---
title: "An RFP Checklist for AI Platform Procurement"
slug: "rfp-checklist-for-ai-platform-procurement"
author: "ibl.ai Engineering"
date: "2026-08-19 16:00:00"
category: "Premium"
topics: "ai rfp, ai procurement, vendor evaluation, ai platform selection, data rights, evaluation criteria, ai sovereignty"
summary: "Twelve questions that separate AI platform vendors from services firms, plus the evaluation criteria to weight. Criteria that reward staffing depth get staffing-heavy proposals."
banner: ""
thumbnail: ""
linkedin: |
  If you're writing an RFP for an AI platform, the criteria you weight determine the proposals you get. That sounds obvious and it's routinely ignored.

  Weight staffing depth, and you'll receive staffing-heavy proposals — which is how you end up funding the construction of retrieval, guardrails, access control and audit logging that every organization needs identically.

  Twelve questions that separate a platform vendor from a services firm:

  1. Which capabilities do you have running in production TODAY?
  2. What proportion of proposed hours goes to foundational layers vs work specific to us?
  3. When does the first real workload serve real users?
  4. Do we receive source code, and under what licence?
  5. Can our own team modify and redeploy without you?
  6. Where is our data processed, and can that be air-gapped?
  7. Can we change the underlying model without rebuilding integrations?
  8. Who owns custom developments built during the engagement?
  9. What happens to inputs, outputs, embeddings and logs — and who certifies deletion?
  10. What's the acceptance criterion, expressed as a measurement?
  11. What does year three cost, including maintenance?
  12. What do we hold if this is cancelled in month nine?

  Questions 1, 4 and 12 are the ones that separate the field fastest.

  On ibl.ai the answers are: a platform in production today, full source under a perpetual licence, and you own all the code and the data — model-agnostic across any LLM, no per-seat pricing.

  #iblai #AgenticAI #EnterpriseAI #Procurement #RFP #AI
---

## The Short Answer

**An AI platform RFP should ask which capabilities already run in production, what the buyer holds at the end, and where data is processed — because those separate platform vendors from services firms. On ibl.ai the answers are a production platform, full source under a perpetual licence where you own all the code and the data, model-agnostic across any LLM, no per-seat pricing, deployable anywhere including air-gapped.**

Evaluation criteria determine the proposals you receive. Weight staffing depth and you will get staffing-heavy proposals, which is how organizations end up funding construction of infrastructure that already exists elsewhere.

The questions below are ordered by how quickly they separate the field. The first, fourth and twelfth do most of the work.

## What separates a platform vendor from a services firm?

Three questions, and they can be asked in a first meeting.

**1. Which of the capabilities we need do you have running in production today?** A platform vendor names a system and its deployments. A services firm describes an approach. Both are legitimate businesses; they are not the same purchase.

**2.

What proportion of the proposed hours goes to foundational layers versus work specific to us?** Foundational means permissions-aware retrieval, evaluation harnesses, guardrails, access control, audit logging and model routing — anything a competitor in your sector would need built identically.

If most of the hours land there, you are funding parity.

**3. When does the first real workload serve real users?** Answers measured in quarters mean construction. Ask what specifically is being built during that time.

We put numbers behind the second question in [our T&M vs owned-platform calculator](/resources/calculators/t-and-m-vs-owned-platform-calculator).

## What should the RFP ask about ownership?

Everything, explicitly, because defaults rarely say what people assume.

**4. Do we receive source code, and under what licence?** Perpetual, or term-limited? Full platform, or the custom layer only?

**5. Can our own team modify and redeploy without you?** Make this an acceptance test performed by your engineers, not a statement in a proposal.

**6. Who owns custom developments built during the engagement?** Funding development does not confer ownership. This is the clause most often discovered at closeout.

**7. What do we hold if this is cancelled in month nine?** A licensed platform on your infrastructure survives cancellation. A partially-built bespoke system does not, and the average abandoned enterprise AI initiative has $7.2M sunk into it.

## What should it ask about data?

Where it goes, what is derived from it, and who can certify its deletion.

**8. Where is our data processed, and can the deployment run air-gapped?** State any residency constraint as a requirement rather than a scored criterion, so proposals that cannot comply are not evaluated at all.

**9. What happens to inputs, outputs, embeddings and logs?** Embeddings derived from your data are the store most often forgotten, and the hardest to reason about after the fact.

**10. Who certifies deletion, in writing?** Certification is only as strong as visibility into the vendor's storage and backups. Where data never left your systems, you certify your own deletion.

For federal buyers this is becoming formal: GSA's draft AI clause would require Government Data to be segregated, deleted at contract conclusion and certified as deleted in writing — covered in [GSA's Draft AI Clause and What It Demands Architecturally](/resources/guides/gsa-ai-clause-552-239-7001-data-rights).

## What should it ask about the model layer?

Whether it is a component or a foundation.

**11. Can we change the underlying model without rebuilding the integrations?** If not, you have bought a dependency. Models are deprecated, repriced and updated on the provider's schedule, and behaviour shifts under prompts that worked last quarter.

Ask specifically whether the platform can serve open-weight models inside your own network, because that is what determines whether sensitive or high-volume workloads have anywhere to go.

**12. What does year three cost, including maintenance?** Every model release and protocol change is a funded backlog item for a bespoke system. Normalise all bids to total cost to a working outcome over three years, including any per-seat multiplier at your full headcount.

## How should the criteria be weighted?

Toward what persists after the engagement ends.

Demonstrated production deployments matching your deployment constraint. Rights actually offered, scored as a discriminator rather than a checkbox. Independent operability, verified by an acceptance test your own engineers run.

Model provenance and the ability to change models later.

And define acceptance as a measurement: a held-out evaluation set drawn from your own data with an agreed passing threshold.

Feature lists can be delivered while the system does not work, which turns acceptance into a negotiation — the point we make in [How to Write a Statement of Work for AI Infrastructure](/blog/how-to-write-a-statement-of-work-for-ai-infrastructure).

For ibl.ai the answers are short.

The platform is in production with 1.6M+ users from 400+ organizations, ships with the full source code under a perpetual licence on your infrastructure, runs any model including GPT and Claude, and deploys anywhere up to a fully air-gapped network — with no per-seat pricing.

The comparison against the firms usually bidding these RFPs is in [Who Should Build Your AI Platform in 2026?](/blog/who-should-build-your-ai-platform-gsi-lab-or-platform-vendor).

## Why does owning the AI stack matter?

**ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing — so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.**

- **You own all the code and the data.** Full source code under a perpetual license, running on your infrastructure. Not API access to someone else's platform — the stack itself is yours.
- **Model-agnostic.** Run any LLM — Claude, GPT, Gemini, Llama, Command, or your own fine-tune — and switch providers without rewriting the platform.
- **No per-seat pricing.** Usage-based billing against a budget cap you set. Cost tracks what your organization actually uses, not how many people you employ.
- **Deploy anywhere.** Your cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY — a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.
