The vendors to provide comprehensive, secure, and scalable debit/prepaid card management solution for the city.
- Solution must adhere to the following:
• Be program-agnostic, configurable, and scalable. Scalability refers to the number of City program participants requiring pre-paid debit cards.
• Support multiple departments simultaneously
• Allow for different eligibility rules and funding sources
• Provide secure financial controls and reporting
• Ensure compliance with all applicable federal, state, and industry standards
• The system shall support City-defined participant groups, vendors, merchants, and service providers without being limited to any single department or program area.
• The city anticipates an estimated 750 program participants will require cards at the outset, once the system is up and running. After that period, the number of participants requiring cards is subject to increase as the City scales up current programs or introduces new programs requiring cards. Proposers should note any limitations or caps on the number of cards that can be issued at any one time.
• The system shall achieve operational efficiency and value
• The system shall deliver effective, reliable, and timely services
- Card Management System Requirements:
• Support online and staff-assisted enrollment functionality.
• Allow secure upload, storage, and retrieval of documentation (if required by specific programs).
• Support role-based access controls for City staff, contractors, and participants. All administrative and user access must enforce MFA. SSO via SAML 2.0. Vendor must implement RBAC with least privilege defaults, session
timeout enforcement, and support for modern authentication
• Allow participants to access account information online or via mobile platform (balance, transactions, alerts).
• Provide real-time card balance verification
• Provide fraud monitoring, suspicious activity alerts, and card lock capabilities. Vendor must provide real time fraud detection analytics, anomaly detection, and alerting, with integration into the City SIEM via Syslog, API, or webhook. System must support continuous monitoring informed by industry fraud threat intelligence.
• Mobile App / Wallet Integration Security: Mobile app components must comply with the OWASP Mobile Top 10, implement device-level encryption, anti-tampering controls, certificate pinning, and secure storage for credentials or tokens.
- Reporting Requirements system must provide configurable, exportable reporting capabilities including (but not
limited to):
• Total number of participants (by program, if applicable)
• Active and inactive cards
• Cards issued and replaced
• Transaction-level reporting
• Funding loads and balance adjustments
• System access record retention, including log retention, tamper-proof log storage, and export capabilities for SIEM integration. Logs must include full event correlation identifiers.
• Fraud activity and dispute tracking
• Financial reconciliation reports
• Customizable reporting by department, funding source, or program
• On-demand and scheduled automated reporting.
Set up free email alerts and get notified when new government bids, tenders and procurement opportunities match your industry and location. Choose daily or weekly delivery.