Digital Manpower Augmentation
A Master Services Agreement response for IT digital skills, staff augmentation, specialist consulting, project delivery support and managed workforce services. A talent pool that connects strategy to execution, where every professional is augmented by an AI delivery platform.
×
This mandate is engaged at partner level, from day one
Paris, 6 August 2026,
To the Evaluation Committee, TPO Management Services,
Madame, Monsieur,
The Digital Manpower Augmentation mandate is, by its scale and its multi-year horizon, a standing commitment to the Authority's delivery capacity, not a one-off staffing contract. Our response combines one governed framework for both staff augmentation and fixed-price outcomes, an AI delivery platform behind every engagement, and audit-grade controls on every deliverable. We choose to back it with our own personal, direct engagement as partners of Forvis Mazars.
Kevin LE DENIC, Partner and Head of Technology, Data & AI Services for the UAE and France, personally commits to the technical solidity of this mandate: the AI delivery platform behind this response, the quality of every deliverable, and the audit-grade discipline this proposal describes.
Sylvain FREON, Partner and member of our Executive Committee, personally commits to the relationship itself: the escalation point of last resort for the Authority, and the sponsor who keeps this mandate visible at the highest level of the firm for its full duration.
We remain, Madame, Monsieur, at the Authority's disposal.
Kevin LE DENIC
Partner, Head of Technology, Data & AI Services · UAE & France
Sylvain FREON
Partner, Executive Committee Member · France
How this volume is structured
A compliance-first response, structured around the SOW
Structure, commitments, method
- A direct answer to each of the six commercial models, with the exact response elements listed in SOW §9.1.
- A role and seniority catalogue, mobilization SLAs, and replacement terms we are ready to contract.
- KPI commitments written against the Authority's own Performance Evaluation Certificate.
- Company profile, staff organization chart, sample profiles and sourcing evidence, as the RFP Terms of Reference and SOW Appendix B require.
- Method, organization and governance only. Every figure lives in the Volume II financial deck, sealed separately as the RFP requires.
How we answered
- Terms and conditions of the RFP are accepted without exception; we do not negotiate in a tender response.
- We only propose delivery patterns we run ourselves today, including the platform this portal runs on.
- Where the SOW asks for a recommendation, we recommend and explain the trade-offs behind it.
- No cost component is ever charged twice, under any model or combination of models.
A governed framework, activated Work Order by Work Order
The Authority is procuring a governed framework: commercial models, rate cards, onboarding controls, security requirements and performance obligations that turn future resource needs into controlled, auditable call-offs.
What the MSA establishes
- Six commercial models: Cost Plus, FTE / Fixed Monthly, T&M, Fixed Price, MSP (optional) and Rate Card / Hybrid.
- A pre-approved rate card and transparent cost-plus schedules for fast, controlled call-off.
- Work Orders, Resource Orders, Task Orders and Service Schedules as the only mobilization mechanism.
- Initial term of 12 months with options to extend.
Where it operates
- Government-controlled, security-sensitive, on-premises first.
- Delivery onsite at Authority premises in Abu Dhabi by default; remote or hybrid only with explicit written approval.
- The vendor acts as a controlled extension of the Authority IT function while carrying full employment administration.
- Variable demand: embedded resources, short-term specialists, project deliverables, urgent replacement capacity.
The SOW is a design brief, and it asks for judgment
The Authority's acceptance criteria
- MSA terms, rate cards, commercial models and governance approved by the Authority.
- Mobilization only under approved Work Orders; billing only after completed screening, security and onboarding.
- Timesheets, attendance, deliverables and monthly reports approved per the MSA.
- Replacement, offboarding, knowledge transfer and access revocation completed, with no open critical issues.
What we recommend
- Spine: Rate Card / Hybrid MSA with controlled Work Orders, so call-off is fast and pre-priced.
- People (staff augmentation): FTE for stable seats, T&M for variable demand and named-expert missions, Cost Plus for a dedicated multi-year capability where warranted.
- Outcomes (fixed price): Fixed Price on scope defined before signature, under a discovery-first doctrine.
- MSP: an optional tower, priced and KPI-gated, activated only by Work Order.
One framework, absorbing both worlds.
Long-term embedded capacity and outcome-based delivery live under the same governance, the same reporting and the same ceiling, so the Authority chooses the model at each Work Order.
A top-ten global network built on exactly two members
Two members, one signature
- Forvis Mazars Group SC, an integrated international partnership operating in over 100 countries and territories, and Forvis Mazars LLP in the United States. There is no third member.
- Roots in France in 1945, an integrated international partnership since the 1990s, and a single global brand since June 2024.
- The firm audits over 1,900 public interest entities worldwide, including listed companies and financial institutions.
Seven lines, and this mandate sits squarely in one
Financial Audit · Tax, Law and Legal · Financial Advisory Services · Consulting · Accounting Expertise and Assistance · Actuarial and Quantitative Finance · Technology, Data and AI
Technology, Data and AI is the line that fields this mandate. Because it sits inside an audit firm rather than beside one, the evidence and documentation standards of the next four slides are not an overlay on delivery. They are the delivery method.
From fewer than 100 to more than 1,100 digital professionals in five years
Advise and transform
- Data-driven transformation: target operating models, data strategy and governance, then the delivery that follows the decision rather than stopping at it.
- Data university and tailored training: structured knowledge transfer to client teams, which is how the SOW's knowledge-transfer obligation is met rather than promised.
Build and run
- Usecase factory and software engineering: applications and products built to a repeatable delivery pattern, from backlog through release, with acceptance evidence at each step.
- Cloud, data engineering and DevOps: platforms, pipelines, CI/CD and release automation, on the client's own infrastructure choices rather than ours.
Analyze and decide again
- Analytics engineering: modelled, tested and documented data products that reporting and dashboarding teams can rely on without rework.
- Data science and AI projects: model development and industrialization, with the traceability an audit firm expects of anything that informs a decision.
One practice, fielded from a global network of engineering hubs
Delivery Lead · Data Product Ownership · Data Engineering and Architecture, DevOps · Software Engineering · Analytics Engineering · Data Science · Business Data Analyst. Where these specialists sit, and which hub fields this mandate, is next.
A dedicated Technology, Data and AI engineering hub in the Emirates
An engineering culture, maintained on purpose
We adapt to your technology stack and advise according to your context
We respect the client's technology choices. Transverse architects frame the requirement against the existing estate, then draw the right profiles from the centres of expertise. This is what makes the SOW's on-premises-first, government-controlled environment a normal starting point.
Deliverables designed for day-one maintenance
A DevOps culture is deliberately infused across the teams, on the principle that we produce software that is used in production. Maintenance and run concerns are designed in, not retrofitted at handover.
Peers train peers, on a ten-year knowledge base
For ten years the teams have crystallized what they learn on a collaborative platform, written by and for the technical consultants. That base is why a replacement inherits working context rather than a handover email.
Certifications that reflect real assignments
Consultants are expected to stay in permanent technology watch and to sit the certifications that evidence skills actually exercised on engagements, which is what the seniority framework in chapter 05 is built on.
A technical culture kept alive by practice, not by policy
A weekly Lightning Talk, in the manner of the open-source communities, where one team member shares the result of their own technology watch · annual participation in the major open-source gatherings such as FOSDEM, and in the Snowflake and Databricks summits · Python as the principal language for data processing, a conviction earned by working these problems since 2010 and by migrating deliberately from R as the libraries matured
Digital manpower should arrive augmented
What staffing vendors field
- A CV that matches keywords, mobilized alone.
- Productivity bounded by the individual: their templates, their memory, their habits.
- Knowledge leaves when the person leaves.
- Quality depends on who you happened to get.
Augmented professionals
- Every professional ships with our AI delivery platform behind them: accelerators, structured methods, reusable assets.
- Output is versioned, reviewed and documented by default, so knowledge stays with the Authority.
- Replacements inherit the full working context: history, decisions and assets.
- A single hire arrives with the platform's accelerators and assets from day one.
Strategy to execution, without the usual gap.
Because the same pool spans advisory, architecture and engineering, the person who frames the target operating model can be backed, same week, by the people who build it. The work moves without a handoff between firms.
Your control regime is our native discipline
What it means in delivery
- Every figure traceable to evidence: timesheets, acceptance records, cost build-ups.
- Working-paper discipline: decisions, assumptions and exceptions documented as we go.
- Independence culture: we tell you when a Work Order should not be Fixed Price, or when a cheaper model fits better.
- Long-cycle trust: audit relationships renew for decades because the controls hold up, engagement after engagement.
Where it lands in this MSA
- Cost Plus §5.1: where used, cost structure is disclosed by component and by seniority band, every line marked actual, provisioned, amortized, one-time or fee-included.
- Governance §8: the monthly report is a controls artefact: resources, pipeline, risks, SLA performance, financial consumption.
- Invoicing §11: invoices only against approved Work Orders, approved timesheets, accepted deliverables. This matches our own internal control standards.
- KPIs: we accept being scored on your certificate, category by category.
A small team on site, with a bigger one behind it
This is how we run our own delivery programmes. It keeps the daily team small and accountable, while the depth the work occasionally needs is drawn on rather than staffed permanently. Volume II prices it.
A deployed pod
Three named profiles, a designer, an architect and an engineer, held as full seats on the Authority's premises. They carry the delivery day to day and answer to the Authority's own priorities.
The same roles, mirrored centrally
Each deployed profile has a more senior counterpart in the central team, engaged part time. Architecture, design and engineering decisions get senior review without a second team being staffed or billed.
Fixed-scope assessments
Target Operating Model and Data Quality assessments, with fixed durations and written acceptance criteria. Ideal first Work Orders: small, dated, measurable. Priced in Volume II.
Why this matters to the Authority.
A pod this size can be directed like an internal team, while the mirrored bench means seniority is available the week it is needed rather than negotiated as a change. Every engagement also leaves assets behind: playbooks, pipelines and documentation that remain yours after the Work Order closes.
This portal is a working sample of augmented delivery
This response, the deck you are reading, the documents behind it and the portal serving them were produced by our own professionals working with BOB, our internal AI platform, in days rather than weeks. The same leverage mobilizes for your Work Orders.
Built as a product
- Secured portal: server-side login, domain allow-list, analytics, structured content surfaces.
- The full tender dataroom converted to structured, queryable documents.
- Deck, response documents and commercial model generated from one governed content spine.
The augmented workflow
- Content structured as versioned modules, tracked and searchable.
- Every change reviewed and tracked: pull requests, history, accountability.
- AI agents draft; our professionals direct, review and approve.
- This is the delivery model each augmented professional brings to your premises.
Staff augmentation for people. Fixed price for outcomes. One MSA for both.
The anatomy of a Work Order, and the rule that governs all of them
An execution plan, before anyone is mobilized
The Authority states the need. We return a concise execution plan: business objective, roles, scope, duration, commercial model, deliverables, assumptions, dependencies, exclusions, reporting requirements, acceptance criteria and closure procedure.
The gated sequence of §10
Sourcing, screening, CV submission, Authority interview, background verification, security clearance where required, then onboarding, in that order and against the service levels of chapter 06. Billing starts only after onboarding completes.
Evidence before invoice
Weekly operational reviews during mobilization, monthly service reviews in steady state. Deliverables accepted against written criteria. Change control in writing before scope moves. Invoices only against approved timesheets, approved Work Orders or accepted deliverables.
Nothing left open
Knowledge transfer, documentation handover, access revocation, final closure report and Authority sign-off. No Work Order closes with a critical security, compliance, commercial or performance issue outstanding.
Appendix A minimum content, present in every Work Order we accept
- Title
- Business objective
- Role or service requirement
- Seniority
- Duration
- Work location
- Commercial model
- Pricing basis
- Reporting line
- Deliverables
- Acceptance criteria
- Assumptions
- Dependencies
- Exclusions
- Security requirements
- Start date
- End date
- Approval authority
- Payment trigger
All six commercial models, answered as asked
| Model | What the Authority asked for | Our answer |
|---|---|---|
| Cost Plus | Open-book cost build-up: salary, statutory costs, benefits, margin, exclusions, total monthly cost | Cost structure disclosed by component and by seniority band, a single management fee agreed in the MSA, three-to-four-year minimum commitment, evidence on request |
| FTE / Fixed Monthly | Role, seniority, fixed monthly rate, included benefits, minimum term, replacement terms, notice period | Six-band catalogue, all-inclusive monthly rates built on a daily rate 5% below the T&M rate for the same band, 6-month minimum term, 30-day notice, replacement in 15 business days with interim cover in 5 |
| T&M | Hourly rate, daily rate, minimum billing unit, approval process, cap, timesheet method | An effort envelope approved per mission, one week to six months, published hourly and daily rates, half-day minimum unit, weekly timesheets with monthly approval |
| Fixed Price | Scope, deliverables, milestones, payment triggers, assumptions, exclusions, acceptance criteria | Discovery-first doctrine, a package catalogue priced in Volume II, milestone payments on acceptance, delay remedy mechanism included |
| MSP (optional) | Managed spend definition, MSP fee, governance scope, reporting, no duplicate charging, supplier management | Zero margin on third-party spend, a fee covering supplier qualification and governance only, S / M / L service packages, KPI-gated continuation |
How Rate Card / Hybrid applies across the models above
Every Work Order is called off through the Rate Card, pre-approved: it can run 100% on contractual daily or monthly rates (FTE or T&M), or as a hybrid combining a rate-based portion with another pricing model, Fixed Price for example, under one no-duplicate-charging rule.
When to use each model, and when not to
| Model | Recommend it when | Limitation: when not to use it | Cost control and risk mitigation |
|---|---|---|---|
| T&M | Missions of variable demand, one week to six months, on an approved effort envelope: investigations, advisory, reviews, named-expert interventions, where scope cannot be fixed honestly | Not for defined deliverables: it moves delivery risk to the Authority and gives no acceptance leverage. Beyond six months of continuous demand for the same person, it converts to FTE | Effort approved per mission and reviewed monthly, half-day minimum unit, billing only against approved timesheets, optional monthly cap per Work Order |
| FTE / Fixed Monthly | Stable, repeatable, long-term seats held full time onsite in the Emirates, for a minimum of six months, where monthly budget certainty is the priority | Not for demand under six months or for fluctuating workload: the minimum term becomes a cost with no output behind it | All-inclusive rate with nothing invoiced outside it, Authority interview before mobilization, no billing for absence beyond approved leave |
| Fixed Price | Defined deliverables and scoped programmes we own end to end, typically three to four quarters, fixed one quarter at a time, delivered by named consultants deployed on the Authority's premises | Not for ambiguous or evolving requirements: §5.4 forbids it, and a Discovery Sprint must define scope first | Delay remedy for unjustified vendor delay, milestone payment on acceptance only, change control in writing, warranty on every deliverable |
| Cost Plus | A dedicated capability held over three to four years, platform-shaped, where the Authority wants the cost structure of a standing team rather than an outcome | Not for short or bounded needs: a multi-year commitment on both sides only pays for itself as a standing platform, not a task | Cost structure disclosed by component and by seniority band, a single management fee agreed in the MSA, utilisation and exit terms fixed before mobilization |
| MSP | Third-party dependencies to source, contract and govern on the Authority's behalf: subcontractors, model and infrastructure vendors, integrators, one accountable point of contact | Not worth activating at small managed spend or with a single supplier: the governance layer costs more than it saves | Zero margin on third-party spend, fee limited to qualification and governance, KPI-gated continuation reviewed quarterly, activated only by Work Order |
How Rate Card / Hybrid applies across the models above
Every Work Order is called off through the Rate Card, pre-approved: it can run 100% on contractual daily or monthly rates (FTE or T&M), or as a hybrid combining a rate-based portion with another pricing model, Fixed Price for example, under one no-duplicate-charging rule.
One entry point, five models, one Work Order either way
Every step down in price is bought by a step up in commitment
| Billing basis | Commitment the Authority makes | What that commitment buys | Model |
|---|---|---|---|
| Hourly or daily rate | An approved effort envelope, one mission at a time, from one week up to six months | The highest unit price on the ladder: the Authority can stop at any point | T&M |
| Fixed monthly rate | A named seat, held full time, for a minimum of six months | A lower unit price than daily, bought by holding the seat rather than calling it off mission by mission | FTE / Fixed Monthly |
| Milestone payment on acceptance | A scope fixed one quarter at a time, delivered over a firm multi-quarter engagement | No unit price at all: the price is for the outcome, and we carry the delivery risk | Fixed Price |
| Open-book monthly cost statement | A dedicated capability held over three to four years | Full cost visibility, in exchange for a standing commitment on both sides | Cost Plus |
| Fee on approved managed spend | None beyond the Work Order; activated only where third parties are involved | One accountable interface above the supply chain, third-party cost passed through at actual | MSP |
How Rate Card / Hybrid applies across the models above
Every Work Order is called off through the Rate Card, pre-approved: it can run 100% on contractual daily or monthly rates (FTE or T&M), or as a hybrid combining a rate-based portion with another pricing model, Fixed Price for example, under one no-duplicate-charging rule.
Time & Materials, for work that cannot be scoped honestly upfront
What we understood
- The governing idea is approved effort: you decide upfront that a piece of work is worth an envelope, and only what is actually worked inside that envelope is billed.
- You want hourly and daily rates, a minimum billing unit, an approval process, a cap, and a timesheet method stated in advance.
- It applies where scope genuinely cannot be fixed honestly at the outset.
Our approach
- We use it for. Mission-shaped work of variable demand, from one week to six months: architecture and code reviews, investigations, advisory, support, named-expert interventions, and impact task forces stood up fast on an urgent, strategic issue. Not for defined deliverables, where it would move delivery risk to the Authority and give no acceptance leverage.
- Three shapes it covers. Missions staffed from our central team and centres of excellence, short named-expert interventions, and impact task forces: a dedicated multi-profile team mobilized within days on an urgent, strategic issue and released just as fast once it is resolved. All billed the same way: approved envelope, time worked at actual.
- The controls. Half-day minimum unit. No billing without an approved timesheet. Overtime only on prior written approval. Optional monthly cap per Work Order.
Our proposed terms
In practice: central expertise and named specialists supporting a running programme
On the AIN programme, taken here as an illustrative example, the forward-deployed team onsite carries the committed scope. Around it sits work that cannot be scoped a year ahead, staffed from the central team, and short interventions from a named expert, such as a two-day AI strategy or security review.
Each mission opens with an approved effort envelope and is billed at actual; if it needs less, the balance is simply not invoiced. Rates are quoted in the Volume II financial deck.
FTE / Fixed Monthly, dedicated seats at an all-inclusive rate
What we understood
- You want a named person in a seat, full time, for a role that will still exist next quarter, at a monthly rate you can budget against.
- You want role, seniority, included benefits, minimum term, notice period and replacement terms stated up front.
- Predictability is the point: one rate, nothing invoiced outside it.
Our approach
- We use it for. Stable, repeatable, long-term roles, for a minimum of six months. Held onsite by default; off-site on the Authority's express approval where the need calls for it. Not for demand under six months or fluctuating workload, where the minimum term buys a cost with no output behind it.
- Why six months. That floor is what turns a seat into a lower unit price than daily T&M. Shorter demand for the same person is better served, and priced accordingly, as a T&M mission.
- The terms. Six bands, Junior to Advisory. Minimum term 6 months, notice 30 days. Authority interview before mobilization. Replacement in 15 business days, interim cover in 5, at no cost when the cause is ours. No billing for absence beyond approved leave.
Our proposed terms
In practice: standing seats on an enterprise application programme
The Authority is implementing a new enterprise application and needs two people held full time for the duration, not a mission team that comes and goes: someone to run the delivery day to day with the business, and an engineer on the data side. Both are roles that will still be there in twelve months, so both are seats rather than missions.
The Authority interviews both before mobilization, and the monthly rate covers everything: employment, payroll, WPS, benefits, administration and vendor management.
Fixed Price, only on defined scope
What we understood
- You want scope, deliverables, milestones, payment triggers, assumptions, exclusions and acceptance criteria fixed before signature, and the delivery risk carried by us.
- You want a remedy if we are late for reasons of our own making, and a warranty on what we hand over.
- SOW §5.4 rules it out where requirements are still forming.
Our approach
- We use it for. Defined deliverables: assessments against fixed durations, the standing Core Expertise Pool, and any process we have first framed through a discovery. Where scope is fuzzy, a Discovery Sprint defines it before anything is committed.
- Who is on site. Named consultants deployed on the Authority's premises for the engagement's duration, listed in the Work Order alongside the scope they own.
- What we will not do. Commit to milestones and penalties on work whose scope follows the Authority's backlog. That work is held as FTE seats and converts to Fixed Price once a discovery has defined it. Milestone payment on acceptance only, delay remedy, warranty at no cost (SOW §11).
Our proposed terms
In practice: where Fixed Price applies, and where it does not
Fixed Price is signed on scope we can define before signature. A forward-deployed pod is not that: its scope follows the Authority's backlog quarter by quarter, so it is delivered on held FTE seats and only converts to Fixed Price once a discovery has defined what is being committed to.
| Package | Mode | What the Authority buys |
|---|---|---|
| Work Order Discovery Sprint | Fixed Price · 2 weeks | Scope, milestones and acceptance criteria, producing a signable Work Order |
| Core Expertise Pool | Fixed Price · annual | A standing expert pool maintaining and evolving the delivered platform across the year |
| Assessments | Fixed Price · 18 to 30 days | Target Operating Model and Data Quality assessments against fixed durations and written acceptance criteria |
| Forward-deployed pod | FTE / Fixed Monthly | Not Fixed Price: scope follows the backlog, so the pod is held as FTE seats and priced in Volume II |
Cost Plus, a dedicated capability held over the long term
What we understood
- §5.1 describes a long-term embedded resource: an open-book cost build-up, salary, statutory costs, benefits, and an agreed management fee, margin or topping charge.
- Where the SOW leaves this open is who agrees that fee. We read it as fixed bilaterally in the MSA, not set unilaterally once the cost base is disclosed.
- It suits a dedicated capability the Authority wants engaged as a standing team, not scoped mission by mission.
Our approach
- We use it for. A dedicated capability built for the Authority and held over three to four years, platform-shaped rather than scoped like a Work Order.
- What we disclose. Cost structure by component and by seniority band, evidence available on request per §5.1. Individual salaries are not disclosed; a shared platform is priced by role, not by person.
- What it implies both ways. Holding a dedicated team is a standing cost, so utilisation and exit obligations are fixed in the Work Order before mobilization, not discovered later.
Our proposed terms
In practice: a standing platform capability, not a mission
Where the Authority wants a dedicated team built and held for a platform's operational life rather than called off mission by mission: a standing group of engineers and specialists, embedded for the duration, with the cost base of every band open to inspection every month.
Because the commitment runs three to four years, utilisation risk and exit terms are agreed with the Work Order before mobilization, not discovered at the point of scaling down.
This model is not developed in detail within this MSA response. Should the Authority wish to operationalize it, standing up a platform of this kind in good and proper form is a separate engagement, outside this MSA's scope.
MSP, an optional governance tower activated by Work Order
What we understood
- You want one party accountable above several suppliers rather than managing each yourself: onboarding, rate compliance, consolidated reporting, SLA monitoring, replacement coordination.
- You want managed spend defined, the fee stated, and no duplication of charges already in direct resource rates.
- It is optional, and it activates only by Work Order.
Our approach
- We use it for. Third-party dependencies: specialist subcontractors, model and infrastructure vendors, integrators, hardware procurement. Not worth activating at small managed spend or with a single supplier.
- Three service packages, set by managed spend. Small, core governance. Medium, adds SLA monitoring, replacement coordination and quarterly supplier reviews. Large, a full vendor-management office. The package follows the spend band rather than being chosen, and the fee applies by slice of that spend.
- Fee and continuation. Third-party cost passed through at actual, zero margin. The fee covers qualification and governance only, lighter for an assessed preferred partner. Continuation reviewed quarterly against KPI thresholds.
Our proposed terms
In practice: contracting and governing a specialist subcontractor
On the AIN programme, taken here as an illustrative example, part of the platform work sits with a specialist open-source partner, NaasAI, whose core team the Authority would otherwise contract directly. Under the tower we hold that contract and consolidate reporting.
The same tower covers the rest of the supply chain: ontology specialists, infrastructure vendors, GPU procurement, application integrators, backed by our own global procurement scale.
Rate Card / Hybrid, the default spine for the whole MSA
What we understood
- You want role bands and rates pre-approved so a call-off takes days rather than a negotiation, with rate validity and an escalation cap stated.
- SOW §5.6 also allows a hybrid: combining Cost Plus, FTE, T&M, Fixed Price and MSP elements where the combination serves value, accountability or flexibility better than one model alone.
- With one condition attached: the same fee, benefit, payroll item, mobilization or governance cost is never charged more than once.
Our approach
- We recommend it as the spine. Six bands, rates firm for the initial 12-month term with any escalation capped and agreed at extension, call-off in days by Work Order, each Work Order naming the model actually used and the ladder step it sits on.
- Why it matters for a programme. A real programme rarely fits one box; the same person prices differently by model, since each step buys a different commitment. Hybrid mixes steps without re-negotiating each one.
- The one rule. A cost included in a monthly rate never reappears as a pass-through, a pass-through never carries the management fee twice, and MSP fees never apply to our direct resources.
Our proposed terms
In practice: the AIN programme, one rate card, four models
| Component | Model | Commitment made | Why this model |
|---|---|---|---|
| Forward-deployed pod | Fixed Price | Firm scope, quarter by quarter | Scope we own end to end, over consecutive quarters |
| Central and named expertise | T&M | Approved envelope, per mission | Reviews and named-expert interventions that cannot be scoped a year ahead |
| Specialist subcontractor | MSP | None beyond the Work Order | We hold the contract at cost, you keep one interface |
| Standing local seats | FTE | Six-month held seat | Optional, where a role outlives the programme |
Cost Plus is not part of this decomposition: it fits a capability held over years as a standing team, not a programme scoped in quarters.
From signature to steady state in ninety days
How to read this timeline
Bars mark the span of an activity; the four diamonds mark quarterly business reviews. Governance setup, rate-card activation and the security & onboarding framework run in parallel from signature so the first call-offs can mobilize inside month 1. Steady-state delivery, with its monthly and quarterly review rhythm, is reached by day 90 and repeats unchanged, Work Order after Work Order, for the life of the MSA. Exact dates are fixed per Work Order at signature; this chart is illustrative.
Proposed staff organization chart
Engagement Leadership
- The Engagement Partner and Executive Sponsor carry contract accountability and the technical solidity of every deliverable.
- They own the score on the Authority's KPI evaluation certificate.
- One-step escalation: the Executive Sponsor is the point of last resort, chairing the quarterly business review on request.
Delivery Management Office
- The Delivery Manager tracks progress on every ongoing project against its Work Order, running deliverable acceptance and change control.
- The Compliance & Reporting Officer produces the monthly budget-consumption report and the activity acceptance certificates the Authority validates, which trigger invoicing.
- These roles consolidate into one person, or spread across several as mobilized volume grows.
Talent Pool
- The Talent Pool Manager answers every staff-augmentation and resource-replacement request, coordinating Authority interviews.
- Delivered through the AI delivery platform, our tooled, incremental delivery method: accelerators, method assets and mission portals behind every band, at no rate premium.
- Staffed by people who also deliver on active projects, or held partly or fully apart from delivery as mobilized volume grows.
Ten capability areas, one accountable pool
Application Development
Backend, frontend, full stack, low-code, mobile
Quality Engineering
Manual QA, automation, SDET, SIT and UAT support
Integration & DevOps
APIs, middleware, CI/CD, Kubernetes, release support
Data & Analytics
Data engineering, BI, architecture, dashboards, platforms
Business Analysis & Product
Requirements, product ownership, process mapping
Infrastructure & Datacenter
Systems, virtualization, Nutanix, storage, network, DR
Cybersecurity
IAM, SOC, security engineering, vulnerability, GRC
Enterprise Applications
Oracle ERP, Odoo, Microsoft platforms, functional consulting
Design & Documentation
UI/UX, design systems, executive visualization, knowledge bases
Specialist Consulting
Enterprise, solution, security and data architecture advisory
Depth where the Authority signalled it matters.
The SOW names Oracle ERP, Odoo, Nutanix and Microsoft platforms explicitly. Our pool covers each, and our audit heritage adds a rare profile: technologists who can document, evidence and defend what they build in front of any review committee.
Six bands, defined in the SOW's own terms
| Band | Typical roles | Mobilization | Rate-based call-off |
|---|---|---|---|
| Junior | Developer, QA engineer, support engineer, technical writer | 2 to 4 weeks | T&M or FTE seat |
| Mid-Level | Full-stack developer, business analyst, data engineer, UI/UX designer, DevOps engineer | 2 to 4 weeks | T&M or FTE seat |
| Senior | Senior engineer, product owner, integration lead, security engineer, BI developer | 3 to 4 weeks | T&M or FTE seat |
| Lead | Delivery lead, squad lead, forward-deployed architect, ITSM lead | 3 to 5 weeks | T&M or FTE seat |
| Expert / Architect | Enterprise, solution, data, security and AI architects; specialist consulting | 4 to 6 weeks | T&M or FTE seat |
| Advisory (Partner pool) | Partner-level assurance, architecture escalation, independent review | Days, by call-off | T&M call-off only |
Every profile, verified before you see it
Technical screening, background verification and security pre-checks complete before CV submission. The Authority interviews, approves, rejects or requests replacement for every proposed resource. No billing before completed onboarding.
Augmentation is included in every band
Accelerators, method assets and platform support come with every band at no rate premium.
A controlled lifecycle, gated at every step
Continuity is built into every exit
- Overlap period between outgoing and incoming resource, handover notes and knowledge-transfer sessions run before the last day.
- Access transition and documentation transfer completed and evidenced, with performance monitoring through the change.
- Because delivery output lives on our platform in versioned, documented form, a replacement inherits the full working context rather than a handover email.
What we never bill
- No billing for unapproved, absent, rejected or not-yet-onboarded resources, in any commercial model.
- Replacement at no additional cost where the cause is our performance, resource unsuitability, resignation, or failure to meet agreed requirements.
- The Authority may reject any proposed resource before or during assignment, and we replace to meet or exceed the original requirement.
A service level with a named measurement method is stated for every stage of this lifecycle in chapter 06.
Trained centrally, incubated on our methods, deployed on-site
Why this matters to the Authority
A resource sourced from France, the Eastern Europe Centre of Excellence, or the Emirates hub delivers the same way, because it was trained and incubated the same way before mobilization. Consistency does not depend on which hub a profile is drawn from.
Kevin LE DENIC, Partner
AdvisoryProfile
A Partner with twelve years directing large-scale data and technology programmes, from strategy definition through organizational transformation to agile delivery of analytics products. Has governed portfolios of over fifty concurrent data projects and programmes at a time, and managed teams of thirty-plus. Serves as Engagement Partner on this mandate, carrying direct, personal accountability for programme delivery and quality.
Core skills
- Programme & Portfolio Management: direction of 50+ concurrent data projects and programmes, portfolio governance, delivery methodology assurance
- Data Governance & Quality: governance operating models, Master Data Management, data-quality diagnostics and remediation
- Organizational Transformation: target operating model design, stakeholder alignment across business and IT, change management
- Delivery Methodology: Agile / Scrum, iterative implementation, Design Thinking
Relevant experience examples
- Vallourec, Program Lead: directed the group's Data Factory programme, spanning a use-case portfolio, a federated data-governance organization and a unified cloud data architecture, Jul to Dec 2021
- Danone, Data Quality Programme Lead: directed the group's HR data governance and quality programme, from workshop-based scoping to an automated data-quality assessment solution, Jan to Apr 2020
- SNCF Réseau, Programme Lead: directed the Finance function's reference-data governance programme across four data domains, defining the operating model and data owners, 2019 to 2020
- BNP Paribas RISK, Innovation Programme Director: directed the RISK function's innovation programme, governing a portfolio of fifty-plus concurrent initiatives from ideation to implementation, coordinating with Group IT, 2017 to 2019
Why this profile fits this mandate
Twelve years directing large-scale data and technology programmes for regulated and public-sector organizations, exactly the programme governance discipline SOW §8 and §12 require. As Engagement Partner, this mandate carries that same personal accountability.
Alexis TOURNEUX, Architect & Delivery Lead
Expert / ArchitectProfile
An engineering-first data architect with six years across Data Engineering and Data Architecture, who takes a solution from framing to production and stays accountable for it. On one engagement, his redesign of a vector-search architecture cut retrieval time from 15 minutes to under one second at billion-scale level under resource-limited environments. Delivers in regulated, security-conscious environments where evidence and traceability are the standard, not the exception.
Core skills
- Data Engineering & Architecture: Data Vault 2.0 modelling, ERwin Data Modeler, Modelio, Mermaid, DAT authorship
- Languages: Python, SQL
- AI & ML: LLMs, LangChain, LiteLLM, n8n, RAG pipelines, vector databases (Qdrant)
- Cloud & DevOps: AWS, Microsoft Azure (Synapse Analytics), GitLab CI, GitHub Actions, Ansible, Terraform
- Web & BI: FastAPI, Django, VueJS, Power BI, Grafana
Relevant experience examples
- EDF R&D, Architect: architected and industrialized an AI-based visual search platform for industrial components across the group's plant network, optimizing retrieval from 15 minutes to under one second at billion-scale level under resource-limited environments, since 2025
- Allianz, Tech Lead / Data Architect: led the redesign of the France finance data platform on a Data Vault 2.0 model, automating around 250 ETL pipelines in Azure Synapse Analytics, 2023 to 2025
- TotalEnergies, Data Architect: designed and validated two successive cloud migrations for a production application, on-premises to Azure then Azure to AWS, against group security and cost standards, 2022
- Vallourec, Data Engineer & Architect: defined a unified cloud data lake architecture on AWS and delivered its first production use case end to end, since 2021
Why this profile fits this mandate
Exactly the Data and Analytics profile SOW §6.1 calls for, proven in regulated, evidence-driven environments comparable to the Authority's.
Majd CHAHINE, Lead Business Analyst
LeadProfile
A data-focused Business Analyst and Product Owner with six-plus years leading reporting, process-audit and reconciliation programmes for corporate functions, finance, HR and operations across a wide range of sectors. Pilots data teams end to end, from requirements workshops through to Power BI delivery and user adoption, with a track record of turning fragmented, high-volume data into governed, decision-ready reporting.
Core skills
- Business Analysis & Product Ownership: requirements engineering, process mapping, backlog management, user stories, UAT support
- Data & Reporting: Power BI, Tableau, Qliksense / QlikView, Power Query, MSSQL, SQL
- Automation & Platform: Power Apps, Power Automate, ETL, Azure
- DevOps & Delivery: GitLab CI, Jenkins, GitLab backlog and issue tracking, advanced Excel
Relevant experience examples
- L'Oréal, Project Manager / Senior Data Analyst: led the group's consolidation and reporting optimization programme, a Power BI solution with row-level security and around thirty KPIs across subsidiaries
- Auchan (overseas subsidiaries), Project Manager / Senior Data Analyst: led the reconciliation of accounting, ERP and payment systems down to invoice level across hundreds of millions of ledger rows, with a bespoke matching algorithm
- Air France, Project Manager / Senior Data Analyst: led a P2P process audit in the catering function, using OCR-based data reprocessing to reconcile orders, contracts and invoices at line-item level
- SNCF (Group Treasury), Data Product Owner: led the digitalization of drawdown-limit management and subsidiary exemption requests for 450+ subsidiaries, with a Power BI reporting layer for the treasury committee
Why this profile fits this mandate
Exactly the Business Analysis and Product profile SOW §6.1 calls for, proven leading data teams and stakeholder workshops for large, multi-entity organizations, including group treasury and finance functions comparable in governance weight to the Authority's.
Cherif DIALLO, Lead AI Engineer
LeadProfile
A Lead AI Engineer with seven years across Data Science, Machine Learning and Data Engineering, who leads GenAI and graph-analytics initiatives from architecture to production. Heads the firm's Data Science offering and serves as technical lead on AI and GenAI engagements, including four years embedded in a national energy operator's R&D division. Delivers in certified, security-accredited environments where data governance is non-negotiable.
Core skills
- Data Engineering & Architecture: Spark & PySpark, distributed computing, ETL orchestration, Cloudera CDP
- Languages: Python, SQL
- AI & ML: LLMs, GenAI, RAG pipelines, LangChain, Azure OpenAI, Neo4j Graph Data Science, NLP & OCR, MLOps
- Cloud & DevOps: Azure (AI Search, Azure ML), AWS, GitLab DevOps, Docker, CI/CD
- Web & BI: Streamlit, FastAPI, Power BI, BusinessObjects
Relevant experience examples
- Public water utility (overseas territory), GenAI Lead: scoped and led an AI initiative automating citizen request handling, an LLM chatbot, OCR document processing and a RAG assistant for agents, Nov 2025 to Feb 2026
- European Investment Bank, Lead Data / AI Engineer: leading an augmented dashboard and graph-intelligence platform combining Neo4j, NLP and generative AI to analyze EU public-procurement markets, since Sept 2025
- UNEDIC (national unemployment insurance body), Data Engineer: modernized data ingestion and monitoring on a certified Cloudera CDP platform (ISO 27001, RGS-accredited), coordinating with national institutional partners, since Dec 2024
- EDF R&D, Data Engineer & Scientist: industrialized an AI-as-a-Service platform indexing 28 million documents on the group's HPC supercomputer, Sept 2023 to Dec 2024
Why this profile fits this mandate
Direct experience embedded in certified, security-accredited public-sector data platforms and leading GenAI initiatives for public institutions, proof this Lead AI Engineer profile already operates at the governance and security bar this mandate requires.
Talel CHELBI, Cybersecurity Assistant Manager
LeadProfile
A Cybersecurity Assistant Manager with over twelve years spanning information systems audit, offensive security, application security, cybersecurity governance and security leadership. Began his career in 2013 auditing information systems, later led security as Head of Security for a company-wide HR platform, then moved to France in 2022 to lead application and offensive security engagements for major international organizations, joining Forvis Mazars Cybersecurity Center of Excellence in 2026.
Core skills
- Information Systems Audit & Governance: ISO/IEC 27001 and ISO 27005 risk-management audits, organizational information-security assessments
- Application & Offensive Security: white-box application security audits, DevSecOps adoption, business-critical web asset hardening
- Security Leadership: Head of Security for a company-wide HRIS, defining security strategy across development, operations and business teams
- Business Continuity & Awareness: business continuity management, cybersecurity training and awareness programmes
Relevant experience examples
- Sopra HR Software, Head of Security: led the security team and defined the security strategy for the company's HR Information System, 2018 to 2022
- Sanofi, Application Security Auditor: performed white-box application security audits and supported DevSecOps adoption, since 2022
- Galeries Lafayette, Offensive Security Engineer: strengthened the security of business-critical applications, websites and digital assets
- Banque Centrale du Congo and other central banks: cybersecurity audits and organizational information-security assessments
Why this profile fits this mandate
Twelve years spanning audit, offensive security, governance and security leadership for regulated financial institutions and critical national infrastructure, the same control discipline this mandate's security posture requires.
Mélanie RIVIÈRE, IT Organization Specialist
LeadProfile
An IT Organization Specialist with eight years in IT consulting for financial services, specializing in DSI economic performance, Cloud FinOps governance and strategic IT sourcing. Advises IT leadership on target operating models and steers complex, multi-vendor transitions across Pharma, Industry, Luxury and Banking/Insurance sectors, combining budget discipline with infrastructure continuity through ecosystem rationalization and contract security.
Core skills
- IT Financial Management: Cloud FinOps and GreenOps governance, chargeback/showback modelling, IT budget steering
- Sourcing & Vendor Management: strategic IT sourcing, contract negotiation, exit and reversibility strategy, AMS tender management
- Operating Model Design: target operating model definition, process optimization, governance design
- Programme & Project Management: multi-wave supplier transitions, stakeholder alignment, KPI framework design
Relevant experience examples
- Major insurance group, Resilience Advisory: supported business lines in defining and documenting exit strategies for critical service providers, and assessed exit-plan robustness against continuity requirements
- Global pharmaceutical group, Tender & Transition Lead: led a 20-plus vendor AMS consolidation tender with reversibility negotiation, then a 9-month, 3-wave transition to a single supplier across roughly 150 applications
- FinOps & GreenOps Operating Model: ran a multi-cloud maturity assessment and roadmap, then designed the FinOps operating model, roles, responsibilities and governance, with tracked optimization actions
- IT Performance & Budget Steering: defined tactical and strategic KPIs for Infrastructure, Data, Finance and VMO steering committees, and implemented chargeback/showback models securing allocation of 30-plus budgets
Why this profile fits this mandate
Direct experience designing IT operating models, sourcing strategy and vendor-management governance for regulated financial-services and pharmaceutical clients, the same operating-model and MSP discipline this mandate's commercial framework is built on.
Lilia FARAH, Forward Deployed Designer
SeniorProfile
A forward-deployed designer with a background in financial-services strategy and data-driven decision-making, now focused on stakeholder workshops, journey mapping and executive framing embedded with delivery teams. Carries the customer-experience and adoption thread from discovery through to production, on the ground with the client.
Core skills
- Discovery & Workshops: stakeholder, persona and journey mapping, executive framing, interview-led discovery
- Adoption & CX: documentation, adoption tracking, stakeholder confidence-building on new systems
- Operating Model: agile target operating model design, generative-AI advisory framing
- Strategy: M&A integration workstreams, customer-acquisition strategy
Relevant experience examples
- Major French bank, M&A Integration Consultant: led post-merger integration workstreams across a 28,000-plus employee, 11-million-customer bank, redesigning corporate relationship-manager workflows for a 35% efficiency gain
- Digital retail bank, Customer Acquisition Strategy: built acquisition strategies lifting outreach 30% and conversion 28%
- Banking squads, GenAI Advisory Co-Lead: co-led generative-AI advisory workstreams and designed agile target operating models for consumer finance
- Peace of Paper (founder): built a creative e-commerce brand to 150,000-plus organic followers, hands-on evidence of audience and product execution
Why this profile fits this mandate
Exactly the discovery, adoption and stakeholder-facing profile SOW §6.1 calls for, proven running workshops and journey mapping embedded on the ground for large, multi-stakeholder organizations.
Paul LE DILY, Software Engineer
SeniorProfile
A software and data engineer with five years building and industrializing data-processing applications for regulated institutions, with deep expertise in the banking sector. Comfortable across the stack, from ETL pipelines and Big Data architectures to the backend services and dashboards built on top of them. Mentors newer consultants and shares technical practice within the team.
Core skills
- Languages: Python, SQL, Java, Scala
- Data Engineering & Big Data: Spark, Airflow, DBT, Databricks, Data Lake / Data Warehouse design
- Cloud & DevOps: AWS, GCP, Docker, CI/CD, Git / GitLab, Jenkins, OpenShift
- Web & AI: Flask, FastAPI, Django, scikit-learn, PyTorch, NLP (BERT)
Relevant experience examples
- EDF, Software Data Engineer: designed and deployed an electrical grid monitoring solution for the French island networks, with a secured admin interface, in production on Google Cloud Platform, 2026
- Banque de France, Data Engineer: modernized the Big Data architecture and data processing for the Monetary Policy department, building a Data Lake and Data Warehouse, orchestrating pipelines with Airflow, and securing Shadow IT applications to align with technical standards, 2023 to 2026
- Odia, Data Scientist: built an NLP classification pipeline for news articles, including tone and emotion detection, 2022
- Neuflize OBC, Analytics Engineer / Analyst: rebuilt ETL pipelines and automated Power BI dashboards for the accounting function, restoring documentation and traceability of financial data, 2021 to 2022
Why this profile fits this mandate
Exactly the Application Development profile SOW §6.1 calls for, proven building and securing production data applications for regulated financial institutions, the same audit-grade discipline this mandate requires.
Mouheb BEN CHEDLY, Cybersecurity Consultant
Mid-LevelProfile
A Cybersecurity Consultant with over four years of experience in offensive security, penetration testing and digital forensics. Since 2022, has run external, internal, web application, desktop application and Active Directory penetration tests, PCI DSS assessments and SWIFT CSP reviews for banking, UN-agency and utility clients, with expertise validated by OSCP and CRTP.
Core skills
- Offensive Security: external, internal, web application, desktop application and Active Directory penetration testing
- Compliance-driven Testing: PCI DSS penetration testing, SWIFT CSP assistance
- Digital Forensics & Threat Intelligence: technical audits, digital forensics, threat hunting and threat modeling
- SOC & Incident Support: SOC assistance, investigation support
Relevant experience examples
- Société Générale (Cameroun, Congo): external and internal penetration testing across banking infrastructure, since 2022
- World Intellectual Property Organization: external penetration testing for a UN specialized agency
- Trinidad and Tobago Electricity Commission: web application, network infrastructure and threat-hunting engagements for a national utility
- Tunisian Foreign Bank, SWIFT CSP Assistance: security assessment against SWIFT Customer Security Programme controls
Why this profile fits this mandate
Offensive-security and penetration-testing depth answering the SOW's infrastructure and application security requirements, evidenced across banking, UN-agency and utility engagements comparable in sensitivity to this mandate.
Achraf BENNOUALI, AI Architect
Mid-LevelProfile
An AI Architect focused on getting systems running securely and operationally on customer infrastructure: platform design, CI/CD, deployment topology and LLMOps industrialization, so capabilities ship into production with observability, promotion criteria and rollback discipline. Sovereign by design, delivering air-gap-compatible, production-hardened systems rather than lab demos.
Core skills
- Platform & DevOps: CI/CD, deployment topology, Kubernetes, infrastructure as code
- LLMOps: Langfuse, MLflow, GPU inference optimization, vLLM, TorchServe
- Cloud: GCP, AWS
- AI & Data: production RAG (Milvus, Elasticsearch), agentic workflows
Relevant experience examples
- Forvis Mazars BOB Innovation & Standards Program, Platform & DevOps Owner: deployed client-facing data and AI products for L'Oréal, Sanofi, BMW and TotalEnergies, owning the platform and DevOps loop as primary technical interface to operational leads
- Leyton, Platform / MLOps Engineer: built production RAG (Milvus, Elasticsearch) and agentic workflows, with CI/CD and MLOps pipelines serving vLLM and TorchServe inference at scale
Why this profile fits this mandate
Exactly the Data and Analytics profile SOW §6.1 calls for, proven delivering sovereign, air-gap-compatible platform architecture in regulated environments comparable to the Authority's.
Abderrahmane EL AOUDI, AI Engineer
Mid-LevelProfile
An AI Engineer who hardens and encodes critical business processes into agent-executable systems: restricted-data integrations, access controls and sovereign routing that keep classified and air-gapped data under control, formalizing process ledgers and ontologies so agents run on validated operating practice.
Core skills
- Ontology & Knowledge Graphs: OWL2, SPARQL, BFO
- Multi-Agent Orchestration: LangGraph, MCP
- Security Engineering: access-based controls, restricted-data integration, sovereign routing
- Production Engineering: Kubernetes, FastAPI, OpenTelemetry
Relevant experience examples
- Forvis Mazars BOB Innovation & Standards Program, AI Engineer: deployed client-facing data and AI products for L'Oréal, Sanofi, Klepierre and Air France
- TotalEnergies, Ontology & Knowledge Graph Audit: led an audit-and-advise mission on ontology and knowledge-graph design for critical-assets maintenance and knowledge capture, improving adherence to BFO, alongside delivery for Finance, Audit and Operations
- Bleu (French sovereign cloud), RAG & Fine-Tuning Engineer: built RAG and fine-tuning pipelines under sovereign-cloud constraints, benchmarking model providers on accuracy, latency and cost
Why this profile fits this mandate
Exactly the Data and Analytics profile SOW §6.1 calls for, proven hardening AI systems for classified, sovereign-constrained environments comparable to the Authority's.
Evidence of sourcing capability
Energy · Data Science & AI framework
Public sector · Big Data platform
Energy · Data Platform staff aug.Sourcing channels
- Internal UAE bench. Consultants already resident and deployable, the fastest channel and the one that carries no visa lead time.
- Global network firms. Access to the wider Forvis Mazars network for scarce and specialist skills.
- Pre-qualified UAE subcontractor panel. Surge capacity and niche certifications, typically 2 to 4 weeks from approved requisition.
- Specialist recruiters. Security-cleared and scarce-skill profiles outside the internal bench, typically 3 to 6 weeks.
- Alumni and referral network. Known performers from prior mandates, typically 1 to 3 weeks when a named match exists.
How sourcing is evidenced
- Requisitions, submissions and interview outcomes tracked in our central recruitment workflow, the source of the candidate-submission service level.
- Technical screening under the FM digital skills assessment protocol, completed before any CV reaches the Authority.
- Background verification through accredited third-party providers, with security pre-checks recorded per candidate.
- Past-performance letters for the three named framework mandates below, plus completion certificates for priority sample profiles, accompany the sealed Volume I envelope.
EDF R&D (Électricité de France)
The mandate
A multi-mission framework covering computer vision (industry-grade OCR, image reverse-search engine), document AI processing (handwritten-date extraction and sensitive-document detection under GDPR), as well as Data Science algorithms development for churn and consumption habits detection. This framework is delivered with a high standard of quality and security, as a nuclear-sector client requires.
How the framework operates
- Call-off mechanism. Per-RFP SOW proposal, either outcome-based or staff augmentation, with dedicated project follow-up.
- Call-off lead time. 2 to 4 weeks from approved requisition to on-site start for embedded profiles; platform missions mobilize on a parallel technical track.
- Governance cadence. Monthly mission steering with EDF R&D delivery leads; quarterly portfolio review with framework owners and a written status pack.
- Service levels. CV submission within 5 business days of requisition; interview coordination within 10 business days; steady-state attainment above 95% on monthly reporting deadlines.
- Replacement. One no-cost replacement per seat per 12-month period under framework terms; exercised twice across the current framework term without service disruption.
Profiles supplied
- Data Architect (Expert / Architect band): visual-search platform, AI-as-a-Service industrialization, KPI dashboards
- Lead AI Engineer (Lead band): document AI (handwritten dates, sensitive-document detection), AI-as-a-Service industrialization
- Mid-Level Software Engineers (Mid-Level band): embedded staff augmentation
- Junior QA Engineer (Junior band): embedded staff augmentation
Relevance to this mandate
Sustained support for deploying industrial-grade AI solutions at group scale, grounded in solution resilience and scalability: for example, cutting retrieval time on the visual-search platform from 15 minutes to under one second at billion-scale level under resource-limited environments, and industrializing the group's first production AI-as-a-Service on an HPC supercomputer. The same framework discipline, security posture and call-off rhythm transfer directly to this mandate.
Unédic (France Travail's national partner for unemployment insurance)
The mandate
A Big Data modernization programme on a certified Cloudera CDP Private Cloud platform (ISO 27001, RGS-accredited), rebuilding ingestion pipelines and monitoring at scale, coordinating with national institutional partners including France Travail and GIP-MDS. Scope extends to data-quality control chains, drift and anomaly detection, and a migration roadmap toward Azure, alongside GenAI use cases such as LLM-augmented document analysis and automated ticket processing.
How the framework operates
- Call-off mechanism. Work orders issued by Unédic programme management against the framework ceiling; each seat named in the order before mobilization.
- Call-off lead time. 3 to 4 weeks from signed work order to on-site start for FTE seats on the certified platform.
- Governance cadence. Monthly service review with programme steering; written KPI pack covering pipeline health, data-quality metrics and open risks.
- Service levels. Monthly reporting on the fifth business day; data-quality incident response within one business day for priority-1 pipeline failures.
- Replacement. Replacement within 15 business days where attrition or performance triggers apply; not yet invoked on the current mandate.
Profiles supplied
- Lead Data & AI Engineer (Lead band): ingestion pipeline modernization, data-quality and monitoring, GenAI document-analysis use cases
- Mid-Level Data Engineers (Mid-Level band): pipeline build and monitoring runbooks, 2 resources
- Data Architect (Expert / Architect band): platform target architecture and Azure migration roadmap, advisory days
Relevance to this mandate
Rebuilt a certified, ISO 27001 / RGS-accredited data platform's ingestion layer and monitoring for a national public-sector institution, coordinating directly with sister institutional bodies. The same certified-environment discipline and multi-stakeholder coordination transfer directly to the Authority's framework.
GRDF (Gaz Réseau Distribution France)
The mandate
A framework agreement mandated by the Group CIO, primarily staff augmentation with select Fixed Price topics, on the group's Data Platform: Data Analytics and Data Engineering, PMO and Business Analyst reinforcement embedded with business teams, and enterprise architecture. Forvis Mazars piloted the group's Microsoft Fabric migration programme, and led a major Fixed Price project migrating a 200-report MicroStrategy estate to Power BI, proposing an innovative AI-agent-driven automated migration approach for it.
How the framework operates
- Delivery split. Staff augmentation seats run FTE onsite; variable, scope-not-fixed effort runs T&M offsite.
- Call-off and governance. Work orders issued by GRDF Data Platform PMO; monthly service review with programme steering; quarterly business review with Group CIO office delegates.
- Method, on the Fixed Price migration. Metadata-driven conversion via an intermediate pivot, decoupling MicroStrategy source from Power BI target.
Profiles supplied
- Data Analytics and Data Engineering, staff augmentation on the group's Data Platform
- PMO and Business Analyst reinforcement, embedded in front of business teams
- Enterprise architecture advisory
- AI-agent migration tooling team (Fixed Price), Microsoft Fabric migration programme piloting
Relevance to this mandate
The same staff-augmentation-plus-Fixed-Price shape as this mandate, CIO-mandated across Data Analytics, Data Engineering, PMO and Business Analyst reinforcement and enterprise architecture, with an innovative AI-agent-driven migration approach delivered on a Fixed Price project. The same programme-governance and innovation posture transfers directly to this mandate.
A fixed reporting rhythm, agreed up front
Operational reviews
Open requisitions, candidate pipeline, interview status, onboarding progress, blockers. Runs for every new Work Order until steady state is declared.
Service reviews
SLA and KPI performance, attendance and leave, timesheets, replacement status, risks and issues, financial consumption against the ceiling.
Business reviews
Trend analysis, improvement initiatives (at least two per year), rate benchmarking, demand outlook and lessons learned, documented.
The monthly management report, as specified in §8
Active resources · open requisitions · submitted candidates · interview status · mobilization status · attendance and leave · timesheets · replacement status · issues and risks · SLA/KPI performance · Work Order status · financial consumption · security and compliance observations. One document, every month, on the fifth business day.
Eleven service-level commitments, each with its measurement method
| Commitment | Target | How it is measured, evidence source | Authority KPI |
|---|---|---|---|
| Candidate submission, standard / scarce roles | 5 / 10 business days | Requisition timestamp against CV pack timestamp, listed per requisition in the monthly report | CVs submitted within SLA ≥95% |
| Mobilization, position filled, standard / scarce | 20 / 30 business days | Approved Work Order date against countersigned onboarding checklist completion | Positions filled within SLA ≥95% |
| Urgent request, first proposal | 48 hours | Timestamped urgent request register, extracted monthly | Urgent requests fulfilled ≥90% |
| Replacement, interim cover / permanent | 5 / 15 business days | Replacement record: notification date against replacement start date | Replacement within SLA ≥95% |
| Report submission | 5th business day | Delivery receipt of the monthly management report to the named Authority contact | Monthly reports on time 100% |
| Query response, acknowledgement / resolution plan | 1 / 3 business days | Query register timestamps, reconciled against the report each month | Risks and issues reported ≥95% |
| Timesheet submission | 3rd business day | Timesheet system export per resource after month end, attached to the invoice pack | Timesheets submitted 100% |
| Invoice accuracy | 100% first time right | Invoices accepted without query, over invoices issued, in the period | Invoice accuracy 100% |
| Issue escalation, acknowledgement at each tier | 1 business day per tier | Escalation log recording tier, owner and timestamp at each hop | Contract obligations fulfilled ≥95% |
| Offboarding, access revocation and documented KT | 100% before last day | Countersigned offboarding checklist and knowledge-transfer record | Offboarding completed 100% |
| Cost Plus open-book quotation, on written request | 10 business days | Request register timestamp against issue date of the build-up by seniority band and proposed management fee | Quotations issued within SLA 100% |
Score us on your form. We commit to every category.
| Evaluation category | Weight | Our operating commitment |
|---|---|---|
| 1 · Governance & Management | 10% | All governance meetings held, monthly reports on the 5th business day, 100% Work Order compliance, risks reported as they arise |
| 2 · Resource Mobilization | 20% | CVs in 5 to 10 business days, positions filled in 20 to 30, onboarding on schedule, replacement in 15, urgent requests proposed in 48 hours |
| 3 · Resource Performance | 20% | Technical competency verified pre-submission, attendance tracked daily, productivity evidenced in the monthly report, KT documented for every exit |
| 4 · Security & Compliance | 15% | NDA before any access, clearance before onboarding, least privilege enforced, zero-tolerance on violations, offboarding checklist 100% |
| 5 · Commercial & Reporting | 15% | Invoice accuracy 100%, only against approved Work Orders and timesheets, rate card compliance absolute, financial reporting monthly |
| 6 · Continuous Improvement | 10% | At least two improvement initiatives per year, corrective actions closed within agreed dates, lessons learned documented per Work Order |
| 7 · Customer Satisfaction | 10% | Quarterly satisfaction pulse, named engagement leadership accountable for the score, escalation path to partner level in one step |
Security defaults and employment compliance
The §7 defaults, operationalized
- Delivery onsite at Authority premises in Abu Dhabi; remote, offshore or hybrid only with explicit written approval.
- NDAs signed before any access to premises, systems, code, data or environments.
- No personal devices, public repositories, unapproved SaaS or remote-access tools. No exceptions without Authority sign-off.
- Least-privilege access, revoked immediately on role completion, replacement or termination.
- Security compliance checklist included in every monthly report.
Benefits, classified up front
- Included in monthly rate: visa and work permit, Emirates ID, medical insurance, leave salary, gratuity provision, payroll and WPS administration, workmen compensation.
- Billed at actual, pre-approved: family medical insurance where approved, incoming air ticket.
- Amortized over 12 months: annual air ticket provision.
- Held by us: professional indemnity and general third-party liability insurance, placed with insurers locally present in the UAE and submitted for TPO approval. Full insurance position on the next slide.
- No benefit, allowance or statutory cost invoiced unless in the approved schedule or Work Order.
The RFP's terms of reference match how we already operate
Terms of reference we already meet
- Validity. This offer remains valid and binding for 120 days from the submission date, with no change or withdrawal during that period.
- Payment. Payment within 30 days of correct invoice submission, on the terms the RFP states, against approved evidence only.
- Retention and DLP. Retention and its release schedule accepted exactly as the RFP states them, applied to fixed-price deliverable Work Orders, with a Defects Liability Period of one calendar year from primary handover.
- Advance payment. Any advance payment request stays within the RFP's stated ceiling and is secured by an unconditional bank guarantee of the same amount from a UAE bank.
- Delay penalties. The RFP's delay penalty formula and its cap are accepted as written, restated in Volume II, and applied per Work Order.
- Submission. Two sealed envelopes, Volume I and Volume II, one original each, endorsed with the tender name, reference and bidder name, addressed to the Tender Opening Committee, Abu Dhabi.
- Registration. Trade licence, municipal licence, Chamber of Commerce and professional registration and power of attorney accompany the submission, with a stamped copy of the RFP.
Cover approved by TPO, placed with UAE insurers
- Insurance procured and maintained at our sole cost, from a company approved by TPO, with insurers and policies satisfactory to the Owner, in force at all times while the contract is in effect.
- All policies endorsed to include the entire Area of Services and the full scope of Services. All premiums, deductibles and excesses are for our account.
- Any agent or subcontractor we engage is required to maintain similar insurance. Any deficiency in their cover or limits remains our sole responsibility.
- All insurances placed only with insurers locally present in the UAE.
- Workmen compensation insurance provided to the limit set by UAE Labour Law and the Workmen's Compensation Ordinance, Chapter 8 of Federal Law No. 1980 and subsequent amendments.
- Professional indemnity and general third-party liability held at firm level. Certificates of currency provided on request and on each renewal.
- Governing law and jurisdiction of Abu Dhabi accepted, with the Authority's sole discretion on arithmetic corrections and its right to request further information.
Two sealed volumes, one compliant package
Sealed separately, as instructed
- Method statement: the operating model, lifecycle and governance set out in this volume.
- Detailed bar chart programme for the 12-month term, in this volume.
- Company profile and staff organization chart, in this volume. Trade licence copy, authorized signature and power of attorney enclosed.
- Role catalogue, seniority framework and sample profiles for priority roles, in this volume.
- Sourcing capability evidence and references, in this volume.
- Insurance approach and the RFP compliance statement, in this volume.
- Stamped copy of the RFP enclosed.
Sealed separately, priced in full
- Form of Tender on letterhead, signed and stamped, governing every figure.
- Rate card, Cost Plus build-up template and package catalogue.
- Benefits and statutory inclusion/exclusion schedule.
- MSP and hybrid charging rules with the no-duplicate-charging guarantee.
- Detailed breakdown (BOQ) for variation orders.
- Presented in full in the Volume II financial deck.
After award: governance live in week one, first Work Order ready in week two.
MSA signature, governance calendar and reporting templates agreed, rate card activated, onboarding framework confirmed with Authority security, and a first call-off issued. The framework is operational within the first month.