Enterprise AI Governance Administration

Location: Tennessee
Posted: Jun 15, 2026
Due: Jul 13, 2026
Agency: State Government of Tennessee
Type of Government: State & Local
Category:
  • 70 - General Purpose Information Technology Equipment (including software).
Solicitation No: RFI 31701-03847
Publication URL: To access bid details, please log in.
Document ID & Hyperlink: RFI 31701-03847
Event Start - Response Due: 06/15/2026

07/13/2026
Event Name: Enterprise AI Governance Administration
Last Updated:

Attachment Preview

Test Title

STATE OF TENNESSEE
FINANCE AND ADMINISTRATION, STRATEGIC TECHNOLOGY SOLUTIONS

REQUEST FOR INFORMATION

FOR

Enterprise AI Governance Administration

RFI # 31701-03847

June 15,2026

1. STATEMENT OF PURPOSE:

The State of Tennessee, Department of Finance and Administration, Strategic Technology Solutions (“State”) issues this Request for Information (“RFI”) for the purpose of seeking information from the vendor community regarding enterprise Artificial Intelligence (AI) Governance Administration platforms and related operational governance capabilities. We appreciate your input and participation in this process.

2. BACKGROUND:

The purpose of this Request for Information (RFI) is to:

• better understand the current AI governance market

• evaluate enterprise AI governance administration capabilities

• assess architectural approaches for operational AI governance

• understand integration capabilities across runtime governance, AI security, observability, and assurance ecosystems

• evaluate future-state readiness for evolving AI operational governance requirements

• and gather information that may inform future procurement strategies

The State recognizes that the AI governance market is rapidly evolving and that capabilities across governance administration, runtime governance, AI security, operational assurance, observability, and data governance may span multiple vendor categories and integrated platforms.

This RFI is focused primarily on enterprise AI Governance Administration capabilities, including:

• AI inventories

• governance workflows

• policy management

• risk classification

• approvals

• centralized governance visibility

• enterprise governance lifecycle management

However, the State also seeks information regarding each respondent’s ability to support or integrate with broader operational AI governance and assurance capabilities, including:

• runtime governance

• AI security & privacy

• prompt inspection

• runtime monitoring

• Human-in-the-Loop governance

• operational traceability

• telemetry

• provenance

• AI observability

• policy enforcement

• emerging assurance capabilities

The State is particularly interested in platforms that demonstrate scalable enterprise architecture, AI-native operational design, extensibility, interoperability, cloud and hybrid environment support, and the ability to evolve alongside rapidly changing AI technologies and regulatory expectations.

The State seeks to distinguish between administrative governance capabilities, operational runtime governance capabilities, AI security capabilities, and assurance-oriented capabilities.

Respondents should clearly identify currently available production capabilities, preview or roadmap capabilities, partner-dependent capabilities, and capabilities requiring custom implementation or engineering services.

The State may use information gathered through this RFI to inform future procurement decisions, refine governance operating models, evaluate architectural approaches, assess vendor maturity, and support development of future Requests for Proposal (RFPs) or related solicitations.

The State requests information in the following areas:

A. Company & Platform Overview

B. AI Governance Administration Capabilities

C. Runtime Governance & Operational Integration

D. AI Usage Intelligence, Cost Governance & Financial Accountability

E. AI Security & Risk Management

F. Auditability, Assurance & Observability

G. Human-in-the-Loop (HITL) & Autonomous Governance

H. Platform Architecture & Future-State Readiness

I. Integration & Interoperability

J. Public Sector & Regulated Environment Experience

K. Product Maturity & Production Readiness

L. Future Roadmap & Strategic Direction

3. COMMUNICATIONS:

3.1. Please submit your response to this RFI to:

Stephanie Landmark

Department of Finance & Administration

Strategic Technology Solutions (STS)

STS Business Operations - Contract Solutions

Stephanie.M.Landmark@tn.gov

3.2. Please feel free to contact STS with any questions regarding this RFI. The main point of contact will be:

Stephanie Landmark

Department of Finance & Administration

Strategic Technology Solutions (STS)

STS Business Operations - Contract Solutions

Stephanie.M.Landmark@tn.gov

3.3. Please reference RFI # 31701-03847 with all communications to this RFI.

4. RFI SCHEDULE OF EVENTS:

EVENT

TIME

(Central Time Zone)

DATE

(all dates are State business days)

1.

RFI Issued

June 15, 2026

1.

Written Questions and Comments Deadline

2:00 pm

June 26, 2026

1.

State Response to Written Questions and Comments

July 6, 2026

1.

RFI Response Deadline

2:00 pm

July 13, 2026

5. GENERAL INFORMATION:

5.1. Please note that responding to this RFI is not a prerequisite for responding to any future solicitations related to this project and a response to this RFI will not create any contract rights. Responses to this RFI will become property of the State.

5.2. The information gathered during this RFI is part of an ongoing procurement. In order to prevent an unfair advantage among potential respondents, the RFI responses will not be available until after the completion of evaluation of any responses, proposals, or bids resulting from a Request for Qualifications, Request for Proposals, Invitation to Bid or other procurement method. In the event that the state chooses not to go further in the procurement process and responses are never evaluated, the responses to the procurement including the responses to the RFI, will be considered confidential by the State. 

5.3. Responses should be prepared, with emphasis on completeness and clarity, and should NOT exceed thirty-five (35) pages in length, excluding title page. Responses, as well as any reference material presented, must be written in English, and must be written on standard 8 ½” x 11” pages and all text must be at least a 12-point font. Answers must be in Microsoft Word or PDF file format. All pages must be numbered.

5.4. The State may request Oral Presentations from RFI respondents.

5.5. The State will not pay for any costs associated with responding to this RFI.

6. INFORMATIONAL FORMS:

The State is requesting the following information from all interested parties. Please fill out the following forms. Respond N/A for capabilities not included in the product:

RFI #31701-03847

TECHNICAL INFORMATIONAL FORM

1. RESPONDENT LEGAL ENTITY NAME:

1. RESPONDENT CONTACT PERSON:

Name, Title:

Address:

Phone Number:

Email:

1. Company & Platform Overview

a. Provide a general overview of your company, ownership structure, leadership team, and AI governance platform(s).

b. Describe your organization’s experience supporting enterprise AI governance programs.

c. Describe your experience supporting public sector or highly regulated environments.

d. Identify primary industries and customer types currently using your platform.

e. Support model: support tiers, SLAs, and availability (hours/regions).

1. AI Governance Administration Capabilities

a. Describe your platform’s capabilities related to: AI inventory management, intake workflows, governance approvals, policy management, risk classification, centralized reporting, model registration, governance lifecycle management

b. Describe how your platform supports enterprise governance visibility and management across agencies, departments, or business units.

c. Describe how your platform supports governance policy management and policy lifecycle administration.

d. Describe how the platform supports exception, waiver, and risk acceptance workflows, including request, review, approval, denial, expiration, renewal, compensating controls, notifications, reporting, and audit history.

1. Runtime Governance & Operational Integration

a. Describe how your platform integrates with AI runtime governance, AI gateways, orchestration layers, guardrails, or operational AI monitoring systems.

b. Describe any runtime governance capabilities natively supported by your platform.

c. Describe support for: prompt inspection, runtime guardrails, runtime policy evaluation, operational monitoring, shadow AI detection, RAG governance, and autonomous AI operational controls.

d. Describe your platform’s approach to operational AI governance visibility and runtime telemetry integration.

e. Describe support for autonomous agents and agentic workflows.

f. Describe support for delegated authority models.

g. Describe support for execution-time policy validation.

h. Describe support for agent authorization boundaries.

i. Describe integrations with AI gateways and runtime control planes.

j. Describe where governance policies are enforced within the AI request lifecycle.

1. AI Usage Intelligence, Cost Governance & Financial Accountability

a. Describe your platform's capabilities for AI usage metering, token consumption tracking, API call tracking, model utilization monitoring, and operational usage analytics.

b. Describe how AI usage can be attributed to specific agencies, departments, business units, applications, projects, use cases, users, or cost centers.

c. Describe support for AI cost governance, including cost allocation, chargeback mechanisms, showback reporting, budget tracking, cost forecasting, usage-based budgeting, and financial accountability workflows.

d. Describe how your platform supports monitoring and reporting of costs across multiple AI providers, models, cloud environments, SaaS AI services, and AI platforms.

e. Describe support for configurable spending thresholds, budget controls, usage quotas, approval requirements, automated alerts, or policy-based spending restrictions.

f. Describe capabilities for identifying anomalous usage patterns, unexpected cost increases, inefficient model utilization, or unauthorized AI consumption.

g. Describe integration capabilities with enterprise financial, procurement, accounting, ERP, budgeting, and IT asset management systems.

h. Describe how governance policies can be linked to financial controls, procurement controls, budget approvals, or cost accountability requirements.

i. Describe available executive dashboards, reporting capabilities, and analytics supporting enterprise AI financial governance and portfolio oversight.

j. Describe support for forecasting AI consumption growth, budget planning, capacity planning, and long-term AI investment management.

k. Describe support for tracking AI costs and utilization across multiple agencies, departments, programs, and business units.

l. Describe capabilities for normalizing usage and cost reporting across multiple AI vendors, model providers, cloud platforms, and AI services.

1. AI Security & Risk Management

a. Describe how your platform supports or integrates with AI security capabilities related to prompt injection detection, model abuse detection, data leakage prevention, model poisoning protection, unauthorized automation prevention, and runtime threat monitoring.

b. Describe how your platform integrates with enterprise security controls, including identity providers, secure web gateways (e.g., Zscaler), DLP solutions, SIEM/SOAR platforms, endpoint protection, and network security tools.

c. Describe support for governance controls related to sensitive, confidential, restricted, regulated, and personally identifiable information (PII), including data classification, access controls, data residency, privacy governance, privacy impact assessments, and compliance requirements.

d.

e. Describe controls preventing sensitive data exposure through prompts, retrieval systems(RAG), training, fine-tuning, embeddings, logs, and agent workflows.

1. Auditability, Assurance & Observability

a. Describe your platform’s capabilities related to telemetry, operational traceability, provenance, drift monitoring, runtime monitoring, explainability, and audit readiness.

b. Describe support for: immutable auditability, evidence collection, policy traceability, output traceability, log integrity validation, signed logs, or cryptographic assurance mechanisms.

c. Describe any support for policy-as-code, deterministic policy enforcement, or verifiable runtime controls.

d. Describe how governance decisions are captured as evidence.

e. Describe how approval lineage is maintained.

f. Describe how policy decisions can be reconstructed during audits.

g. Describe support for evidentiary chains linking users, prompts, models, outputs, approvals, and operational actions.

1. Human-in-the-Loop (HITL) & Autonomous Governance

a. Describe how your platform supports human oversight and configurable autonomy for AI systems and agents, including review thresholds, approval workflows, confidence-based escalation, intervention, override capabilities, and policy-driven controls that determine when human review is required.

1. Platform Architecture & Future-State Readiness

a. Describe the architectural origins of your platform, including whether AI governance capabilities were originally designed as AI-native functionality, or added onto existing governance, workflow, GRC, ITSM, security, privacy, or data management platforms.

b. Describe: core architectural principles, modularity, extensibility, API strategy, event-driven architecture support, cloud-native architecture support, and telemetry-driven capabilities.

c. Describe how your platform architecture supports evolving AI operational governance requirements over the next 3–5 years.

d. Describe any architectural limitations, dependencies, or legacy constraints that may impact future AI governance scalability or adaptability in the various environments leveraged by the state: on-prem, private cloud, public cloud, and SAAS

e. Provide a high-level architecture diagram illustrating governance workflows, runtime integrations, telemetry flows, policy enforcement points, operational monitoring integration, and external system integrations.

f. Describe where your solution can reside. (i.e. cloud tenant, on-prem, vendor hosted cloud)

g. What percentage of engineering resources are dedicated to AI governance capabilities?

h. Describe the evolution of the platform architecture over the past three years.

i. Describe how the platform supports emerging agentic AI architectures.

j. Describe the largest AI governance deployment currently operating on the platform.

1. Integration & Interoperability

a. Describe integration capabilities with: AWS Bedrock, Azure OpenAI, hybrid environments, SaaS AI systems, SIEM platforms, identity systems, data governance platforms, AI gateways, and observability tooling.

b. Describe your platform’s interoperability approach across multi-vendor AI governance ecosystems.

c. Describe supported APIs, SDKs, event streaming, webhook support, or extensibility frameworks.

1. Product Maturity & Production Readiness

a. For all major capabilities identified in this response, indicate whether the capability is Generally Available (GA) / Production, Limited Availability, Preview / Beta, Roadmap, Partner-Provided, Custom Implementation Required

b. Identify which capabilities are currently deployed in production customer environments.

c. Identify any capabilities materially dependent upon specific cloud providers, proprietary ecosystems, model providers, or partner technologies.

d. Describe your product release cadence and approach to supporting rapidly evolving AI technologies and emerging threats.

e. Describe your approach to customer commitments, accountability, or at-risk arrangements related to capabilities and customer outcomes represented during procurement processes.

f. Provide examples of contractual accountability, service commitments, milestone validation, or production acceptance mechanisms used with customers.

g. Identify capabilities not currently available to all production customers.

h. Identify capabilities requiring separate products or third-party services.

i. Describe willingness to contractually commit to represented capabilities.

j. Describe willingness to tie capabilities to milestone-based acceptance criteria.

1. Public Sector & Regulatory Alignment

a. Describe your experience supporting FedRAMP, CJIS, HIPAA, FERPA, IRS Pub 1075, or similar regulated environments.

b. Describe support and configurability for audit readiness, public records retention, and regulatory reporting requirements.

c. Provide relevant public sector customer references where permissible.

1. Future Roadmap & Strategic Direction

a. Describe your strategic roadmap for evolving AI governance capabilities over the next 3–5 years.

b. Describe anticipated investments related to runtime governance, AI operational assurance, autonomous governance, AI security, explainability, policy-as-code, deterministic controls, and operational observability.

c. Please provide any additional information, recommendations, or considerations that may benefit the State as it evaluates future AI governance strategies.

COST INFORMATIONAL FORM

1. Pricing model — describe your high-level licensing/pricing approach (e.g., per user, per AI system, tiered), and key cost drivers.

ADDITIONAL CONSIDERATIONS

1. Please provide input on alternative approaches or additional things to consider that might benefit the State.

This is the opportunity summary page. It provides an overview of this opportunity and a preview of the attached documentation.
Daily notification on new contract opportunities

With GovernmentContracts, you can:

  • Find more opportunities and win more business
  • Receive daily alerts for all new bid opportunities
  • Get contract opportunities matched to your business
ONE WEEK FREE TRIAL

See also

Document ID & Hyperlink: RFP 34320-19527 Solicitation Notice Event Start - Response Due:

State Government of Tennessee

Bid Due: 8/14/2026

Bid Bid 08042026DEM High Yield Toner for Lexmark MX431 Deadline Date/Time: August 04,

Memphis City Schools

Bid Due: 8/04/2026

Bid Bid 08042026DEM High Yield Toner for Lexmark MX431 Deadline Date/Time: August 04,

Memphis City Schools

Bid Due: 8/04/2026

Event 32701-13950 Terms and Conditions Specifications PreBid Memo 07/13/2026 08/11/2026 Indian Mountain SP

State Government of Tennessee

Bid Due: 8/11/2026

* Disclaimer: Information regarding bids, requests for proposals (RFPs), or requests for qualifications (RFQs) is provided on this website only for convenience and does not constitute official public notice. Persons wishing to respond to or inquire about bids, RFPs, or RFQs should contact the appropriate government department.