Supply of a tracing tool for forensic investigations to the road accident fund over a twelve-month period, based in gauteng. Bids close on 2 october 2026 at 11:00. Evaluation follows the 80/20 preference point system: 80 points for price and 20 points for specific goals, split as 10 points for historically disadvantaged individuals, 8 for women and 2 for persons with disability. The decisive submission is sbd 6.1 — A specific-goal claim lodged without the required supporting proof earns NO preference points.
Key Requirements
Closing: bids close on 2 October 2026 at 11:00.
Contract: appointment for a tracing tool for forensic investigations, for a period of twelve (12) months, in Gauteng.
Preference system: the 80/20 system applies (contract value up to R50 000 000, all applicable taxes included); price carries 80 points and specific goals 20 points.
Specific goals: 10 points for historically disadvantaged individuals, 8 points for women and 2 points for persons with disability, claimed on SBD 6.1.
Mandatory form: SBD 6.1 (Preference Points Claim Form) must be completed and submitted; a preference claim not supported by the proof or documentation required in the tender means no points are awarded for those goals.
Substantiation: the organ of state may call for proof of any preference claim before adjudication or at any later stage.
Fraudulent claims: disqualification from the tendering process, recovery of costs, losses or damages, cancellation of the contract with damages claimed, restriction of the bidder, its shareholders and directors from doing business with any organ of state for up to 10 years after the audi alteram partem rule has been applied, and referral for criminal prosecution.
The Road Accident Fund (RAF) wishes to appoint an experienced service provider to provide a Tracing Tool for forensic Investigations for a period of twelve (12) months.
Tender context
Return to this tender’s issuing organisation, province, or category.
The road accident fund (raf) wishes to appoint an experienced service provider to provide a tracing tool for forensic investigations for a period of twelve (12) months.
Professional Services & Consulting Industry Profile
Regulatory Bodies
SAGCSAICA
Tenders in this industry often require registration with these bodies.
Typical Documents
5 items
Company Registration (CIPC)
Tax Clearance Certificate
B-BBEE Certificate
CSD Registration
Company Profile
Recommended Certifications
Having these can improve your winning chances: CA(SA) - Chartered Accountant, PMI-PMP (Project Management Professional), Prince2 Practitioner, Six Sigma Certification
Document read. The full tender notice and its supporting documents are read end-to-end. Key sections, requirements, dates, and contact details are identified and pulled into a working summary you can act on.
Compliance review. The working summary is checked against South African procurement standards — PFMA, PPPFA, B-BBEE, CIDB, local content, and preferential procurement — so nothing critical is missed before you start your bid response.
DocumentAnnexure A - Security Measures.pdfReview complete
Description
Source: Annexure A - Security Measures.pdf (unknown)
Important Dates
23 Sept
2026
PUBLICATION
Tender Published
Tender was published
02 Oct
2026
DEADLINE
Closing Date
Tender closing date
Procurement Rules & Compliance ContextThis tender may be governed by South African public procurement rules covering fairness, transparency, preferential procurement, anti-corruption, administrative justice and access to information.
10 rules
These references help suppliers understand the public-procurement framework around this opportunity. They are generated from the tender category, issuing organisation type and procurement context.
Core procurement rules
These rules commonly apply to South African public-sector procurement.
7
Broad-Based Black Economic Empowerment Act (B-BBEE Act)
Act 53 of 2003
high
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Constitution of the Republic of South Africa, 1996 – Section 217
Act 108 of 1996 (s217)
high
This is general procurement context, not legal advice. Always verify requirements in the official tender documents and issuing authority notices.
The Road Accident Fund (RAF) requires a SaaS-based tracing tool for forensic investigations, to be supplied and supported for twelve months. The tool must provide identity, address, telephone, employment, company, property and relationship tracing with lawful data sources, confidence scoring, audit trails, integration, and POPIA compliance. Bidders must be CSD-registered, complete mandatory forms, and meet technical and presentation thresholds to proceed to price evaluation.
The Road Accident Fund requires an experienced service provider to supply a tracing tool for forensic investigations for a twelve-month contract. The service provider will handle confidential, private, personal or sensitive information and must implement extensive technical and organisational security measures to protect it.
The Road Accident Fund requires an experienced service provider to supply a tracing tool for forensic investigations for a twelve-month period. The tool will support the RAF's forensic investigation activities.
The Road Accident Fund requires an experienced service provider to supply a tracing tool for forensic investigations for a period of twelve months. The contract will be awarded under the 80/20 preference point system, with 80 points for price and 20 points for specific goals.
Not sure if your business is ready for this tender? Check CSD, CIDB, and B-BBEE requirements, run a readiness assessment, and move from opportunity to submission.
APPOINTMENT OF A SERVICE PROVIDER OR CONSORTIUM OF SERVICE PROVIDERS FOR PROVISIONING OF SERVICES ON THE EARLY CHILDHOOD DEVELOPMENT NUTRITION SUPPORT PROGRAMME OF THE DEPARTMENT OF BASIC EDUCATION FOR A PERIOD OF THREE YEARS
Based on 25 comparable awarded tenders. Companies with similar profiles typically bid near the median.
* Estimates are based on historical data and do not guarantee actual award values.
Bid-ready summary. The submission guidelines, evaluation criteria, technical, financial, and compliance sections are refined into professional, easy-to-scan prose. This is the final version you can rely on when preparing your bid or briefing your team.
We refine every tender document through these stages so you can brief your team and prepare your bid with confidence. Anything marked as "in progress" will be upgraded automatically — no action required from you.
Document read
Compliance review
Bid-ready summary
The annexure sets out the technical and organisational security measures the service provider must apply while it holds RAF confidential, private, personal or sensitive information during the contract. The provider must maintain policies that satisfy both RAF requirements and the Protection of Personal Information Act.
Technical Specifications
Source: Annexure A - Security Measures.pdf (unknown)
Scope of this annexure
Sets out the technical and organisational security measures the appointed service provider must implement while handling RAF confidential, private, personal and sensitive information (files, data and documents) for the duration of the contract.
Document handling and transport
Written protocols for moving files between the RAF and the provider's premises.
Lockable transport system for transferring files to and from premises.
Files kept in lockable containers or packaging during handling and transport to prevent loss, theft or damage.
Accurate records of every document held, covering storage location, access history and retention schedule, organised for easy and accurate tracking.
Retrieval and storage
Secure retrieval protocols, including verification of the identity of the person requesting documents.
Detailed log of all retrieval activity: date and time, identity of requester, and reason for retrieval.
Physical documents and records stored in lockable cabinets to prevent unauthorised access or tampering.
Access limited to authorised personnel, with policies and procedures to control and monitor that access.
Facility and physical security
Premises with a secure perimeter, controlled access and/or surveillance systems.
Secure doors, locks and alarms to prevent unauthorised entry.
All document storage facilities adequately protected against unauthorised access.
Fire suppression system or equivalent, with carbon dioxide fire extinguishers, to prevent damage or loss of records in a fire.
Digital and network security
Firewalls, intrusion detection and encryption on digital document storage systems.
Access granted on a need-to-know basis, using strong authentication, with permissions reviewed and updated regularly.
Encryption of data in transit and at rest, using protocols and algorithms that meet industry standards.
Systems, software and applications regularly updated and patched against vulnerabilities.
Robust protection against malware, phishing and unauthorised access.
Incident response
A documented incident response plan to address and mitigate data breaches promptly.
Immediate notification to the RAF of any data breach or security incident affecting the information.
On any real, attempted or suspected physical security breach, the provider must inform the RAF and supply CCTV footage, a police report and linked alarm system records.
Subcontractors
Any subcontractor must meet the same data protection and cybersecurity standards.
The provider remains responsible for the actions and compliance of subcontractors and third parties.
Third parties handling personal information must be screened or vetted for their data protection policies and must sign a data protection agreement.
Compliance Requirements
Source: Annexure A - Security Measures.pdf (unknown)
Data protection
The provider must hold policies that meet RAF requirements and the Protection of Personal Information Act (POPIA).
Personal and sensitive data must be processed in line with applicable data protection laws and regulations.
Measures must safeguard data against unauthorised access, disclosure, alteration and destruction.
Confidentiality obligations must be imposed on agents, subcontractors and any third party that receives records.
The provider must comply fully with the relevant legislative and regulatory frameworks for processing personal information.
Vetting and oversight
The RAF reserves the right to conduct security screening or vetting of company directors and of the resources provided.
The RAF reserves the right to audit and monitor the provider's compliance with these measures.
The provider must cooperate with any RAF audit or assessment of data protection and cybersecurity compliance.
Health & Safety
Source: Annexure A - Security Measures.pdf (unknown)
Fire safety
The provider's premises must have a fire suppression system or equivalent.
Carbon dioxide fire extinguishers must be available to prevent damage to or loss of documents and records in a fire.
Facility security
Premises must have a secure perimeter with controlled access and/or surveillance systems.
Secure doors, locks and alarms must prevent unauthorised access.
Physical security measures must protect documents at all times, including controlled access points, surveillance cameras and/or 24/7 monitoring.
Access to documents and records must be controlled and monitored, with only authorised personnel permitted to handle, view or transport them.
Contractual Terms
Source: Annexure A - Security Measures.pdf (unknown)
Data protection obligations
Personal and sensitive data must be handled and processed in compliance with applicable data protection laws.
Safeguards must prevent unauthorised access, disclosure, alteration and destruction of data.
Any data breach or incident affecting information security must be reported to the RAF immediately.
Confidentiality of personal, confidential and sensitive data must be protected, including by binding agents, subcontractors and any third party that receives records to confidentiality.
The provider must comply fully with the applicable legislative and regulatory frameworks for processing personal information.
Third parties processing personal information on the RAF's behalf must be screened or vetted for their data protection policies and must sign a data protection agreement.
The RAF may conduct security screening or vetting of company directors and of the resources provided.
Cybersecurity
Robust measures against malware, phishing and unauthorised access.
Encryption of data in transit and at rest, using industry-standard protocols and algorithms.
Systems, software and applications updated and patched regularly to close vulnerabilities.
Incident reporting and response
A documented incident response plan must be in place to address and mitigate data breaches promptly.
Security incidents and data breaches must be reported to the RAF without delay.
Subcontractors and third parties
Subcontractors must meet the same data protection and cybersecurity standards.
The provider is accountable for the actions and compliance of subcontractors and third parties delivering services to the RAF.
Audit and monitoring
The RAF may audit and monitor compliance with these measures.
The provider must cooperate with RAF audits and assessments of data protection and cybersecurity compliance.
Special Conditions
Source: Annexure A - Security Measures.pdf (unknown)
Confidential information
During the contract the provider will hold RAF confidential, private, personal or sensitive information, referred to as files, data and documents.
The provider must have policies in place that meet RAF requirements and the Protection of Personal Information Act.
Document handling and transport
Protocols must govern the proper handling and transport of files between the RAF and the provider's premises.
A secure, lockable transport system must be used.
Files must be kept in lockable containers or packaging during handling and transport to prevent loss, theft or damage.
Accurate records must be kept of each document stored, covering location, access history and retention schedule, organised for easy and accurate tracking.
Retrieval and storage
Secure retrieval protocols must verify the identity of the requester and ensure records are transported securely.
A detailed log of retrieval activity must record the date and time, the requester's identity and the reason for retrieval.
Physical documents and records must be stored in lockable cabinets to prevent unauthorised access or tampering.
Access must be limited to authorised personnel, with policies and procedures to control and monitor it.
Network security
Digital storage systems must use firewalls, intrusion detection and encryption against unauthorised access or attack.
The Road Accident Fund, a Schedule 3A public entity established under the Road Accident Fund Act, 1996 (Act No. 56 of 1996), provides compulsory social insurance cover to road users, rehabilitates and compensates persons injured by negligent driving, and promotes road safety. Its head office is in Centurion, Pretoria, with offices countrywide.
The RAF requires an experienced service provider to supply a tracing tool for forensic investigations for a period of twelve (12) months. The tool must support lawful, auditable identity, contact, employment, company, property and relationship tracing, with confidence scoring, evidence trails, audit reporting, secure integration, bulk screening, role-based access control and POPIA compliance, delivered as a managed SaaS service.
Quotations sent to any other address will not be considered.
Closing: 02 October 2026 at 11:00. Late quotations are rejected.
Quotation validity: 30 days from the closing date.
Reference to quote on all correspondence: PR10117099.
Returnable documents
All annexures to the RFQ must be completed and signed.
SBD 4 (Bidder's Disclosure): discloses directors' or shareholders' interests and state employment links.
SBD 6.1 (Preference Points Claim, PPR 2022): claims preference points under the applicable preference system.
Annexure B (Bidder's Client References): at least three references evidencing tracing-solution experience.
Annexure E cost breakdown table: priced per line item, VAT inclusive where the bidder is VAT registered.
Signed letter of authorisation, reseller, partnership or licence agreement (or equivalent) from the technology/data provider confirming the bidder may supply the proposed solution to the RAF for the contract term.
Valid medical certificate from a registered medical practitioner where disability is claimed.
Disqualification risks
Quotation received after the closing time.
Quotation sent to the wrong email address.
Any annexure or returnable form not completed and signed.
Prices not entered on the prescribed cost breakdown table.
A non-VAT-registered bidder charging VAT.
Collusive behaviour, including more than one bid from separate registered companies sharing a director or shareholder, or one bidder responding through more than one entity.
Offering gifts, hospitality or other benefits (including branded marketing material) to RAF officials.
Four sequential phases; failure at any phase ends the bid.
Phase 1 — Mandatory requirements
Bidders tick comply or do not comply; non-compliant bids are disqualified and not evaluated further.
Mandatory item: signed partner letter or equivalent authorisation from the technology/data provider. The RAF may validate all letters submitted.
Phase 2 — Technical requirements (50 points)
Track record: 25 points. Minimum three references on Annexure B showing tracing-solution experience; the RAF may validate references.
Project proposal: 25 points. Five points for each required item present in the proposal, zero if absent.
Minimum qualifying score: 40 out of 50 to proceed.
Phase 3 — Presentation (50 points)
Presentation of the tool's capabilities to the RAF; 40 minutes, with a maximum of five days' notice.
Five points for each required capability demonstrated, zero if absent.
Minimum qualifying score: 40 out of 50 to proceed to price and specific goals.
Phase 4 — Price and specific goals (100 points)
Price: 80 points.
Specific goals: 20 points.
Preference point system: 80/20, applicable to quotations from R30 000 up to R1 000 000 including all taxes. The RAF may also apply 80/20 to quotations below R30 000.
Supply of a Software-as-a-Service tracing tool for RAF forensic investigations, for a period of twelve (12) months, including hosting, platform management, maintenance, monitoring, updates, incident management, service reporting, backup and recovery, user support and account management.
Required tracing capabilities
Identity and address tracing from lawful, auditable and approved data sources.
Telephone and contact-number verification, including current and historical contact information.
Employment history and current employer verification where legally permissible.
Company directorship, beneficial-interest and business-affiliation checks.
Property ownership and property-linked information checks.
Identification of associated persons, entities and relationship networks.
Deceased, estate and historical-record checks where legally permitted.
Cross-checking and corroboration across multiple independent data sources.
Search by name, South African identity number, company registration number, address, phone number and other approved identifiers.
Data sources and provenance
Bidders must disclose the categories of data sources used and confirm lawful acquisition, processing, storage and availability.
Evidence required of provenance, permitted-use rights, refresh frequency, coverage, accuracy controls and use restrictions per data category.
The solution must distinguish verified data, inferred data and unconfirmed candidate matches.
Search, matching and confidence scoring
Support exact, fuzzy and partial matching against approved identifiers.
Provide confidence scores or match indicators.
Describe matching methodology and controls against false positives and false negatives.
Provide evidence trails showing which data points produced a match.
Allow users to review, filter and export results in a controlled, auditable manner.
Reporting and audit
Generate formal, timestamped reports suitable for internal use, audit review and evidentiary support, covering search criteria, data sources queried, result summaries, confidence indicators, user details, timestamps and the basis for results.
Include an auditing and reporting module tracking individual staff usage, with timestamps and a mandatory operational reason or case reference per search.
Maintain a secure, tamper-evident log of all user activity across tracing functions.
Integration and bulk screening
Secure integration via documented APIs or equivalent mechanisms, subject to RAF security and architecture requirements.
Role-based access control for users, administrators and support personnel.
Least-privilege access, segregation of duties and user lifecycle management.
Logging of all searches, views, exports, administrative and configuration changes.
Tamper-resistant, searchable audit logs retained per agreed retention requirements.
Description of encryption, authentication, monitoring, vulnerability management and incident response.
Legal and POPIA compliance
Demonstrated compliance with the Protection of Personal Information Act, applicable South African data protection law, lawful processing principles, information security obligations and sector-specific requirements.
Description of data retention, deletion, data-subject-rights, breach-notification and subcontractor-management processes.
Confirmation of support for the RAF's accountability, audit and reporting obligations under the public-sector governance framework.
Service levels and performance
Measurable service levels proposed for availability, response times, incident resolution, support hours and reporting frequency.
Scalability for agreed user volumes, transaction volumes and bulk screening.
Disaster recovery and business continuity commitments.
Monthly service reports covering usage, incidents, availability, changes, security events and service improvements.
Implementation, training and transition
Complete implementation plan covering initiation, requirements confirmation, configuration, integration, testing, security assurance, user acceptance testing, training, go-live, hypercare and transition to steady-state support.
Implementation resources, project governance, risk management and knowledge transfer included in the proposal.
Report content required
Individuals: telephone and cellular numbers (historical and current, with network provider), physical address, passport numbers, employment history and address, marital status, criminal checks, educational history, properties registered in the individual's name, movable assets, shareholding and directorship, credit checks, and unabridged birth certificate.
Companies: physical and postal address, registration numbers, properties registered in the company's name, and shareholding and directorship.
CSD registration is mandatory; the RAF conducts business only with CSD-registered suppliers.
Tax matters must be declared in order by SARS.
B-BBEE and specific goals
Preference points are claimed on SBD 6.1 under PPR 2022, within the 80/20 system.
Race and gender points claimed for Historically Disadvantaged Individuals are verified through the CSD.
Disability claims require a valid medical certificate from a registered medical practitioner.
Mandatory authorisation
Signed letter of authorisation, reseller agreement, partnership agreement, licence agreement or equivalent from the technology/data provider confirming the bidder is authorised to supply the proposed solution to the RAF for the contract duration. The RAF may validate all letters.
Bidder qualification requirements
Demonstrated experience in SaaS-based tracing, verification, data-enrichment or investigative-intelligence solutions.
Demonstrated managed-services and implementation support to public-sector or enterprise clients.
Evidence of financial standing, operational capacity, information security capability and legal authority to provide the services.
References for comparable engagements, including scale, duration and service scope.
Confirmation of registration on applicable supplier databases and compliance with applicable tax and statutory requirements.
Conduct
No gifts, hospitality or other benefits (including branded marketing material) to RAF officials; any request for such benefits must be reported to the toll-free fraud line 0800 005919.
No collusive bidding; multiple bids from entities with common directors or shareholders, or one bidder bidding through more than one entity, result in disqualification of all.
SBD 4 (Bidder's Disclosure): must be completed and signed, disclosing any state employment of the bidder or its directors, shareholders, members or partners, any relationship with staff of the procuring institution, and any interest in a related enterprise.
Disqualification risk
A bidder listed on the Register for Tender Defaulters or the List of Restricted Suppliers is automatically excluded from the bid process.
A disclosure found to be untrue or incomplete disqualifies the bid.
Evaluation Criteria
Source: SCM-Bid Documents SBD 4.doc (unknown)
No evaluation criteria, scoring split or preference point system is set out in the available material.
Stated exclusion
Bidders appearing on the Register for Tender Defaulters or the List of Restricted Suppliers are automatically disqualified.
Compliance Requirements
Source: SCM-Bid Documents SBD 4.doc (unknown)
Mandatory declaration
SBD 4 (Bidder's Disclosure) must be signed and submitted; it covers state employment of the bidder or its controlling persons, relationships with employees of the procuring institution, and interests in other related enterprises.
Exclusion
Listing on the Register for Tender Defaulters or the List of Restricted Suppliers bars the bidder from the process.
False or incomplete disclosure leads to disqualification and possible action under PFMA SCM Instruction 03 of 2021/22, the Competition Act 89 of 1998 or the Prevention and Combating of Corrupt Activities Act 12 of 2004.
DocumentSBD 6.1 IN TERMS OF PPR2022.docxReview complete
Submission Guidelines
Source: SBD 6.1 IN TERMS OF PPR2022.docx (unknown)
Returnable form
SBD 6.1 (Preference Points Claim Form): claims preference points for specific goals under the Preferential Procurement Regulations 2022 and must be completed and submitted with the bid.
Consequences of omission
If the proof or documentation required to support a specific-goal claim is not submitted with the bid, no preference points are awarded for those goals.
The organ of state may call for substantiation of any preference claim before adjudication or at any later stage.
Evaluation Criteria
Source: SBD 6.1 IN TERMS OF PPR2022.docx (unknown)
Preference point system
80/20 system applies (contract value up to R50 000 000, all applicable taxes included).
Points for specific goals are awarded only where the claim is supported by the proof or documentation required in the tender.
The organ of state may require a bidder to substantiate any preference claim at any time.
Compliance Requirements
Source: SBD 6.1 IN TERMS OF PPR2022.docx (unknown)
Mandatory form
SBD 6.1 (Preference Points Claim Form): must be completed and submitted to claim points for specific goals.
Disqualification and sanction risks
A preference claim made on a fraudulent basis may lead to disqualification from the tendering process.
The organ of state may recover costs, losses or damages suffered as a result of the conduct.
The contract may be cancelled, with damages claimed for any less favourable replacement arrangement.
The bidder, its shareholders and directors may be restricted from doing business with any organ of state for up to 10 years, after the audi alteram partem rule has been applied.
The matter may be referred for criminal prosecution.
Sets the constitutional standard for fair, equitable, transparent, competitive and cost-effective public procurement.
Relevant because this is a South African public-sector procurement opportunity.
2, Eco Glades Office Park, 420 Witch-Hazel Ave, Centurion, Pretoria, 0046, South Africa
Document-Backed
Source Snapshot Available
AI Enhanced
Source confidence
High source confidence
Official source
eTenders.gov.za
Documents found
4
Last checked
01 Oct 2026
AI status
Enhanced
Data conflicts
None detected
This tender has strong source evidence, including source metadata and supporting tender information synced from the government tender portal.
Tenders SA is not the issuing authority. All tenders are automatically synced from the official government tender portal. Always confirm final submission details, closing dates, briefing sessions, eligibility requirements, and documents on the official government portal before applying.
Get deep intelligence on Computer programming, consultancy and related activities. Unlock full pricing strategies, bid frequency, and historical win rates.