Delivery governance
Roles, cadence, decisions, dependencies, commercial view and change control made explicit.
- Responsibility matrix
- Decision and change logs
- Risk and dependency view
- Progress and forecast
- Escalation path
Procurement
This page describes our approach to delivery governance, security, accessibility, quality, continuity and contracting. Assignment-specific requirements are confirmed in the tender response and contract.
Evaluation areas
The final response follows the buyer’s invitation to tender, evaluation criteria, contract terms and governance model.
Roles, cadence, decisions, dependencies, commercial view and change control made explicit.
Security requirements are defined with the solution and verified against its risks, data and operating context.
Legal baseline and target level are agreed early, then followed through design, code, content and acceptance.
Acceptance criteria, testing levels and release gates create traceability from requirement to result.
Interfaces, data flows and system dependencies are documented for implementation, testing and maintenance.
AI-enabled solutions need a defined purpose, data view, human oversight, logging, testing and known limits.
Support and maintenance are defined per service, including ownership, response targets and controlled supplier transition.
Responsible choices are connected to maintainability, efficient use of infrastructure and a longer useful service life.
The commercial model, applicable terms, acceptance, responsibilities and service boundaries are agreed per engagement.
Named experts are proposed only against a confirmed scope, with clear roles, availability and assignment-relevant evidence.
Security supplier view
Controls are defined against the system’s risks, data and operating environment. The structure follows the supplier questions published by Finland’s National Cyber Security Centre.
Open the official Traficom guidanceTender evidence
Evidence is provided against the criteria and format of each procurement.
Finnish public ICT context
The contract identifies the applicable JIT 2025 terms, buyer-specific conditions, security and data-processing annexes, service levels, acceptance and transition requirements.
Read the official JIT 2025 publicationTeam structure
The exact team, named experts and availability are confirmed for each procurement.
Market dialogue or active procurement
We will review the scope, evaluation criteria, risks and proposed delivery model.