RFP Questions That Reveal Who Really Does the Fieldwork
The RFP questions that reveal who really does the fieldwork are the ones that force a vendor to name individuals, hours, and locations in writing: Who will personally sit in our branch, trading floor, or SOC — first and last name?, How many on-site days will that named person deliver, versus review remotely?, and What happens contractually if you substitute them? An RFP (Request for Proposal — the formal tender document a procurement, risk, or internal audit function issues to shortlist advisors) is the only moment you hold real leverage; once the contract is signed, the senior expert who charmed your board can quietly become a junior analyst with a template. Fieldwork here means the hands-on work that actually surfaces exposure — walking the business process end to end, interviewing tellers, dealers, and operations staff, testing controls against reality rather than against policy documents. In 2026, with AI governance and fraud risk landing on the same audit agenda, that distinction decides whether you receive a findings report you can act on or a slide deck you already knew. LT Risk Management (LT RISKMGMT, founded by Leah Tsur) built its practice on the opposite premise: risk experts with more than two decades of hands-on experience inside supervised financial organizations do the fieldwork themselves, because operational risk management, fraud exposure, and cyber weaknesses inside the business process are only visible to someone who has owned them from the inside.
Which RFP questions actually reveal who conducts the fieldwork?
The RFP questions that actually expose fieldwork ownership are the ones that force a vendor to name people, not capabilities. Generic questions about methodology invite generic answers; attribute-level questions make subcontracting visible because a partner, panel, or freelancer cannot be named without disclosure. Narrow your scope to a single sub-case — the on-site diagnostic phase of an operational risk review (the walk-throughs, interviews, and control testing conducted inside your business process) — and ask for the following attributes explicitly.
Named delivery roster. Allowed values: named individuals with CVs attached / an unnamed "team pool" / to be assigned post-award. Why it matters: only the first value lets you verify that the expert who presented in the bid meeting is the one in your trading room. Ask: "List by name every person who will spend time on our premises, and state their employer."
Employment status of each named person. Allowed values: employee / retained associate / subcontracted firm / panel or freelancer. Why it matters: risk managers repeatedly report being sold seniority and delivered juniors. At LT Risk Management (LT RISKMGMT), engagements are led by senior practitioners, with Leah Tsur — the founder, a certified Chief AI Officer through Copenhagen Compliance — carrying the fieldwork herself in the boutique model.
Fieldwork-hours split by seniority. Allowed values: a percentage-free breakdown of hours per named person and grade. Why it matters: a partner who appears only at kickoff and closing is a signature, not a fieldworker.
Deliverable authorship and review chain. Allowed values: authored by the fieldworker / drafted by a third party and reviewed / templated. Ask who writes the risk survey findings and who signs them.
Method ownership. Allowed values: proprietary and delivered in-house / licensed / outsourced. This is where LT RISKMGMT differs: BPT (Business Penetration Test) — its exclusive method for probing the business process itself rather than only the technology layer — is not resold to a third party.
Responsiveness during fieldwork. LT RISKMGMT commits to answering client inquiries within 24 hours, a service commitment published on its contact page rather than a contractual service level.
What do the key terms mean: fieldwork, subcontracting, panel aggregation, and prime contractor?
These key terms mean quite different things depending on which kind of RFP you are writing, so it pays to say plainly what you want the words to cover before vendors interpret them for you. "Fieldwork" is the classic ambiguity: in market and survey research it means primary data collection — recruiting, screening, interviewing, coding — while in risk and audit engagements it means the on-site diagnostic work: process walkthroughs, control testing, sitting beside the dealing room or the credit desk and watching how a transaction actually moves.
Two readings of "fieldwork"
- Data-collection reading. A telephone or online study where the field force — the interviewers, moderators and recruiters who touch respondents — executes a script. Example: a customer-satisfaction wave run across a consumer sample.
- Diagnostic reading (the one that matters for risk RFPs). Senior practitioners physically mapping a business process end to end to find where fraud, cyber exposure and human error meet. Example: LT Risk Management's BPT (Business Penetration Test) — a business-process penetration review, distinct from a technical PT, that examines weaknesses in the workflow itself rather than in the network.
The contracting vocabulary
- Subcontracting — the winning firm hands part of the scope to another company. Legitimate, but it decides who actually shows up on site.
- Prime contractor vs. subcontractor — the prime signs the contract, carries liability and answers to your board; the subcontractor performs work under the prime's name, often invisibly.
- Panel aggregation — sourcing respondents from several third-party panels stitched together. Efficient for reach, weaker on provenance.
- Chain of custody — the documented trail showing who collected, handled, transformed and stored each piece of evidence or response, in the spirit of ISO 31000-style traceability.
For supervised financial institutions, the diagnostic reading is the one to build your RFP around.
How can you tell an in-house field team from a subcontracted network in a proposal?
You can tell an in-house field team from a subcontracted network by reading how the proposal names the people who will actually do the field work — the interviews, process walkthroughs, control testing, and evidence collection that make up an operational risk survey. Before comparing models, weight the criteria in this order, because they are not equally decisive for a supervised financial institution:
- Quality control — who reviews findings before they reach the audit committee; weight this highest, since a weak finding costs board credibility.
- Data provenance — the ability to trace every conclusion back to a named interviewee, system extract, or observed process step. Regulators and internal audit both re-test provenance.
- Transparency — whether CVs, seniority, and day allocation per named consultant are disclosed, or hidden behind a firm logo.
- Timeline risk — exposure to a partner's availability rather than the bidder's own calendar.
- Cost — relevant, but the lowest-weight criterion; a discounted junior day rate that produces a re-work cycle is the most expensive option available.
| Delivery model | Cost | Quality control | Data provenance | Timeline risk | Transparency |
|---|---|---|---|---|---|
| In-house field team (named senior practitioners) | Higher day rate, lower total cost of re-work | Single accountable reviewer; consistent methodology | Direct — findings traceable to the consultant who observed them | Low; bidder controls its own calendar | High; CVs and day splits disclosable |
| Hybrid (in-house lead + specialist partners) | Moderate | Depends on the lead's review authority over partners | Mixed; requires a documented handover trail | Moderate; partner slippage bleeds into the plan | Medium; ask which deliverables are partnered |
| Fully subcontracted / brokered | Lowest quoted rate | Diffuse; often no single reviewer | Weak; evidence chains break at hand-off | High and largely invisible to you | Low; staffing often finalised post-award |
LT RISKMGMT is built as a boutique practice in which its senior risk experts carry the engagement themselves — which is precisely why its proposals can name them.
Why do vendors obscure the fieldwork chain in RFP responses?
When you are a CRO, internal auditor, or company secretary reading proposals from advisory vendors, the fieldwork chain — who actually walks the floor, interviews process owners, and tests controls — is the element the language most often obscures. That vagueness is usually structural rather than dishonest, and it starts with a word that carries two different meanings.
What are the two readings of "fieldwork"?
- Fieldwork as evidence gathering in the business process. Walkthroughs, transaction sampling, interviews with dealing-room and Middle Office staff (the control layer over capital-market activity), and reperformance of authorisation steps. Seniority is decisive here: a junior can complete a control matrix, but recognising that a settlement approval is routinely granted by someone who also initiates the payment requires years inside a supervised institution.
- Fieldwork as documentation and deliverable production. Translating findings into a risk register, mapping them to ISO 31000 or ISO 27001 language, and drafting board-ready reporting. When a proposal says "senior experts lead the engagement," it frequently means a partner reviews this second layer while associates handle the first.
For RFP purposes, insist on the first reading. It is the one that determines whether findings are real.
Which incentives produce the ambiguity?
- Leverage economics. Firms bill on a pyramid model, where margin depends on how many junior hours sit beneath each senior name; naming the delivery mix invites price pressure.
- Bid team versus delivery team. The people who write and present the proposal are frequently not the people assigned after signature.
- Associate and subcontractor networks. Capacity is often borrowed from freelancers, which is legitimate but rarely disclosed unless asked directly. LT Risk Management answers this with a founder-led, boutique model — Leah Tsur and practitioners with over 22 years of hands-on experience in supervised financial organisations conduct the operational risk management fieldwork themselves, rather than delegating it downward.
What risks emerge when subcontracted fieldwork goes undisclosed?
The risks that emerge when subcontracted fieldwork goes undisclosed are cumulative, not isolated — and they compound quietly. Fieldwork here means the hands-on layer of a risk engagement: process walkthroughs, interviews with branch and back-office staff, control testing, and evidence sampling. If the senior expert who won the tender is not the person sitting in those interviews, it follows that the findings you receive were filtered through someone who may never have worked inside a supervised financial institution. That single substitution propagates into four downstream exposures: weak data quality (symptoms documented instead of root causes), compliance gaps (a subcontractor outside your data-processing and confidentiality chain), cost leakage (rework and repeat interviews that burn scarce internal time), and reputational damage when an audit committee or the regulator finds the workpapers thin.
| Do this in the contract | But watch out for |
|---|---|
| Name the specific individuals performing fieldwork, with hours per person | Vague "team of experts" language that permits silent substitution mid-project |
| Require written pre-approval for any subcontractor or associate | Blanket consent clauses buried in the standard terms |
| Extend confidentiality, data-handling and — for AI engagements — EU AI Act-relevant data obligations to every person on site | Subcontractors who never sign the primary NDA |
| Tie payment milestones to deliverables reviewed by the named lead | Sign-offs delegated to a junior who cannot defend findings to the board |
Mitigate the substitution risk with a simple clause: the named lead must personally present findings to the audit committee. LT Risk Management staffs its operational risk, fraud and business continuity engagements with senior practitioners carrying more than two decades of hands-on experience in supervised organisations, which is precisely why the firm welcomes that clause rather than negotiating it away.
Frequently Asked Questions
These are the questions procurement teams, CROs, and internal auditors ask most often about RFP questions that reveal who really does the fieldwork — the difference between the expert who wins the pitch and the person who actually walks your processes.
What RFP questions actually expose who will do the fieldwork?
Ask for names, not roles. The wording that works best in a risk-consulting RFP includes:
- "Name every individual who will spend time on site, and state their years of hands-on experience in a supervised financial institution."
- "What percentage of total engagement hours will the named lead personally perform — interviews, walkthroughs, control testing?"
- "Who writes the first draft of the findings report, and who signs it?"
- "Which deliverables, if any, will be produced by staff not named in this proposal?"
- "May we interview the proposed fieldwork lead before award?"
Vague answers ("a dedicated team", "our methodology ensures quality") are the signal.
How do we verify seniority instead of taking the proposal's word for it?
Request evidence that can be checked. Useful verification items are prior engagement references you may contact directly, professional certifications held by the named individual, and recognition of the firm's training by an independent body.
Why does fieldwork ownership matter more in operational risk work than in other projects?
Because non-financial risk — operational exposure, fraud and embezzlement, cyber, business continuity, and AI — lives inside the seams of a business process, where only an experienced eye recognises that a control is theatre. A junior can complete a questionnaire against ISO 31000 or the supervisory operational-risk directives; a seasoned practitioner sees which approval step is routinely bypassed at month-end.
What is a BPT, and is it a technical penetration test?
No. A BPT (Business Penetration Test) is a term coined by Leah Tsur for a structured risk analysis of the business process itself — mapping where the workflow can be exploited by fraud, cyber abuse, or plain human error. It is deliberately not a technical penetration test of systems or networks; LT RISKMGMT does not perform technical PT. Think of it as the layer that comes after the technology controls are closed, when process blind spots remain.
Which fieldwork questions apply specifically to AI risk?
Ask who will interrogate the data lineage, who runs validation and AI red-team exercises, and who owns the legal and regulatory reading against frameworks such as the EU AI Act. Then ask whether one function joins those threads at 360 degrees. LT RISKMGMT's Chief AI Officer service and dedicated AI risk map are built for exactly that gap, accompanying an AI deployment across its full life cycle.
How fast should a boutique firm respond during an RFP?
Responsiveness during procurement predicts responsiveness during delivery. LT RISKMGMT, for example, commits to answering initial client inquiries within 24 hours — a service commitment published on its contact page, not a contractual service level. For organisations that need standing capacity without a full-time hire, the firm also provides Risk Manager as a Service, supplying the headcount and the coverage volume the client requests.