Progress
Unique Identification Authority Of India (UIDAI) invites bids for ISO 27701:2025 Certification and Surveillance Audit services for the Privacy Information Management System (PIMS). The scope spans Initial Audit, Pre-Assessment Audit, Certification Audit, Surveillance Audit, 1st and 2nd Surveillance Audits post-certification. EMD ₹32,745 applies. Location is NEW DELHI, DELHI. The engagement targets auditors with PIMS ISO 27701:2025 experience, capable of handling multi-stage audits and post-certification surveillance. The procurement emphasizes a robust escalation matrix, past project evidence, and flexible contract volume under 25% scalars per the contract terms. Unique scope includes both certification and ongoing surveillance activities, ensuring continued conformance to privacy management standards. The tender presents a compliance-heavy, audit-focused engagement requiring proven information security and privacy governance expertise. The absence of BOQ items indicates a services-led engagement rather than goods procurement.
ISO 27701:2025 certified privacy information management system auditing
Multi-stage audit scope: Initial, Pre-Assessment, Certification, Surveillance (1st and 2nd post-certification)
Surveillance cadence post-certification, with documented evidence requirements
Eligibility: proven capability to perform complex privacy governance audits in government context
EMD of ₹32,745 required for bid security and bid validity
Contract scope expandable by 25% with consent; no supplier exclusivity
Escalation matrix must be provided; past experience documentation accepted in multiple formats
Not explicitly defined; bidders should align with standard government payment terms post-delivery and audit acceptance
Audits to be scheduled in phases; bidders must propose multi-stage audit plan with milestones
No explicit LD framework provided; contract to define SLAs with potential penalties for delays
Proven ISO 27701:2025 certification/audit experience or equivalent privacy standard audits
Financial stability evidenced by audited statements and no ongoing insolvency
Ability to provide escalation matrix and post-audit support
Past project proofs acceptable via contracts, client attestations, or execution notes
Quantity
3
Bid Type
Two Packet Bid
Bid Validity
180 (Days)
Bid Type
Service
Evaluation
Total value wise evaluation
RA Qualification Rule
H1-Highest Priced Bid Elimination
Tech Clarification Time
3 Days
EMD Required
Yes
MII Compliance
Yes
MSE Purchase Preference
Yes
MSE Preference Band
L1+15%
MSE Exemption/Relaxation
Yes
Startup Exemption/Relaxation
Yes
Bid Splitting Applied
No
Min. Avg. Annual Turnover
3
Experience Required
3 Year (s)
Arbitration Clause
No
Mediation Clause
No
Tender Category
Service
Bid To RA
No
Bid To RA Enabled
Yes
Item Category
Hiring Of Agency For ISO Certification Service - Certification and Surveillance Audit of Privacy Information Management System (PIMS) ISO 27701:2025 as per Scope of Work; Initial Audit; Pre-Assessment Audit, Certification Audit , Hiring Of Agency For ISO Certification Service - Certification and Surveillance Audit of Privacy Information Management System (PIMS) ISO 27701:2025 as per Scope of Work; Surveillance Audit; 1st Surveillance Audit post Certification , Hiring Of Agency For ISO Certification Service - Certification and Surveillance Audit of Privacy Information Management System (PIMS) ISO 27701:2025 as per Scope of Work; Surveillance Audit; 2nd Surveillance Audit post Certification
Advisory Bank
State Bank of India
ePBG Percentage
5%
ePBG Duration (Months)
38
Delivery Locations
1
Delivery Cities
New Delhi
Delivery Pincodes
110001
| Consignee | Address | City | State | Pincode | Quantity | Delivery Days | Additional Requirement |
|---|---|---|---|---|---|---|---|
| Hemant Kumar Jain | 110001,4 Aaadhaar, Bangla Sahib Road, Gole Market, New Delhi | New Delhi | Delhi | 110001 | 1 | - | - |
End-to-end support — bid preparation, GeM registration, document filing & compliance by industry experts.
Free consultation · 24h response
Main Document
OTHER
GEM_GENERAL_TERMS_AND_CONDITIONS
GEM_GENERAL_TERMS_AND_CONDITIONS
Discover companies most likely to bid on this tender
GST registration certificate
Permanent Account Number (PAN) card
Experience certificates for ISO 27701:2025 or similar privacy management system audits
Financial statements (last 2–3 years) and current solvency proof
EMD submission document (₹32,745) as per payment terms
Technical bid detailing audit methodology and schedule
OEM authorizations or attestations if sub-contracted partners are used
Past client contracts and execution certificates
Key insights about DELHI tender market
Bidders must submit GST, PAN, and financials with an EMD of ₹32,745. Provide past ISO 27701:2025 audit proofs, an audit plan, and escalation matrix. Ensure compliance with 25% quantity/duration flex if the scope changes and align with UIDAI terms on post-certification surveillance.
Required documents include GST certificate, PAN card, 2–3 years of financial statements, experience certificates for ISO 27701:2025 or similar, EMD submission, technical bid detailing audit methodology, OEM authorizations if applicable, and client execution certificates or contract copies for past audits.
Auditors must demonstrate ISO 27701:2025 certification capabilities, provide an initial, pre-assessment, certification, and surveillance audit plan, present evidence of past privacy governance audits, and show a robust escalation matrix for service support during and after audits.
The tender specifies non-disclosed dates in the data provided. Bidder should monitor UIDAI tender portal for submission deadlines, ensure all required documents are ready, and validate EMD submission via online or bank transfer before the closing time.
The tender does not detail explicit payment terms; bidders should anticipate standard government payment practices after audit acceptance and certification stages, with milestone-based payments aligned to schedule completions and acceptance of surveillance audits.
Acceptable proofs include contract copies with invoices and bidder self-certification, client execution certificates stating contract value, or third-party inspection release notes confirming audit or certification work completed.
Prepare a structured audit plan covering initial and surveillance phases, demonstrate privacy governance controls, document evidence collection procedures, and present a clear non-conformity resolution process to align with ISO 27701:2025 requirements.
Scope includes Initial, Pre-Assessment, Certification, Surveillance audits (1st and 2nd post-certification) for Privacy Information Management System under ISO 27701:2025, with multi-stage validation and ongoing surveillance to maintain certification status.