upon appointment, based on ACSA’s contract template.
Termination: ACSA may terminate, postpone, or delay the contract upon written notice as per prescribed process.
Validity Period: Bid prices must remain firm for 120 business/working days.
Confidentiality: ACSA will not disclose bidder information without written approval; bidders must not disclose ACSA information and must have third parties sign confidentiality agreements if consulted.
Security Vetting: ACSA is a National Key Point; bidders may be subject to security vetting, and non-compliance may lead to disqualification.
Disclaimers: ACSA reserves rights to award whole or part of the bid, split awards, negotiate with shortlisted bidders, award to other than the highest scorer, reject the lowest acceptable bid, or cancel the bid.
Changes to the bid document are prohibited and may lead to disqualification.
Special Conditions
Source: Audit Management System RFP.pdf (RFP)
Alternative bids are generally not accepted unless requested by the Accounting Officer.
Late bids will not be accepted.
Bid responses must strictly comply with the document; non-compliance may lead to disqualification. No changes allowed after closing.
Bidders may not have interests in other bidders/consortia.
ACSA is a National Key Point; security vetting may apply, and non-compliance may disqualify bidders.
Requirements
Source: Audit Management System RFP.pdf (RFP)
Foreign bidders must declare residency, branch, permanent establishment, income source, and tax liability in RSA; if none, TCS PIN registration may not be required.
Bids must be submitted on official forms, not retyped, and comply with the Preferential Procurement Policy Framework Act and regulations.
Successful bidder must sign a written contract post-award.
Tax compliance is mandatory; provide TCS PIN or CSD number, with separate submissions for consortia/JVs.
Failure to provide required particulars may render the bid invalid.
DocumentAnnexure B - Evaluation Criteria.pdfReview complete
Submission Guidelines
Source: Annexure B - Evaluation Criteria.pdf (unknown)
Submit the following returnable documents as part of your bid:
Signed/stamped original contactable reference letter(s) from client(s) where the Audit Management System or similar solution was implemented. Each letter must include: clear letterhead, client’s contact details, scope of services rendered, contract duration (start and end date), and signature by the client’s authorized official.
Implementation plan detailing: executive overview, critical path, development approach, testing approach (unit, functional, performance, stress, vulnerability), evidence of a complete Project Management Life Cycle, and reporting areas, mechanisms, and frequency during project management.
System architecture diagram including: solution overview (key components), environments (Dev, QA, Pre-prod, Test, Production), communication protocols (e.g., HTTP, HTML, XML, REST API, JSON), backup requirements (process, storage, restoration), and business continuity configuration.
Returnable Documents
Source: Annexure B - Evaluation Criteria.pdf (unknown)
Required returnable documents:
Signed/stamped original contactable reference letter(s) from client(s) where the Audit Management System or similar solution was implemented.
Evaluation Criteria
Source: Annexure B - Evaluation Criteria.pdf (unknown)
Evaluation is scored out of 100 points with the following breakdown:
Bidder’s Experience (30 points):
5+ cumulative years of relevant experience in implementing, supporting, and maintaining an Audit Management System: 30 points.
3 to <5 years: 20 points.
1 to <3 years: 10 points.
<1 year: 0 points.
Business Requirements (50 points):
Score ≥200 points: 50 points.
Score ≥150 and <200 points: 40 points.
Score ≥125 and <150 points: 20 points.
Score <125 points: 0 points.
Solution Delivery Timelines (20 points):
Delivery in <10 months: 20 points.
Delivery in exactly 10 months: 10 points.
Delivery in >10 but <12 months: 5 points.
Delivery in ≥12 months: 0 points.
Additional Rules:
Minimum 80 overall points required to proceed to the demo evaluation stage.
Only bidders meeting the 80-point threshold will be invited for a demo. The demo must clearly show the Audit Management solution, and only P1 requirements will be evaluated.
Technical Specifications
Source: Annexure B - Evaluation Criteria.pdf (unknown)
Scope: Supply, support, and maintenance of an Audit Management System for Airports Company South Africa for a maximum period of 60 months.
Technical Requirements:
System must support multiple environments: Dev, QA, Pre-prod, Test, and Production.
Must utilize communication protocols such as HTTP, HTML, XML, REST API, or JSON.
Backup requirements: Define how backups are performed, stored, and restored, including user request processes.
Business Continuity: System must be configured to ensure uninterrupted business operations.
System architecture diagram must illustrate structure, components, and interactions.
Testing Requirements:
Testing approach must cover unit, functional, performance, stress, and vulnerability testing.
Methodology
Source: Annexure B - Evaluation Criteria.pdf
System Architecture Diagram must illustrate the structure and components of the system, showing how its various parts interact. Include:
Provide signed/stamped original contactable reference letter(s) from client(s) where the Audit Management System or similar solution was implemented. Each letter must include:
a) Clear letterhead.
b) Client’s contact details.
c) Scope of services rendered.
d) Contract duration (start and end date).
e) Signed by the client’s authorized official.
Evaluation Criteria for Experience:
5+ cumulative years of relevant experience: 30 points.
3 to <5 years: 20 points.
1 to <3 years: 10 points.
<1 year: 0 points.
Quality Management
Source: Annexure B - Evaluation Criteria.pdf
Quality requirements:
System must support multiple environments: Dev, QA, Pre-prod, Test, and Production.
Backup requirements: Define how backups are performed, stored, and restored, including user request processes.
Business Continuity: System must be configured to ensure uninterrupted business operations.
Section
Source: Annexure B - Evaluation Criteria.pdf
Solution Demo Evaluation:
Only bidders meeting the overall minimum score (80 points) will be invited.
Bidders must present a demo clearly showing the Audit Management solution.
Only P1 requirements will be evaluated.
Sets the constitutional standard for fair, equitable, transparent, competitive and cost-effective public procurement.
Relevant because this is a South African public-sector procurement opportunity.
This tender has strong source evidence, including source metadata and supporting tender information synced from the government tender portal.
Tenders SA is not the issuing authority. All tenders are automatically synced from the official government tender portal. Always confirm final submission details, closing dates, briefing sessions, eligibility requirements, and documents on the official government portal before applying.