Back to Resources

Procurement resource

Law Enforcement AI RFP Security Checklist

Questions for evaluating governance, data handling, deployment, identity, auditability, AI safeguards, operations, and contract evidence.

How to use this checklist

Ask vendors to answer for the exact product tier, deployment, model providers, and services being proposed. Request written evidence and assign each item to a vendor, hosting provider, or agency owner. This guide does not determine CJIS compliance or replace agency security, procurement, or legal review.

01

Governance and approved use

Define what the system may do, who owns each decision, and how exceptions are handled.

  • List the approved and prohibited use cases, incident types, report types, and user roles.
  • Describe the required officer and supervisor review steps before any draft is exported or submitted.
  • Identify the agency owner, security owner, operational owner, and vendor escalation contacts.
  • Explain how the agency can configure disclosures, acknowledgements, and acceptable-use language.
  • Provide a process for reporting, investigating, and remediating unsafe or inaccurate outputs.
  • Document how material model, provider, workflow, or policy changes are communicated and approved.
Owner: __________________Evidence: ________________Status: __________________
02

Data ownership and handling

Follow every category of agency information through processing, storage, support, and deletion.

  • Provide a data-flow diagram for notes, reports, policies, identity data, logs, backups, and telemetry.
  • Identify every hosting provider, model provider, subprocessor, region, and support-access path.
  • Confirm agency ownership of inputs, outputs, uploaded sources, configurations, and audit records.
  • State whether agency data can be used for model training, evaluation, or service improvement—and under what agreement.
  • Describe configurable retention, legal hold, export, deletion, backup expiration, and contract-termination procedures.
  • Explain how sensitive data is excluded from unnecessary diagnostic logs, analytics, and support tooling.
Owner: __________________Evidence: ________________Status: __________________
03

Deployment and infrastructure security

Evaluate the exact environment and service tier proposed for the agency—not a generic reference architecture.

  • Identify the agency-approved deployment options, network boundaries, regions, and tenancy model.
  • Document encryption in transit and at rest, key ownership, key rotation, and secrets management.
  • Describe network isolation, private connectivity, administrative access, and environment separation.
  • Provide vulnerability management, patching, penetration testing, and secure-development practices.
  • Explain backup, disaster recovery, restoration testing, availability targets, and service dependencies.
  • Map applicable CJIS Security Policy controls and clearly assign vendor, hosting-provider, and agency responsibilities.
Owner: __________________Evidence: ________________Status: __________________
04

Identity and access control

Ensure the agency can enforce its identity policy and least-privilege model.

  • Support agency-managed SSO through OIDC or SAML and MFA enforcement through the identity provider.
  • Provide role-based access for users, reviewers, administrators, security personnel, and support staff.
  • Describe provisioning, deprovisioning, role changes, session controls, and optional SCIM support.
  • Separate privileged administration from routine report-writing and review permissions.
  • Record and review vendor or support access, including approval, duration, purpose, and actions taken.
  • Explain controls for service accounts, API credentials, secrets, and machine-to-machine integrations.
Owner: __________________Evidence: ________________Status: __________________
05

Audit, transparency, and records

Require enough evidence to review use, investigate incidents, and support agency oversight.

  • List logged user, reviewer, administrator, authentication, export, configuration, and policy-source events.
  • Record timestamps, actor identity, source versions, model or workflow versions, and approval events where applicable.
  • Describe log integrity, access, retention, search, export, alerting, and integration with agency monitoring tools.
  • Explain how the agency can determine when AI assistance was used and which sources supported an output.
  • Provide procedures for responding to discovery, public-records, legal-hold, and internal-investigation requests.
  • Identify which records remain available after users, policies, models, or integrations change.
Owner: __________________Evidence: ________________Status: __________________
06

AI quality and workflow safeguards

Test how the system behaves when facts are missing, sources conflict, or a request falls outside scope.

  • Require human review and acknowledgement before export; prohibit automatic report submission.
  • Demonstrate how the system distinguishes source facts, user statements, retrieved material, and generated language.
  • Explain how missing, uncertain, contradictory, or unsupported information is surfaced without inventing details.
  • Provide citations, section references, and effective versions for policy or statute-grounded responses.
  • Document pre-deployment evaluation, ongoing monitoring, incident review, red-team testing, and known limitations.
  • Support agency testing with representative routine, complex, incomplete, adversarial, and policy-sensitive scenarios.
Owner: __________________Evidence: ________________Status: __________________
07

Integration, operations, and support

Confirm the system fits the agency's daily workflow and remains supportable after the pilot.

  • Describe RMS export or integration options, data formats, API controls, failure handling, and reconciliation.
  • Document how policy packs, templates, statute sources, and agency configurations are updated and versioned.
  • Provide implementation, training, administrator, help-desk, and escalation responsibilities.
  • Define uptime, support response, maintenance notice, incident notification, and recovery commitments.
  • Explain how usage, adoption, quality, supervisor returns, and user-reported issues can be measured.
  • Provide an exit plan for data export, configuration export, transition support, and verified deletion.
Owner: __________________Evidence: ________________Status: __________________
08

Contract and evidence package

Put operational promises into the agreement and retain evidence for the specific service purchased.

  • Attach the final architecture, data-flow, responsibility matrix, security controls, and subprocessor list.
  • Include data-use, training, ownership, confidentiality, retention, deletion, and support-access commitments.
  • Define breach and security-incident notification, investigation cooperation, and evidence preservation.
  • Require notice and approval terms for material provider, hosting, model, or control changes.
  • Document audit rights, assessment reports, remediation expectations, and recurring evidence delivery.
  • Validate the final requirements with the agency's CJIS Systems Officer, security team, procurement team, and counsel.
Owner: __________________Evidence: ________________Status: __________________

Reference material

LeoPen resource · Updated July 18, 2026