Trusted Voice Research Infrastructure for NGOs, Governments & Global Development Partners
Procurement Center

The evidence pack, including the parts we cannot supply.

Institutional procurement runs on documents. This is every one a review team will ask us for, with what it is for, who it is for, and where it stands — and six of them require an auditor, an assessor or an insurer rather than us. Those are listed here with the same prominence as the ones that exist.

Read the state before the list

A procurement pack is the one place where an absent document is more dangerous than an unflattering one. A missing report that is clearly marked missing costs a conversation; a page that quietly omits it costs the relationship the moment a security reviewer asks.

Published

Published here, with its owner, version and review date on the document itself.

Available on request

It exists and is shared under an engagement or an NDA rather than published openly.

In preparation

Being written. Ask and we will tell you where it stands and when it is expected.

Not yet available

It does not exist yet. We are not presenting a placeholder as a document.

Requires an independent party

This cannot be written by us. Its whole value is that an independent auditor, assessor or insurer signed it, and none has. We will not produce our own version.

Where we stand against a supplier assessment

A review team does not score documents, it scores requirements. These are the requirements a public-sector, donor or INGO assessment works through, with our position on each — including the ones we can only partly answer and the ones that need somebody other than us.

Ready today
3
Partially evidenced
4
Need an independent party
2
Nothing to show yet
1

Each state is derived from the documents beneath it, not written. A requirement cannot be marked ready while a document it rests on is missing, and moving one means producing the document rather than editing this page.

Legal standing and registration

Not available

Is the supplier a registered legal entity in good standing, and can it prove it?

What answers it

  • Certificate of incorporation and tax registration Not yet available

What is missing

A certificate of incorporation and a tax clearance certificate.

Closed by: Company registry and revenue authority

Financial standing

Requires an independent party

Can the supplier show it will still exist at the end of the contract?

What answers it

  • Audited financial statements Requires an independent party

What is missing

Audited financial statements covering the periods your process requires.

Closed by: External auditor

Security assurance

Partially evidenced

How is the platform secured, and who other than the supplier has verified it?

What answers it

What is missing

An independent attestation. The controls are described and evidenced internally, and no independent party has tested or certified them.

Closed by: Independent audit firm, security assessor or accredited certification body

Accessibility

Partially evidenced

Does the product meet the accessibility standard our procurement rules impose?

What answers it

What is missing

An independently audited conformance report. Ours is measured, automated and manual, and it is our own measurement.

Closed by: Independent accessibility auditor

Service levels and continuity

Partially evidenced

What is committed when it breaks, and what happens if the supplier disappears?

What answers it

What is missing

A written business continuity and disaster recovery plan, including exit and data return.

Closed by: Platform — in preparation

Insurance and liability

Requires an independent party

Is there cover behind the liability the contract assigns?

What answers it

  • Insurance schedule Requires an independent party

What is missing

Certificates of professional indemnity and cyber liability cover at the limits your process requires.

Closed by: Insurer

The pack

Ordered the way a due-diligence file is assembled: who we are, what the platform is, how it is secured, what happens to your data, how the service runs, how it is bought, and what an independent party would have to confirm.

The organisation

Enterprise capability statement

Published Open

What VoiceInsights is, what it runs, and for whom — the document a procurement file opens with.

Audience: Procurement, programme leadership, donorsClassification: Public

Certificate of incorporation and tax registration

Not yet available

Proof the counterparty is a real, registered entity in good standing.

Held by the business rather than by the platform. Not published here, and not something this repository can or should generate.

Audience: Procurement, financeClassification: Shared under engagementNeeds: Company registry and revenue authority

Audited financial statements

Requires an independent party

Financial standing, for a buyer assessing supplier viability.

Audience: Procurement, financeClassification: Shared under engagementNeeds: External auditor

Insurance schedule

Requires an independent party

Professional indemnity and liability cover, which many institutional contracts require.

Audience: Procurement, legalClassification: Shared under engagementNeeds: Insurer

The platform

Platform overview

Published Open

What the platform does, end to end, for a reviewer who will not read a demo.

Audience: Technical and programme reviewersClassification: Public

Research modes — capability and limits

Published Open

Which research designs run end to end, which run on shared structures, and what each cannot do.

Audience: Research leads, M&E, technical evaluatorsClassification: Public

Language capability matrix

Published Open

What can be done in a given language, recorded separately for six capabilities and read live from the registry.

Audience: Programme leads, technical evaluatorsClassification: Public

Integration status

Published Open

What connects today, what is configured per deployment, and which formats are implemented against systems we have never contacted.

Audience: IT reviewers, systems architectsClassification: Public

Security

Security overview

Published Open

Identity, access, tenant isolation, session handling, encryption posture and monitoring.

Audience: Security reviewers, enterprise ITClassification: Public

Trust register — claims and their evidence

Published Open

Every public assurance claim with its verification state, read live. An overdue or unverified claim is never shown as satisfied.

Audience: Security reviewers, procurement, donorsClassification: Public

Data protection and privacy

Subprocessor register and processing locations

Published Open

Who else processes customer data, for what, in which entity country, and the state of each data processing agreement.

Audience: Data protection officers, legal, procurementClassification: Public

Data protection position

Published Open

Ownership, controller and processor roles, consent, retention, deletion, legal hold and transfer.

Audience: Data protection officers, legalClassification: Public

Responsible AI position

Published Open

Where a model is permitted to contribute, where it is not, and what must be true before AI-assisted output is published.

Audience: Ethics reviewers, research leads, procurementClassification: Public

Data processing agreement

In preparation

The contractual instrument governing processing on the customer’s behalf.

A template requires legal review before it is offered. We will not publish an unreviewed contract.

Audience: Legal, data protection officersClassification: ContractualNeeds: Legal review

Service, support and continuity

Accessibility statement

Published Open

The conformance target, what has been measured, how it was measured, and what has not been independently audited.

Audience: Procurement, accessibility reviewers, public-sector buyersClassification: Public

Support and service model

Published Open

How support is reached, what response expectations exist, and how incidents are communicated.

Audience: Operations, procurementClassification: Public

Service levels and continuity

Published Open

Availability posture, backup and recovery state, and what has and has not been rehearsed.

Audience: Operations, procurement, riskClassification: Public

Business continuity and disaster recovery plan

In preparation

The documented plan, its recovery objectives, and the record of it being exercised.

Backup tooling exists and a restore drill has been run. A HUMAN recovery rehearsal has not been held, so the plan is not yet a document we would stand behind.

Audience: Risk, operations, procurementClassification: Shared under engagement

Commercial and engagement

Implementation and training approach

Published Open

How a deployment is scoped, configured, populated and handed over, and how teams are trained.

Audience: Programme leadership, procurementClassification: Public

Commercial and engagement model

Published Open

How VoiceInsights is licensed and bought: annual licence, implementation, usage, and a proposal-and-purchase-order route.

Audience: Procurement, financeClassification: Public

Vendor due-diligence response pack

Available on request

A completed response to the questions institutional due-diligence questionnaires repeat.

Assembled per questionnaire from the registers rather than kept as a static file, because a stale due-diligence answer is worse than none.

Audience: Procurement, vendor managementClassification: Shared under engagement

Independent assurance

SOC 2 Type II report

Requires an independent party

Independent attestation of control design and operating effectiveness over a period.

Audience: Security reviewers, enterprise ITClassification: Shared under NDA when it existsNeeds: Independent audit firm

Independent penetration test report

Requires an independent party

Adversarial testing of the running platform by a party with no stake in the result.

Audience: Security reviewersClassification: Shared under NDA when it existsNeeds: Independent security assessor

ISO/IEC 27001 certification

Requires an independent party

An accredited body attesting that an information security management system meets the standard. No such certificate is held.

Audience: Procurement, security reviewersClassification: Public when it existsNeeds: Accredited certification body

Independent WCAG 2.2 AA audit

Requires an independent party

Independently audited conformance, as distinct from our own automated and manual measurement.

Audience: Public-sector procurementClassification: Public when it existsNeeds: Independent accessibility auditor

Why these are web documents rather than a PDF bundle

Each published document above is a page rather than a file, and that is a deliberate choice with a real trade-off.

What you should know

  • A page is a projection of a governed register. When a claim is re-verified or a subprocessor changes, the document changes with it. A PDF bundle assembled last quarter is a snapshot that has already started to drift, and a due-diligence answer that has drifted is worse than none.
  • Every one prints. Each document carries a print stylesheet that drops the navigation and expands links to their full URL, so saving it as PDF from your browser produces a clean attachment for a tender file.
  • Where your process requires a signed, dated PDF pack on letterhead, ask and we will produce one against a stated version date, so the file you attach and the page it came from can be reconciled later.

What to send us

If you have a due-diligence questionnaire, a security assessment template or a vendor form, send it. We answer from the registers rather than from a marketing document, so the answers you get are the same facts these pages carry — including the ones that are inconvenient.