Customer Service and Records Administration Services for ABLE United
- Response deadline
- Dec 7, 2026 Due in 76 days
- Date posted
- Sep 21, 2026
- Source
- Open notice
Description
The ABLE United Program requires comprehensive records administration, customer service, reporting, and operational support services necessary to operate a Qualified ABLE Program. The services summarized below and detailed further in the example Contract included as Appendix A, represent the minimum required services. The selected Respondent will provide these services in accordance with the Program disclosures (included as Appendix B) and the Business Rules (included as Appendix C). Respondents may propose additional enhancements that provide value to the Program. 3.01(1) Recordkeeping and Account Administration The selected Respondent will provide full-service recordkeeping and administrative support for ABLE Accounts, including account establishment and maintenance, processing of contributions and withdrawals, transaction recordkeeping, tax reporting, and other operational functions necessary to administer ABLE Accounts. The selected Respondent will also provide debit or prepaid card functionality for ABLE Account Owners as part of its core service offering. 3.01(2) Customer Service and Participant Support The selected Respondent will provide participant support services for ABLE Account Owners, contributors, and prospective participants across multiple contact channels, including telephone, online chat, electronic communications, and written correspondence. Respondents should be capable of supporting accessible communications and digital services consistent with ADA requirements. 3.01(3) Technology Platform and Online Access The selected Respondent will provide a secure, reliable, and scalable technology platform that enables online account opening and management, contribution and withdrawal processing, investment allocation changes, and participant access to account information and transaction history. The platform shall be accessible through web and mobile-compatible interfaces and designed to support a high-quality user experience consistent with accessibility standards, including compliance with applicable ADA requirements. The platform shall support integration with third-party systems, including financial institutions, payment processors, and Program partners, and shall maintain accuracy and consistency across systems. Security controls for the platform are addressed in Sections 3.01(6), 3.01(10, and 3.01(11). 3.01(4) Governance and Audit Support The selected Respondent will support Board oversight and Program administration through operational reporting and reconciliation support. The Respondent must maintain appropriate independent audit reports and provide documentation supporting operational controls and disaster recovery testing. 3.01(5) Data Ownership and Access The selected Respondent will maintain Program Data in a secure environment and acknowledges that all Program Data is owned by the Board. The Respondent shall provide the Board with timely, complete, and unrestricted access to Program Data for purposes including Program oversight, reporting, audit, and transition to a successor vendor. The selected Respondent shall maintain appropriate data access controls, audit logs, and data governance practices to ensure the integrity, security, and traceability of Program Data. The Respondent shall support data extraction and delivery in industry-standard, machine-readable formats upon request and shall ensure that 5 Program Data can be transferred to the Board or its designee without delay, degradation, or additional cost beyond agreed-upon contractual terms. 3.01(6) Data Protection and Security Controls The selected Respondent will maintain data protection and access controls appropriate for the administration of financial accounts and compliance with applicable federal and state requirements. The selected Respondent shall implement controls that include encryption of data at rest and in transit, user authentication, role-based access controls, and protection of sensitive information. Requirements for monitoring, fraud and threat detection, and incident response are addressed in Sections 3.01(8) and 3.01(10). Requirements for security governance, audits, reporting, and compliance documentation are addressed in Section 3.01(11). 3.01(7) Investment Option Administration The selected Respondent will support the administration of Board-approved Investment Options, including the allocation of contributions and withdrawals and coordination with underlying investment managers and custodians. The selected Respondent may also support the administration of an FDIC-insured option if approved by the Board. The selected Respondent must perform these services in compliance with applicable federal and state laws, regulations, and Program requirements governing Qualified ABLE Programs. 3.01(8) Incident Response and Cybersecurity Operations The selected Respondent will maintain a formal Incident Response Program to support the timely detection, response, and remediation of system and cybersecurity incidents. The selected Respondent shall develop and maintain a documented Incident Response Plan that defines roles, escalation procedures and communication protocols. The Plan shall be reviewed at least annually and updated as necessary. The selected Respondent shall notify the Board of any security breach as soon as practicable, participate in cybersecurity and disaster recovery tabletop exercises led by the Board, and shall coordinate with Board staff and other service providers during incident response activities. The selected Respondent shall document and report incidents, including preparing and delivering Root Cause Analysis (RCA) reports for critical and high-severity events, and shall demonstrate the ability to respond to and resolve incidents in a manner that minimizes impact to program operations and participants. 3.01(9) Business Continuity and Disaster Recovery The selected Respondent will maintain Business Continuity and Disaster Recovery (BC/DR) capabilities to ensure continuity of operations in the event of system disruptions or disasters. The Respondent shall develop and maintain a Business Continuity Plan that addresses operations within the first forty-eight (48) hours of a disruption and shall conduct annual testing of business continuity and disaster recovery plans. The Respondent shall identify and remediate any deficiencies. The selected Respondent shall maintain secure, up-to-date backups of all critical systems and data and shall demonstrate the ability to sustain and restore operations in a timely manner following system outages, cybersecurity incidents, or other disruptions. 6 3.01(10) System Monitoring and Threat Detection The selected Respondent will continuously monitor systems, integrations, and user activity to ensure system performance, data integrity, and security. The Respondent shall monitor for fraud, suspicious activity, unauthorized access, and data anomalies. The Respondent shall implement automated alerting and escalation procedures and shall proactively identify, investigate, and resolve issues to maintain system stability and security. 3.01(11) Security Governance and Compliance The selected Respondent will maintain a comprehensive security and compliance program and a security governance framework aligned with applicable regulatory requirements and industry best practices. The Respondent shall conduct quarterly security audits and user access reviews and shall maintain audit logs for system access, data changes, and administrative activity. The selected Respondent shall participate in security training and awareness programs, including phishing simulations as required by the Board, and shall demonstrate compliance with applicable federal and state requirements governing financial accounts and data protection. The Respondent shall provide documentation and reporting to support compliance and audit requirements. 3.01(12) Reporting, Documentation, and Transparency The selected Respondent will provide operational reporting and maintain documentation necessary to support Program oversight, audit readiness, and continuity of operations. The Respondent shall provide monthly reporting on system performance, incidents, and support activity and shall maintain current documentation related to implementation plans, security plans, business continuity, system configurations, integrations, and security controls. The selected Respondent shall provide quarterly reporting on documentation updates, audit findings, and corrective actions. All documentation shall be maintained in a format that supports audit, compliance, and transition to a future service provider, if required. 3.01(13) Value-Added Services The Respondent may offer services other than those specifically outlined in the solicitation that it believes offer additional operational benefits, efficiencies, or risk reduction (Value-Added Services). Although the Board has identified its current business needs, those needs are not intended to limit the Respondent’s innovations or creativity in preparing a Response. The Board will consider innovative ideas, new concepts, and partnership arrangements not otherwise presented in this ITN, including unique business features, special services, cost savings or shared-savings arrangements, discounts, or terms and conditions specific to the selected Respondent. If the Respondent is awarded the Contract and a Value-Added Service is included in the Contract without an established start date, the Board will provide the agreed-upon notice before the service is implemented.
Classifications
- NAICS80161500
Documents (3)
- ITN26-01_ABLE_Records_Administration.pdfapplication/pdf3.3 MBNot yet available
- ITN26-01_Written_Response_Packet.docxapplication/octet-stream60 KBNot yet available
- ITN26-01_Request for Clarification Form.docxapplication/octet-stream29 KBNot yet available
Contacts
- itninfo.prepaid@myfloridaprepaid.com(850) 488-8514