Publication
Published/dedicated bid document dated 14 August 2026.
Loading…
Custom Bid for Services - Procurement of Audit Services for IT System Audit
Ministry Of Corporate Affairs · Mumbai Suburban, Maharashtra9758222
Written by TenderKart AI from the documents published when it was generated. Check the tender for later corrigenda before you bid.
14 Aug 2026
7 Sept 2026
₹1.5 Cr
₹7.5 L
All important dates as they stand after corrigenda: publication, pre-bid/clarification deadline, bid submission deadline, bid opening, and bid validity period.
Published/dedicated bid document dated 14 August 2026.
Written queries were due by 20 August 2026 at 3:00 PM; the pre-bid meeting was held on 24 August 2026 at 11:00 AM at SEBI premises.
Online bid submission closes 7 September 2026 at 3:00 PM; opening is 7 September 2026 at 3:30 PM.
Minimum 120 days from the submission deadline, stated as valid through 5 January 2027.
Tender value or estimated cost, EMD/bid security (amount, acceptable forms, validity), tender document fees, performance security, and key payment terms.
Estimated bid value is INR 1,50,00,000 inclusive of all taxes; it is guidance for EMD/eligibility and not a price benchmark.
INR 7,50,000 by NEFT/RTGS or bank guarantee; Medium enterprises pay INR 3,75,000, while eligible Micro/Small enterprises are exempt subject to valid MSME/Udyam proof and Form 15. NEFT/RTGS should be sent at least two days before closing; a physical BG must reach SEBI by bid closing.
The operative clause requires at least 120 days from bid submission. The prescribed BG form instead says at least 120 days beyond bid validity; this conflict is reported under contradictions and the safer BG validity is the longer form requirement.
No tender/bid participation fee is payable; GeM states that asking for one through buyer-added terms is impermissible.
Successful bidder must furnish an unconditional, irrevocable PBG for 10% of contract value inclusive of taxes within 21 days of award notification. It remains valid 120 days beyond all contractual obligations and carries a nine-month claim period after validity.
Quote firm base prices exclusive of GST, with taxes separately identified; amended L1 comparison uses total cost including taxes, change management and training. Payments are milestone/acceptance based, by NEFT/RTGS after TDS; no part-payment within a milestone.
Every pass/fail eligibility and qualification requirement: experience and past performance, turnover/net worth, registrations and certifications, consortium/JV rules, and debarment or blacklisting conditions.
Bidder must be an Indian company under the Companies Act 1956/2013 or LLP under the LLP Act 2008, operating for at least three years, with a registered office in India.
Bidder must not be blacklisted by any Government department, bank, PSU or other Indian institution for unsatisfactory performance, breach, corruption, fraud or unethical practices. Agencies debarred/blacklisted by Department of Expenditure/Ministry of Finance are not considered.
Bidder must have been CERT-In empanelled for at least three of the past five years and have at least 12 months residual empanelment from 31 July 2026; it must remain empanelled throughout the contract. Dis-empanelment can reject the bid/terminate and invoke security.
Bidder must have a back-to-back MoU/agreement with a separate known certification agency accredited by a recognized IAF accrediting body for ISO 27001:2022. Accreditation must have at least 12 months validity from 31 July 2026 and continue through the contract; replacement agreement is due within one month if accreditation is lost.
During the last seven years, complete either 3 similar projects of at least INR 8,00,000 each, 2 of at least INR 9,00,000 each, or 1 of at least INR 15,00,000, inclusive of taxes. MSME thresholds are respectively INR 6,00,000, INR 6,75,000 and INR 11,25,000. A completed project means at least one certification/recertification cycle.
During the last seven years, complete either 3 similar projects of at least INR 13,00,000 each, 2 of at least INR 16,00,000 each, or 1 of at least INR 26,00,000, inclusive of taxes. MSME thresholds are INR 9,75,000, INR 12,00,000 and INR 19,50,000 respectively.
Average annual turnover for the last three financial years ending 31 March 2026 must be at least INR 45,00,000; MSME threshold is INR 33,75,000. A banker-issued assignment-specific solvency certificate for INR 1,50,00,000 is mandatory. No net-worth threshold is stated.
Bidder must not have been SEBI's application implementer, solution/service provider or auditor (including VAPT/system/cyber/ISO) during the previous one year, and must be separate from the ISO certification agency.
Joint venture, collaboration and consortium bids are not accepted. A bidder from a country sharing a land border with India is eligible only if registered with the Competent Authority.
Only mandatory-eligible bidders proceed. They must obtain at least 75/100 in each converted section A and B, at least 65% in each subsection, and at least 150/200 overall before conversion; client references/site visits must be arranged within 30 calendar days of bid opening or the bid may be disqualified.
Separate full-time-payroll resources must be deployed onsite; minimum ISO team is one each Lead Auditor, Lead Implementer, Junior Auditor and Junior Implementer, with specified degrees/certifications/experience. System/cyber resources likewise must meet Table 15, and SEBI may reject/interview profiles.
What is being procured: the work, supplies or services, deliverables and quantities, locations, phases, completion or delivery timelines, applicable standards, and notable exclusions.
One indivisible engagement covering three annual cycles from FY 2026-27 through FY 2028-29: ISO 27001:2022 recertification/maintenance, IT systems audit and cybersecurity audit. Partial-scope bids are not allowed.
Year 1 includes scope/plan, gap and risk assessment, document updates, internal audit, corrective-action handholding, external recertification and certificate award; years 2-3 include internal and external surveillance audits and continued certification.
Annual audit covers implementation of all current and later-approved SEBI IT policies, implementation/fault-isolation/insurance processes and best practices. Each cycle includes approach, document review, gap/risk assessment, project/LoB-wise audit reports, corrective-action handholding and one follow-on audit.
Annual cyber audit verifies SEBI CSCRF (20 August 2024 circular and later FAQs), policies, CIS controls v8+, CCMP and BIA; all 32 web applications are treated as critical and reviewed annually. VAPT execution is excluded, but VAPT compliance/evidence must be validated.
ISO scope covers Mumbai primary DC and Chennai DR, including SOC/NOC at both; the pre-bid ruling says all activities are onsite. Personnel are onsite for ISO certification/surveillance, IT systems and cyber audits/follow-ons.
Systems and CIS cyber sampling is at least 10% and representative; increasing the sample is not extra scope. Asset/application counts may grow 25% year-on-year within price. Additional LoBs/processes beyond 25% use prescribed unit rates, but aggregate change payment is capped at 25% of corresponding audit price.
Provide one-time classroom/physical orientation and one-year exam vouchers/material for 2 officers each for CISA/CISSP/CISM, CHFI/CRISC, and ISO 27001:2022 Lead Auditor; train up to 5 ISMS personnel annually for three years. Orientation is capped at five working days; bidder is not responsible for exam outcomes.
Delivery starts on agreement signing. First-year ISO milestones run to 24 weeks; later surveillance cycles to 20 weeks from annual initiation. IT/cyber approach is due within 3 weeks, with follow-on within 30 days after SEBI's corrective-action completion. Each annual audit's two phases must finish within 12 months.
The complete checklist of documents to submit — mandatory vs conditional, with any prescribed formats, proformas or annexures — plus how to submit: portal and mode, envelope/cover structure, digital signature requirements, signing and attestation rules, and physical originals with their deadline.
Submit Part I technical and Part II price bids electronically on GeM; physical tenders are not accepted. Commercial information must not appear unmasked in the technical bid.
Every online document must be digitally signed by the authorized signatory. Pages must be sequentially numbered with a contents list; physical documents must be in indelible ink, corrections initialled, and every physical page initialled/stamped.
Physical original EMD BG, if used, must reach the C-7 SEBI Bhavan II address by bid closing in the prescribed sealed envelope. The Integrity Pact original must also be delivered physically; the minutes urge delivery well before closing, but the RFP does not state an unambiguous deadline—seek confirmation.
Every corrigendum/addendum in order — what changed (original vs amended value), its impact, and the action for the bidder — ending with the values that finally apply.
On 27 August 2026, Corrigendum GEM/2026/B/7919550-C1 superseded all earlier buyer-added bid-specific terms and attached the revised ATC/RFP plus pre-bid minutes/responses. Bidders must use this 202-page attachment rather than the repeated 175-page originals.
Clause 1.6.2(a) changed the EMD bank name from ICICI Bank Ltd. to Bank of India; the Bank of India IFSC/account shown in the RFP therefore align with the amendment. Bidder action: use Bank of India and verify beneficiary/account before transfer.
L1 changed from total audit-service cost to total audit-service cost including taxes, still including change management and training. Bidder action: ensure GST and every priced component are correctly entered because tax-inclusive total decides L1.
The underlying 200-mark thresholds remain: 75 in each A/B section, 65% in each subsection and 150 overall; scores are proportionally converted to GeM's 100-mark scale, with 50 marks per section and 75 overall qualifying. Bidder action: meet the original granular thresholds, not merely the portal total.
Pre-bid responses distinguish Micro/Small enterprises (full EMD exemption under GeM GTC with valid MSME/Udyam certificate and Form 15) from Medium enterprises (50% EMD, i.e. INR 3,75,000).
All activities are onsite; all 32 web applications are reviewed annually and treated as critical; VAPT execution is excluded but VAPT compliance validation remains; certification exam results are not the bidder's responsibility. Increased audit samples beyond 10% are not additional scope.
No partial-scope bid is allowed; the draft MSA is final and non-negotiable; normally one revalidation audit occurs per annual cycle; substantial report-format changes notified before audit are not extra scope; client-reference visits must be arranged within 30 days of opening and non-compliance may disqualify.
Closing/opening remain 7 September 2026 at 3:00/3:30 PM; bid validity is 120 days through 5 January 2027; EMD is INR 7,50,000 (subject to clarified MSE/Medium treatment); PBG is 10%; contract is three years; L1 is tax-inclusive; revised ATC and all pre-bid rulings apply.
Genuine conflicts within and across the documents (original vs corrigenda, clause vs annexure, tender document vs BOQ): both sides with citations, and which value prevails.
The RFP account table says ICICI Bank Ltd. even though IFSC BKID0000122 points to Bank of India; Corrigendum 1 expressly changes the name to Bank of India. Bank of India prevails.
Clause 1.6.2(g) requires EMD for at least 120 days from proposal submission, while mandatory Form 10 requires the BG to be valid at least 120 days beyond the 120-day bid-validity period. For a BG, follow the stricter printed Form 10 (effectively at least 240 days from closing) unless SEBI confirms otherwise.
Mandatory eligibility and Form 18 require at least 12 months residual validity from 31 July 2026, but the technical compliance sheet asks for validity six months beyond the 120-day proposal validity (a different endpoint). The repeated mandatory criterion and Form 18 are more specific; use the 12-month residual requirement and continued empanelment.
Clause 1.6.2(d) sends the physical BG to SEBI Bhavan II, C-7, while the prescribed BG form is addressed to SEBI Bhavan, C4-A. The physical-submission clause is purpose-specific and prevails for delivery: use C-7; retain C4-A in the beneficiary/addressee text only if the bank form requires it.
The EMD-forfeiture text says security is due within 21 days from contract signing, while the dedicated PBG clause says within 21 days from award notification. The dedicated security clause prevails: count 21 days from award notification.
Only critical, tender-specific pre-bid queries that could materially change bid/no-bid, pricing, eligibility or contractual risk. Skip generic or obvious questions the documents already answer clearly.
Please confirm the exact minimum expiry and claim dates for Form 10: Clause 1.6.2 requires 120 days from closing, but Form 10 says 120 days beyond bid validity. This can determine bank pricing and bid responsiveness.
Please state the final deadline, recipient and delivery address for the original stamped Integrity Pact. The RFP requires a physical copy at the fact-sheet address and the minutes say 'well ahead' of closing, but no precise deadline is printed.
GeM's bid field says ePBG is not required, while the revised RFP mandates a 10% physical bank guarantee. Please confirm that no ePBG portal action is needed and identify the physical PBG submission address/acceptable issuing-bank mechanism.
SEBI's current certificate is valid only through 25 March 2027, while the year-1 recertification milestone allows 24 weeks from agreement. Please confirm the target agreement/recertification dates and responsibility for any gap in certification caused by SEBI approvals or delayed award.
The pre-bid response requires all activities onsite, but the scope expressly lists only Mumbai and Chennai DC/SOC-NOC sites. Please list every office/project location, expected working windows, access/background-check lead time and which travel must be priced.
Please confirm the correct BOQ row/table and worked billing rule for LoB/process growth: Clause 2.2.5 references both Table 20 and Table 17 and caps aggregate payment at 25%, which can materially affect pricing for mandatory scope growth.
Commercial, legal and execution risks a bidder should weigh: liquidated damages and penalties, unusual or one-sided clauses, tight timelines, and payment or security risks.
All work is onsite; every one of 32 critical web applications is annual scope; 10% sampling is only a minimum and any higher sample is not extra scope. Price staffing/travel and evidence access conservatively.
Up to 25% year-on-year asset/application growth must be absorbed in quoted year-2/year-3 prices. Growth beyond 25% is paid by formula, but total change payment is capped at 25%; bidder still must audit all required LoBs/processes.
No part-payment is permitted. Invoices require SEBI acceptance and signed milestone evidence; SEBI may withhold payments for bidder delay/default. Deemed acceptance is 30 business days for payment milestones and 40 business days for final acceptance, restarting after rejection.
Delay LD is 1% of the corresponding milestone per week or part; SLA credits include escalating ISO-agency delay penalties and report/support deficiencies. Combined LD/SLA is capped at 10% of annual payment, but delay may also trigger termination and PBG invocation.
PBG is 10% of tax-inclusive contract value, valid 120 days beyond obligations with a nine-month claim period; SEBI can invoke it for broad defaults, delay, improper performance, unauthorized assignment or loss and can require extensions.
Loss of CERT-In empanelment can reject/terminate and invoke security; only a three-month grace applies on expiry after current-year work. Loss of the ISO certifying agency's accreditation requires replacement within one month, with SLA penalty/termination risk.
Prices stay firm for the full three years despite exchange rates, inflation, market conditions or duty changes. Travel, out-of-pocket and most training-related costs are bidder-borne; only SEBI officers' training boarding/lodging is paid by SEBI.
SEBI says the draft MSA is final and no negotiations are allowed. Pre-notified substantial report-format changes are not extra scope, and all deliverable/report IPR rests solely with SEBI.
Resources need NDAs valid two years after contract end. Bidder indemnities cover broad losses, litigation costs, fines, confidentiality and third-party claims, recoverable from payments/PBG; liability cap excludes willful misconduct and third-party IP indemnity.
The inviting authority and relevant contacts: office, person, designation, address, phone and email — and which address receives physical submissions, if any.
Shri K Pavan Kumar, Manager, SEBI, SEBI Bhavan-2, Plot No. C4-A, G Block; phone +91-22-2644-9899; email [email protected]. Pre-bid queries: [email protected].
CGM-CISO (ITD-1), Securities and Exchange Board of India, SEBI Bhavan, Plot No. C4-A, G Block, Bandra Kurla Complex, Bandra (East), Mumbai 400051, India.
Chief General Manager–CISO (ITD-1), SEBI, SEBI Bhavan II, Plot No. C-7, G Block, Bandra Kurla Complex, Bandra (E), Mumbai 400051, Maharashtra, India.
HOD grievance email: [email protected]; buyer email: [email protected].