What you need to know about High-Risk IT Procurements
An Overview
Under Section 2.2-4303.01 of the Code of Virginia, a high-risk contract is any contract that meets one of the following conditions:
-
It has an initial term exceeding $10 million
-
It has an initial term exceeding five million and meets one of the following criteria:
-
The public body has not procured the goods or services in the past five years
-
The public body intends to procure the goods or services jointly with another public body
-
The anticipated contract term is greater than five years, not including renewals
-
Under Section § 2.2-4303.01 of the Code of Virginia, the Office of the Attorney General (OAG) and the Virginia Information Technologies Agency (VITA) must review all solicitations and contracts that meet the definition of “high-risk” and involve information technology goods and services for all state public bodies.
The high-risk review process provides the following benefits to agencies:
-
IT solicitations and contracts are reviewed by OAG and VITA to confirm compliance with all applicable Virginia laws, policies, standards and guidance before release and award.
-
VITA ensures contracts include clear, measurable performance metrics and enforcement provisions, such as penalties or incentives, that support effective supplier performance management.
-
Agencies receive tailored guidance on templates, contractual clauses and industry best practices. This helps strengthen procurement documents and supports agencies in obtaining maximum value for the Commonwealth while minimizing risk. Reviews verify that solicitations and contracts include strong risk-management and mitigation measures to support smoother implementation and effective supplier-agency relationships.
-
VITA's review identifies operational, performance, security, legal, compliance and financial risks. Agencies receive a memorandum outlining any identified issues so they can address them before releasing the solicitation or awarding the contract or decide whether the risks are acceptable.
What do I submit for a high-risk review?
To submit a high-risk solicitation or contract for review, complete the following:
- Ensure the high-risk IT solicitation or contract is included in your agency's strategic plan and submit a business requirement for technology (BRT) request in Planview to begin the governance process:
- The request should be submitted by your agency's IT resource (AITR) or Planview designee.
- If this procurement involves new technology, submit a business requirement for new technology (BRnT).
- Confirm investment business case (IBC) approval.
- Submit a procurement governance request (PGR):
- PGRs should be submitted by your agency's IT resource (AITR) or Planview designee.
- The PGR will be approved by the VITA directorates and the CIO in Planview.
- Submit the high-risk IT solicitation or contract to VITA:
- The AITR or Planview designee will upload the complete document package in Planview.
- VITA's project management division (PMD) will begin the high-risk governance review process in Planview.
- VITA divisions, including supply chain risk management (SCRM), will download and review the document package.
- Once the Planview high-risk lifecycle review is received, VITA supply chain risk management (SCRM) will review the document package and provide feedback through comments and redlines:
- Submit your high-risk IT solicitation or contract review request to the Office of the Attorney General (OAG) at the same time.
- Complete the Office of the Attorney General high-risk review request form.
- Your agency must address any comments that indicate a critical risk or noncompliance with Section 2.2-4303.01 and resubmit the high-risk solicitation or contract with the required revisions for VITA to review:
- Issues or risks not addressed in the resubmitted documents will be documented in a risk memorandum and provide to agency leadership for review and signature.
- Before SCRM recommends CIO approval for solicitation release or contract award, SCRM must receive the signed OAG high-risk review form.
- The AITR will receive notification once the CIO has approved the request in Planview:
- Have your AITR take a screenshot of the CIO approval in Planview.
- Download the CIO approval screenshot and store the screenshot for the procurement file.
- You may proceed with posting the request for proposal (RFP) or awarding the contract only after formal CIO approval is received.
Yes. Contact your agency's IT resource (AITR) to ensure the procurement governance request (PGR) was submitted and approved by the chief information officer (CIO) of the Commonwealth of Virginia prior to submitting your high-risk solicitation or contract to VITA for review.
-
Visit the COV Ramp page for guidance on required oversight steps and the documentation your solicitation must include.
-
If any component of the high-risk IT solicitation involves cloud services, obtain a COV Ramp assessment form from the VITA service portal.
-
Search for cloud service assessment, then scroll to attachment for 1-1003 - Appendix A and download the form. The COV Ramp assessment must be attached to your solicitation and completed by offerors as instructed in the request for proposal (RFP).
-
Contact SCMinfo@vita.virginia.gov for the required cloud terms and conditions.
What help is available?
Assistance is available to agencies on high-risk solicitations and contracts. VITA procurement (supply chain management) offers training on the development of IT solicitations and contracts, IT contract terms, associated risks, statements of work, performance measures and service level agreements, project milestones and deliverables tables, negotiations and contract management. If there is interest in these topics, please email VITA procurement at scminfo@vita.virginia.gov.
VITA procurement recommends you ensure strong performance measures are included in your IT solicitation and contract. Performance measures are quantifiable metrics of expected service levels, and are the backbone of a successful contract. Performance measures should be tailored to provide accurate and reliable data on the supplier's performance against agreed upon service provisions. The metrics chosen should be able to correctly identify how well, and to what extent, the supplier regularly meets the expected levels of service outlined in your contract. Visit Chapter 30.3.1 Performance Measures of our IT Procurement Manual for additional guidance and examples.
Each performance measure should be tied to a corresponding enforcement provision. Strong enforcement provisions will incentivize the supplier to consistently meet the performance measures set out in the contract. Visit Chapter 30.3.2 Enforcement Provisions and Remedies of VITA’s IT Procurement Manual and the Performance Metrics Tool tool for additional guidance and examples. Also, see the performance measures training video.
Contractual remedies are a means to hold the supplier accountable in a tangible way for failing to meet required performance measures. They incentivize the supplier to consistently meet or exceed the contractually required performance measures. The remedies can be in the form of monetary penalties, or exercising contractual options such as termination or seeking neglected services from another supplier. Visit Chapter 30.3.2 Enforcement Provisions and Remedies of our IT Procurement Manual and the Performance Metrics Tool for additional guidance and examples.
VITA recommends that agencies include a project milestones and deliverables table in their solicitations and contracts. Please download the Project Milestones and Deliverables Template and follow instructions found in the word document.
Review Process and Timeframe
-
Per § 2.2-4303.01, SCRM has 30 business days to review a high-risk IT solicitation or contract. However, SCRM aims to complete reviews in fewer than 30 business days, depending on when the documents were received, the number of other high-risk review requests preceding your request and SCRM's overall workload.
-
Completion timeframes will vary depending on when the documents were received and the number of requests in process.
Your agency should upload the revised IT solicitation or contract documents into Planview for re-review. Please place all revised documents in a clearly labeled sub-folder so they can be easily identified.
-
Note: VITA reviewers do not receive notification when documents are resubmitted. You must contact us directly when a second or third version of the documents has been uploaded to Planview.
-
SCRM aims to review revised high-risk documentation within seven to ten business days of being notified by email that the revised documents are available in Planview.
-
Any issues or risks not addressed by the agency will be documented in a risk memorandum.
-
This memorandum will be sent to your agency to be circulated to your executive leadership so they can either ensure issues are addressed before release or award or make an informed decision on whether to accept the risk.
-
If leadership chooses to accept the risk, VITA will require your agency's leadership signature on the memorandum before releasing a recommendation to approve the solicitation or contract.
VITA and OAG work closely to help minimize the number of separate reviews an agency must undergo to receive approval for solicitation release or contract award. To support this, we offer an option for the SCRM and OAG high-risk review to occur simultaneously in a secure external VITA SharePoint site. To take advantage of this option, your agency must:
-
Reach out to the OAG directly to inform them that they can share their review notes and feedback with VITA.
-
Provide the names and email addresses of all agency personnel and the OAG representatives assigned to the high-risk review so they can be added as editing members of the SharePoint folder.
-
Upload documents to the SharePoint folder after receiving notification that the folder has been created.
-
Note: you will still need to submit the documentation through VITA's system of record, Planview, and follow OAG's standard submission process.
-
What if I have additional questions?
If you have any other questions, we recommend you review Chapter 30 High Risk IT Solicitations and Contracts of VITA’s IT Procurement Manual and other resources on this webpage. Also, see Procurement Policies and Forms and Tools on the VITA website under Procurement Policies & Procedures.
Questions and inquiries should be emailed to VITA procurement at scminfo@vita.virginia.gov. Your email will be forwarded to a member of VITA’s contract risk management (CRM) team for response. Additionally, you can locate the CRM team members on the Contact SCM page of the VITA website.
SCM can provide advice and consulting services
We are here to help you with your agency's high-risk IT solicitations and contracts. VITA procurement can provide advice and consulting services to agencies to assist them in preparing solicitations and contracts with the proper performance metrics and enforcement provisions, as well as other IT terms and conditions.
Agencies should notify VITA of an upcoming high-risk procurement by contacting scminfo@vita.virginia.gov. Information regarding the Office of the Attorney General's review of high-risk solicitations and contracts can be found at https://www.oag.state.va.us
Would you like to provide SCM feedback on its site?