← Back to blog

Organizational Conflict of Interest in RFPs: A Contractor's Playbook

August 14, 2026
Organizational Conflict of Interest in RFPs: A Contractor's Playbook

When an RFP raises an organizational conflict of interest, your first three moves are non-negotiable: disclose the conflict to the contracting officer (CO), run a targeted internal OCI assessment, and submit a contract-specific mitigation or avoidance plan. FAR Subpart 9.5 governs the entire process, and agency supplements like NASA's NFS Subpart 1809.5 add procurement-specific layers. Acting early preserves your options. Waiting until after award shrinks them to almost nothing.

Immediate action checklist:

  • Identify which OCI type applies: unequal access to information, impaired objectivity, or biased ground rules
  • Collect supporting facts: affected contracts, personnel, data flows, and affiliate relationships
  • Notify your CO and legal counsel in writing before the proposal deadline
  • Draft initial mitigation language tied to the specific conflict, not a generic template
  • Flag impacted subcontractors, teaming partners, and affiliates for parallel disclosure review
  • Document every step for the contract file and potential protest defense

Pro Tip: Identify OCI risks before you write a single page of your proposal. Early CO engagement is the single most effective risk-reduction move available — it keeps avoidance and neutralization on the table, which are far cleaner outcomes than mitigation after award.


Key Takeaways

Disclose early, assess every affiliate, and submit a contract-specific mitigation plan: those three steps, grounded in FAR Subpart 9.5, determine whether an OCI disqualifies you or gets resolved before award.

PointDetails
Three OCI types to knowUnequal access to information, impaired objectivity, and biased ground rules each require a different resolution approach.
Disclose before the deadlineFAR 9.507-1(b) and model clauses like 48 CFR 3452.209-70 require disclosure of known conflicts; non-disclosure risks termination and False Claims Act liability.
Mitigation plans must be operationalPilieroMazza warns that plans treated as paper exercises create liability; plans must be actively implemented, monitored, and updated.
2025 proposed FAR rule raises the stakesThe January 15, 2025 proposed rule would make approved mitigation plans contractually binding, converting noncompliance into potential material breach.
Rfpforgeai supports OCI complianceRfpforgeai extracts OCI-relevant clauses, generates compliance matrices, and maintains versioned mitigation-plan records for audit-ready proposal files.

Table of Contents

What is an organizational conflict of interest in an RFP?

An organizational conflict of interest (OCI) in federal acquisitions occurs when a contractor's work on one contract creates a situation where the contractor either cannot render impartial advice or assistance to the government, or gains an unfair competitive advantage in a related procurement. FAR Subpart 9.5 defines the governing framework, and case law has consolidated OCI risks into three canonical categories that every proposal team should be able to recognize on sight.

The three FAR-recognized OCI types: Unequal access to information — the contractor has access to nonpublic information that gives it a competitive advantage in a related solicitation. Example: a contractor supporting a program office's requirements development then competes for the follow-on production contract, having seen draft specs no competitor reviewed. Impaired objectivity — the contractor's financial interest in one contract could bias its judgment on a related advisory or evaluation task. Example: a systems integrator evaluating competing vendors when it has a financial stake in one of those vendors' products. Biased ground rules — the contractor helped write the SOW, specs, or evaluation criteria for a procurement in which it will compete. Example: a contractor drafting performance work statements for a follow-on contract that mirrors its own existing capabilities.

FAR Subpart 9.5 applies broadly to prime contracts and, through flow-down provisions, to subcontracts where the subcontractor's work could create the same conflict risks. There is no dollar threshold that automatically exempts a procurement; COs apply judgment based on the nature of the work and the relationship between contracts. Agency supplements, including NASA's NFS Subpart 1809.5, extend and tailor these rules for specific program environments.


How do organizational conflicts of interest show up in RFP documents?

Most OCI risks are visible in the solicitation itself if you know what language to scan for. Proposal teams that read only the instructions-to-offerors section miss the highest-risk passages, which tend to sit in the SOW, technical specifications, evaluation factors, and data-access attachments.

Red flags to scan in every RFP:

  • SOW language that references prior advisory, systems engineering, or program support work the offeror currently performs for the same agency
  • Specs or performance standards that closely mirror a specific contractor's existing product or service architecture
  • Evaluation criteria that weight proprietary methodologies or tools the incumbent already uses
  • Data-access clauses granting the awardee access to source selection information, budget data, or nonpublic technical reports from a related program
  • Incumbent-role language that implies the current contractor helped develop the requirement
  • Provisions requiring the contractor to evaluate, assess, or recommend competing products or services in which it has a financial interest
  • Clauses referencing OCI mitigation or disclosure obligations (e.g., FAR 52.209-7, agency-specific provisions) — these signal the CO already identified a potential conflict

The NRC's OCI guidance frames two diagnostic questions that cut through ambiguity quickly: Could this role bias the contractor's judgment? Does this role give the contractor an unfair competitive advantage? Apply both questions to every task in the SOW.

Short SOW snippets that commonly create biased ground rules look like this: "The contractor shall develop performance metrics and evaluation criteria for the follow-on acquisition" or "The contractor shall provide technical advisory support to the program office during source selection." Either sentence, read in a competitive RFP, is a disclosure trigger.

Pro Tip: Build a short automated text-matching routine against your RFP intake process. Flag clause identifiers like FAR 52.209-7, phrases like "organizational conflict of interest," "limitation on future contracting," "firewall," and "nonpublic information." These terms in a solicitation mean the CO has already flagged a potential OCI, and your response needs to address it directly.


What are your disclosure and due diligence obligations as a contractor?

Contractor obligations in an RFP process go beyond reading the solicitation. You have an affirmative duty to investigate your own organization's relationships and disclose anything that could constitute an OCI, whether or not the solicitation explicitly asks.

Due diligence starts with a structured review of your parent company, all affiliates, subsidiaries, teaming partners, and proposed subcontractors. The question for each entity is whether its current or recent work for the government creates any of the three OCI types relative to the target RFP. Personnel assignments matter too: a key person who recently supported the program office on a related advisory contract is a disclosure trigger even if the company itself has no direct prior contract with the agency.

48 CFR 3452.209-70 sets out model certification language that most solicitations incorporate or adapt. Under that provision, offerors must certify that no relevant facts create an OCI and disclose any actual or potential conflicts they are aware of. Failure to disclose, or misrepresentation in the certification, exposes the contractor to contract remedies including termination and civil penalties.

Disclosure statement template (adapt to your specific facts):

ElementWhat to include
Nature of the conflictDescribe the specific relationship, role, or data access that creates the potential OCI
Affected contractsList contract numbers, agency names, and performance periods for all related work
Personnel involvedName or describe roles of individuals with access to nonpublic information or advisory functions
DurationState the period during which the conflicting relationship exists or existed
Proposed resolutionIdentify your preferred resolution method (avoidance, neutralization, mitigation) and summarize the approach
Supporting documentationList attachments: org charts, NDAs, firewall procedures, subcontractor certifications

Timing matters. Most solicitations require disclosure before proposal submission, and some require it within a set number of days of identifying a potential conflict during performance. Read the solicitation's OCI provision carefully for the specific deadline. If the solicitation is silent on timing, disclose as early as possible and document the date.

Pro Tip: Never rely on a subcontractor's verbal assurance that it has no OCI. Require written certifications from every teaming partner and proposed subcontractor before your proposal goes out the door. That documentation is your first line of defense in a protest.


What must a contracting officer do when an OCI arises?

COs carry the primary obligation to identify and resolve OCIs before award. FAR Subpart 9.5 requires COs to analyze planned acquisitions early in acquisition planning, identify potential conflicts, and recommend actions to avoid, neutralize, or mitigate significant potential conflicts before issuing the solicitation.

FAR 9.504(a) states: "Contracting officers shall analyze planned acquisitions in order to: (1) Identify and evaluate potential organizational conflicts of interest as early in the acquisition process as practicable; and (2) Avoid, neutralize, or mitigate significant potential conflicts before contract award."

When a significant potential OCI exists, the CO typically consults legal counsel before issuing the solicitation. The CO then prepares a written analysis documenting the nature of the conflict, the resolution approach selected, and the rationale. That analysis goes into the contract file and becomes the baseline against which any protest or post-award dispute is measured.

Steps COs will take that you can anticipate and assist with:

  • Request a written OCI disclosure and proposed mitigation plan from the offeror
  • Issue a solicitation provision describing the nature of the potential conflict and the required contractor response
  • Evaluate submitted mitigation plans for specificity, measurability, and enforceability
  • Negotiate mitigation plan terms and incorporate the approved plan into the contract
  • For acquisitions over $1 billion, brief senior procurement executives per DFARS 209.571-4 requirements
  • Document the resolution in the contract file, including any waiver determination

Understanding this sequence helps you position your proposal response. A CO who has already flagged an OCI in the solicitation is looking for a specific, credible mitigation plan, not a generic conflict-of-interest policy statement. Your response should address the CO's documented concern directly.


What resolution methods does FAR recognize, and how do you choose?

FAR Subpart 9.5 and the NASA OCI handbook both recognize four resolution methods, listed in order of preference: avoidance, neutralization, mitigation, and waiver. The preference ordering matters because COs are expected to use the least-intrusive effective method.

Resolution methodWhen it appliesWho implements itTypical contract languageLitigation risk
AvoidanceOCI cannot be adequately mitigated; contractor withdraws or restructures scopeContractor (withdraws) or CO (restructures acquisition)Limitation on future contracting clause; scope exclusionLowest — conflict eliminated
NeutralizationConflict can be removed by restricting access or role without disqualifying the contractorContractor, with CO approvalFirewall provision; data access restriction; personnel exclusionLow — conflict neutralized at source
MitigationConflict cannot be avoided or neutralized but can be managed with controlsContractor proposes; CO approves and incorporates into contractOCI mitigation plan incorporated by reference or attachmentModerate — plan must be actively implemented
WaiverConflict exists but award is in the government's interest despite the conflictCO (with agency head approval for significant conflicts)Waiver determination in contract file; disclosure to offerorHigher — waiver can be protested; conflict remains

Avoidance is the cleanest outcome. If a contractor helped write the SOW for a follow-on procurement, the cleanest resolution is often a limitation on future contracting that bars the contractor from competing for that specific follow-on. Biased ground rules are among the hardest OCI types to mitigate effectively, which is why practitioners often favor acquisition redesign or a scope limitation over relying on mitigation alone.

Mitigation is the most common path in practice because it preserves the contractor's ability to compete. But it carries the highest ongoing compliance burden. Under the January 15, 2025 proposed FAR rule, approved mitigation plans are expected to be incorporated into contracts, converting noncompliance from a policy violation into a potential material breach.

Mitigation plan required elements:

  • Scope: describe the specific conflict being mitigated and the contracts involved
  • Firewalls: physical and technical barriers separating conflicted personnel from the target program
  • Segregated teams: organizational separation with documented reporting lines
  • Personnel restrictions: named or role-based restrictions on access and participation
  • Data handling: rules for storage, access, and destruction of nonpublic information
  • Monitoring: internal audit schedule, compliance officer designation, and review frequency
  • Reporting: process for reporting noncompliance to the CO, including timelines
  • Duration and termination triggers: when the plan expires and what events require revision

Pro Tip: When drafting a mitigation plan, name specific individuals, specific data systems, and specific review dates. Vague commitments like "appropriate firewalls will be maintained" give the CO nothing to verify and will likely draw a request for revision or a protest challenge. Specificity is what makes a plan credible.


OCI mitigation plan checklist: what to include before you submit

A government-ready OCI mitigation plan is not a policy document. It is a contract-specific, operationally detailed commitment that the CO can evaluate, approve, and enforce. Use this checklist before submission.

Personnel controls:

  1. List every individual with access to nonpublic information or a conflicting advisory role by name and title
  2. Specify which programs, data systems, and meetings each restricted individual is excluded from
  3. Require written acknowledgment from each restricted individual confirming they understand the restrictions
  4. Identify the compliance officer responsible for monitoring personnel controls

Technical and physical firewalls: 5. Describe the IT access controls separating conflicted work from the target program (separate networks, accounts, or document repositories) 6. Specify physical separation requirements if personnel share facilities 7. Document how firewall effectiveness will be tested and how often

Data access rules: 8. Identify all nonpublic government data the contractor currently holds that is relevant to the target procurement 9. State the retention, access, and destruction protocols for that data 10. Require subcontractors and teaming partners to certify compliance with the same data rules

Subcontractor and affiliate controls: 11. Extend all personnel and data controls to subcontractors and affiliates with conflicting roles 12. Require written subcontractor certifications and attach them to the plan

Monitoring and reporting: 13. Set a quarterly internal audit schedule at minimum, with results reported to the CO 14. Define the process for reporting a discovered noncompliance event to the CO within a specified number of days (typically 5–10 business days) 15. Name the internal escalation path from compliance officer to senior management

Revision triggers: 16. List events that require plan revision: personnel changes, new subcontract awards, scope changes, and any discovered noncompliance

OCI mitigation plan checklist: what to include before you submit — overview diagram

Sample language for personnel restrictions: "[Named individual / role title] shall have no access to, and shall not participate in, any work performed under Contract No. [XXXX], including attendance at program reviews, access to program data systems, or review of deliverables related to [specific program]. This restriction remains in effect for the duration of Contract No. [YYYY] and for [X] years following final delivery."

Dos and don'ts:

  • ✓ Make every commitment specific, measurable, and tied to a named person or system
  • ✓ Include a revision process so the plan stays current as circumstances change
  • ✓ Have legal counsel review the plan before submission
  • ✗ Never use generic language like "appropriate measures will be taken"
  • ✗ Never copy a mitigation plan from a prior contract without tailoring it to the current conflict
  • ✗ Never omit subcontractor controls — affiliate noncompliance is your liability

Common contractor mistakes and how practitioners say to fix them

The most consistent warning from government contracts practitioners is that contractors treat OCI mitigation plans as a proposal checkbox rather than an operational commitment. PilieroMazza is direct on this point: plans must be tailored to the contract, actively implemented, and regularly updated. A plan that sits in the contract file unread is a liability, not a safeguard.

The enforcement stakes rose significantly with the January 15, 2025 proposed FAR rule, which directs agencies to incorporate approved mitigation plans into contracts. Once incorporated, a plan becomes a contractual obligation. PilieroMazza warns that noncompliance with an incorporated plan could trigger False Claims Act exposure if the contractor continues to bill the government while knowingly violating the plan's terms.

Concrete best practices for compliance teams:

  • Maintain an OCI registry that tracks every active prime contract, subcontract, teaming agreement, and affiliate role, updated at each new award and each personnel change
  • Assign a named compliance officer for each contract with an active mitigation plan, with clear authority to halt conflicting work
  • Conduct internal audits on the schedule the plan specifies, document results, and report to the CO as required — do not wait for the CO to ask
  • Update the plan whenever a triggering event occurs: a key person leaves, a new subcontractor joins, or the scope changes
  • Coordinate with legal counsel before responding to any CO inquiry about plan compliance

Common mistakes and corrective steps:

  • Missed affiliate disclosure: A contractor discloses its own prior work but omits a subsidiary's advisory contract with the same agency. Corrective step: expand due diligence to every legal entity under the corporate umbrella before proposal submission.
  • Generic firewall language: A plan states "a firewall will be maintained" without naming systems, personnel, or audit procedures. Corrective step: revise to name specific IT systems, specific individuals, and a specific audit schedule before the CO requests revision.
  • Plan not updated after personnel change: A key restricted individual leaves and is replaced, but the plan still names the original person. Corrective step: treat every personnel change as a plan revision trigger and notify the CO within the timeframe the plan specifies.

Pro Tip: Build your OCI registry into your business development intake process, not your contract administration process. By the time you are writing a proposal, you should already know which of your active contracts create OCI risk for the target RFP. That pre-proposal screening is what separates teams that disclose proactively from teams that get protested.


What happens if you fail to disclose or your mitigation plan falls short?

Non-disclosure of an OCI is one of the highest-risk decisions a contractor can make in federal procurement. The consequences range from bid protest and disqualification to termination, suspension, debarment, and civil liability under the False Claims Act.

Administrative and civil remedies:

  • Bid protest and disqualification: A competitor or the CO can file a GAO protest alleging the awardee had an impermissible OCI. GAO has sustained protests on all three OCI types, and a sustained protest typically results in corrective action, re-evaluation, or award termination.
  • Termination for default or convenience: 48 CFR 3452.209-70 and similar model clauses reserve the government's right to terminate a contract if the contractor failed to disclose a known OCI or misrepresented facts in its certification.
  • False Claims Act exposure: If a contractor certifies no OCI exists, receives payment, and the government later discovers an undisclosed conflict, the certification becomes a potentially false claim. Under the proposed 2025 rule, the same risk attaches to noncompliance with an incorporated mitigation plan.
  • Suspension and debarment: Willful non-disclosure or repeated noncompliance can trigger suspension or debarment proceedings, effectively barring the contractor from federal work for a defined period.

GAO protest patterns worth knowing:

GAO decisions on unequal access to information typically turn on whether the contractor actually possessed nonpublic information that gave it a competitive advantage, not merely whether it had access to a related program. Impaired objectivity protests often succeed when the contractor's financial interest in an outcome is direct and quantifiable. Biased ground rules cases are the most fact-intensive and often hinge on how closely the final solicitation tracks the contractor's prior advisory work.

If you discover an OCI after award:

  1. Disclose immediately to the CO in writing, describing the nature, scope, and duration of the conflict
  2. Propose specific corrective actions, including a revised or new mitigation plan
  3. Document every step taken from discovery through resolution
  4. Engage legal counsel before making any representations to the CO about the conflict's materiality

Key FAR sections and solicitation language to watch

Knowing which FAR sections govern OCI and what solicitation language signals a conflict requirement lets you respond precisely rather than generically.

FAR section / provisionWhat it controlsContractor action required
FAR 9.504CO's duty to identify and evaluate OCIs early; recommend resolution before awardCooperate with CO inquiries; respond to requests for disclosure
FAR Subpart 9.5Rules for specific situations: preparing specs, providing evaluation services, obtaining access to proprietary informationReview SOW against these rules before proposal submission
FAR Subpart 9.5Waiver procedures: CO may waive OCI with agency head approval when award is in the government's interestRequest waiver in writing with full factual basis if avoidance/mitigation is not feasible
FAR 9.507-1(b)Solicitation provision language: CO must include a provision describing the nature of the potential conflict and required offeror responseRespond to the provision with a disclosure statement and proposed mitigation plan
FAR Subpart 9.5Examples of common conflict situations illustrating the three OCI typesUse as a diagnostic checklist against your SOW and contract portfolio
48 CFR 3452.209-70Model certification clause: offeror certifies no OCI and discloses any known conflictsComplete the certification accurately; attach disclosure if any conflict exists
NFS Subpart 1809.5NASA-specific OCI rules, including program office involvement and acquisition strategy meeting requirementsFollow NASA-specific procedures for NASA procurements

FAR 9.507-1(b) requires: "The contracting officer shall include in the solicitation a provision that describes the nature of the potential conflict, the basis for the determination that the conflict exists, and the measures to be taken to avoid, neutralize, or mitigate the conflict."

The NASA OCI handbook adds that early program office involvement, ideally at the acquisition strategy meeting stage, maximizes the options available to avoid or neutralize conflicts before the solicitation is released. Once the RFP is out, the resolution options narrow.

Watch for two clause negotiation points that carry disproportionate risk. First, fixed-term restraints in limitation-on-future-contracting clauses: if the clause bars you from competing for a category of work for a defined period, negotiate the scope and duration before award, not after. Second, termination language tied to mitigation plan noncompliance: under the proposed 2025 rule, this language is likely to become standard, so review it carefully with counsel before signing.


What does a contracting officer actually look for in a mitigation plan?

COs evaluate mitigation plans against a short set of concrete criteria. Understanding those criteria lets you design a plan that passes review on the first submission rather than going through multiple revision cycles.

CO evaluation checklist:

  • Specificity: Does the plan name the specific conflict, the specific contracts involved, and the specific individuals or roles restricted? Generic plans are returned for revision.
  • Measurable safeguards: Can the CO verify compliance through observable controls — audit logs, access records, org charts, segregated accounts? If a safeguard cannot be measured, it cannot be enforced.
  • Monitoring and reporting: Does the plan include an internal audit schedule, a named compliance officer, and a defined process for reporting noncompliance to the CO? COs want to see a self-policing mechanism, not just a promise.
  • Legal review: Has the plan been reviewed by legal counsel? COs often ask. A plan that shows evidence of legal review signals the contractor takes the obligation seriously.
  • Duration and termination triggers: Does the plan specify when it expires and what events require revision or CO notification? Open-ended plans with no revision triggers are a red flag.

Documentation COs will request as proof of implementation:

  • Organizational charts showing the separation between conflicted and non-conflicted teams
  • IT access logs or system configuration records showing firewall controls are active
  • Signed personnel acknowledgment forms confirming restricted individuals understand their obligations
  • Subcontractor certifications and flow-down agreements
  • Internal audit reports from prior review periods

What is negotiable vs. non-negotiable:

Duration of personnel restrictions and the specific scope of data access controls are typically negotiable before award. The obligation to report noncompliance to the CO and the government's right to terminate for material plan violations are not. Approach negotiation with a clear factual basis for any proposed modification, and document the CO's agreement in writing.


The part of OCI management most contractors underestimate

The regulatory framework for OCIs is well-documented. The FAR sections are clear. The three OCI types have decades of case law behind them. What practitioners consistently underestimate is the operational gap between a signed mitigation plan and a compliant one.

A mitigation plan that sits in the contract file while the restricted personnel continue attending program reviews is not a mitigation plan. It is a liability. The proposed 2025 FAR changes make this gap more dangerous, not less, because an incorporated plan converts every compliance failure into a potential contractual breach. The False Claims Act exposure that PilieroMazza flags is not theoretical. It follows directly from the combination of a certification, a payment, and a known violation.

The contractors who handle OCIs well share one habit: they treat the mitigation plan as a living document with a named owner, a review calendar, and a direct line to legal counsel. They do not wait for the CO to ask whether the plan is being followed. They report proactively, update the plan when circumstances change, and document every step.

One pattern that consistently avoids disqualification is early, candid CO engagement before the proposal deadline. A contractor that surfaces a potential OCI, explains the facts clearly, and proposes a specific resolution gives the CO something to work with. A contractor that stays silent and hopes the CO does not notice gives the CO a protest record to defend. For high-dollar or waiver-sensitive procurements, involving outside counsel in that initial CO conversation is not optional. It is the difference between a resolved conflict and a sustained protest.


Cut OCI risk in your next proposal with Rfpforgeai

Proposal teams that catch OCI red flags early submit cleaner disclosures, stronger mitigation plans, and fewer corrective-action requests. Rfpforgeai gives your team that early-warning capability built directly into the proposal workflow.

Rfpforgeai

The platform automatically extracts SOW clauses, data-access provisions, and OCI-related solicitation language from uploaded RFPs, highlighting the passages that commonly trigger a conflict review. From there, you can generate a compliance matrix that maps each OCI-relevant clause to your disclosure obligations, pull mitigation-plan templates tailored to the conflict type, and maintain a versioned audit trail that holds up in a protest. During performance, the platform supports continuous monitoring by keeping your mitigation-plan commitments visible alongside active contract requirements, so nothing drifts out of compliance quietly.

If your next federal RFP raises an OCI concern, start with Rfpforgeai and let the platform do the clause extraction and compliance mapping while your team focuses on the substance of the mitigation strategy.


Primary sources and further reading

The sources below are the authoritative texts and practitioner resources that underpin this guide.

SourceWhy it matters
AcquisitionPrimary regulatory text defining OCI, CO duties, resolution methods, and solicitation provision requirements
NASA OCI Handbook (PDF)NASA-specific guidance on resolution method ordering, program office involvement, and illustrative examples
January 15, 2025 proposed FAR ruleProposed FAR rule broadening OCI definitions, requiring tailorable solicitation provisions, and directing contract incorporation of mitigation plans
PilieroMazza: OCI Mitigation Plans and Proposed Rule EnforcementPractitioner analysis of False Claims Act risk and enforcement implications of the 2025 proposed rule
PilieroMazza: Understanding OCI Mitigation PlansPractical guidance on tailoring, implementing, and updating mitigation plans; common contractor mistakes
48 CFR 3452.209-70, Cornell LIIModel certification and disclosure clause language; remedies for non-disclosure including termination and civil penalties
AcquisitionDoD-specific mitigation plan incorporation rules and senior procurement executive briefing requirements for acquisitions over $1 billion
AcquisitionAgency-specific examples of OCI-generating situations and waiver criteria

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources