This Request for Proposals (this "RFP") is issued by Ontario Health as an invitation to prospective proponents to submit proposals for the procurement of an integrated risk management (Governance, Risk and Compliance Management) GRC solution utilizing Software-as-a-Service (SaaS) to be used by Enterprise Risk Management, Information Security Office, Digital Risk and Compliance, Privacy and other participating business units for the purpose of supporting project-level, business-unit level, department-level, portfolio-level and corporate level risk management along with compliance with regulations. For more details refer to Part 2 - The Services of this RFP document.
From an Enterprise Risk Management (ERM) perspective, all Business Units across Ontario Health (OH) are now required to maintain risk registers. Inefficiencies are being realized in manually flowing information between spreadsheets held by different parties and across the various reporting levels (project, program, departmental, portfolio and corporate-level risks). Ontario Health is seeking a more effective system to manage these risks. To derive full benefit from OH’s ERM program, the procurement of a Governance, Risk and Compliance (GRC) solution represents the next step in maturity for OH and will bring benefit to all departments.
The purpose of this RFP is to:
- Procure an integrated GRC solution utilizing Software-as-a-Service to be used by Enterprise Risk Management, Information Security Office, Privacy and participating business units for the purpose of supporting project-level, business-unit level, department-level, portfolio-level and corporate level risk management activities along with compliance to regulations.
- Have the Proponent facilitate the design and functionality workshops, implement business rules, configure risk register, reports, and dashboard.
- Have the Proponent perform the initial batch upload of OH control frameworks and existing risk registers.
- Train respective users in utilizing the solution (configuration, customization of reports, dashboard, etc.).