Skip to main content
DoneThat

AI Adoption GuideProcurementEvaluate

Compliance requirement extraction

NLP auto-extracts certification and regulatory requirements from the RFP and checks each bid for explicit compliance coverage.

Procurement processRequestApproveSourceEvaluateSelectOrderReceiveReview

By Don, DoneThat’s AI coach · updated

Pull the shalls from the pack you issued

The job is to extract mandatory certifications, licenses, and regulatory shalls from this event's issued RFP, then check whether each bid actually answered those rows. A missing certificate is a gap. It is not a fail until a named evaluator says so.

Do not extract from a clause library, last year's event, or a category list of typical credentials. The only source of truth is the pack bidders received, including addenda. If RFP/RFQ auto-drafting produced a first draft, still extract from the version that went out.

If the RFP does not name a standard, do not fill one in. "Quality management certification" is not permission to invent an ISO number. Write the shall as the pack wrote it, and mark bids against that wording.

Sourcing and bid-evaluation suites in the Inventive AI, Zycus, Jaggaer, and Coupa class already hold the issued pack and the bid room. Run the check on those files. Do not invent a second binder so a model can read a stale copy.

This is not proposal scoring against RFP criteria. Scoring weights quality, price, and approach. This grid answers a prior question: did they answer the mandatory rows at all.

Split certifications, licenses, and regulatory shalls

Three kinds of row, three kinds of evidence. Mixing them is how a footer logo becomes "certified" and a lapsed license becomes a quality score.

Mandatory certifications. Named certificates the RFP required, with the issuing body if the pack named one. Evidence is a certificate, a letter of conformity, or the exhibit the RFP asked for. A logo, a footer mark, and a slogan are not a certificate. A parent-company certificate does not cover the bidding entity unless the pack said it does.

Licenses. Jurisdiction-specific authority to do the work: contractor license, professional license, site permit, or whatever the issued pack named. Check the named jurisdiction, the class of work, and expiry relative to the start date in the RFP. A license for a different state is not found, not close enough.

Regulatory shalls. Discrete obligations: insurance evidence, prohibited practices, site rules, data-handling rules, restrictions on subcontractors. Extract each shall as a checkable statement. "Supplier shall carry appropriate insurance" is not checkable. Leave it as an ambiguous row and send it back to the author. Do not invent a dollar amount or a policy type the RFP never stated.

Write each row with the source citation, the exact shall or named credential, whether it is mandatory or scored, and what evidence the pack asked for. If the pack did not ask for an exhibit, say so. Do not invent Exhibit C because other events used one.

Addenda overwrite the base pack. If Addendum 2 drops a cert or changes an insurance shall, the grid follows the addendum. Checking bids against the pre-addendum list is how you fail a compliant bid and pass a silent one.

Mark each bid covered, not found, or contradicted

For each requirement row and each bid, read the narrative and the attachments. Mark one of three states. Do not invent a fourth called "probably."

Covered. The bid states the requirement and points to evidence that matches what the pack asked for. Cite the page or file. Covered means they answered this row. It does not mean the certificate is authentic or still current with the issuer. Verification is a human, and where policy requires it, a registry check.

Not found. No matching claim, and no matching attachment. Silence is the case reviewers miss when they skim. Report silence as silence. Do not infer coverage from "we take quality seriously," or from historical performance retrieval on a prior contract. Last year's file is not this bid.

Contradicted. The bid answers the row in two places and the answers disagree, or the claim disagrees with the attachment. Send contradicted rows to internal contradiction detection as well. Do not pick the friendlier sentence and mark covered.

ESG claims sit on a different path. ESG supplier screening classifies suppliers on sustainability and labor sources you name. Do not fold a missing carbon exhibit into this grid unless this RFP made that exhibit a mandatory shall.

The output is a matrix: requirement, bid, state, citation, and a suggested clarification question for every not-found and contradicted cell. The matrix is a worklist. It is not an award recommendation.

A missing exhibit is a gap until a human says so

Wire this to clarification, not to exclusion.

If a mandatory row is not found or contradicted, the default action is a written clarification that quotes the shall, cites the bid or the silence, and asks for the named evidence. The evaluator, or the person your event governance names, then chooses: accept the late evidence, score the gap, or disqualify under the published rules.

Do not let the model auto-disqualify. A missing exhibit can be a portal glitch, a file in the wrong envelope, or a bid that answered in the narrative and forgot the label. Disqualification is a governance act. It needs a named human, a timestamp, and the rule you are applying.

Do not let the model auto-pass on a logo, a parent-company certificate, or a certificate that names a different site. Covered is a citation you can open. If you cannot open it, it is not found.

Keep covered cells out of the fail pile. Teams that treat the whole matrix as a disqualification list stop using it.

Feed the finished grid into scoring as the compliance dimension once a human has closed the gaps they intend to close. Do not let a coverage percentage become the technical score. A bid can cover every mandatory cert and still lose on approach.

Trial this on a closed event first. Extract from the issued pack, map the bids you already scored, and compare cells to what the panel recorded. Disagreements are usually an ambiguous shall, a footer treated as a cert, or last year's PDF. Fix those before you put the matrix in front of a live panel.

Is this worth automating for you?

Whether this pays back depends on how much time it takes your team today. Most teams estimate that from memory, and the estimate is usually wrong in one direction or the other.

DoneThat reconstructs where the time actually went, with no timers to forget, so you can measure the baseline before committing to a project and check the gain afterward.

Measure the baseline first