RFP Template for Selecting EWA Providers: 60 Evaluation Criteria

RFP Template for Selecting EWA Providers: 60 Evaluation Criteria for Businesses
An RFP for selecting EWA providers should evaluate the entire chain from work done, approval rights, available funds, bank disbursement to payroll reconciliation, not just compare interfaces and fees. The template below helps businesses pose the same set of questions to all providers, request evidence, and score based on importance.
> In short: An RFP should include 10 groups with 60 criteria, mandatory exclusion conditions, and a weighted scoring system. Each response must specify: available, needs configuration, needs development, or not supported; and attach documents or demos as evidence.
> Usage note: Nguyen Minh Khang — Strategy Team Specialist, not a complete legal bidding document and not a commitment that Earned Wage Access meets all criteria. Nhan Kiet must respond to each item with current evidence when participating in an actual RFP.
1. How is an EWA RFP different from a typical HR software RFP?
(See also: Checklist for Selecting EWA Providers and How Businesses Evaluate EWA Providers.)
EWA involves HR data, timekeeping, payroll, personal data, and money transfers simultaneously. A display error may only cause inconvenience; a transaction status or approved work error can cause real money discrepancies.
Therefore, an RFP must check five core capabilities:
- No generating funds from future or unapproved work.
- No incorrect payments to wrong people, wrong accounts, or duplicate transactions.
- Explain every cent in the available amount.
- Reconcile transactions with banks and payroll.
- Protect personal data and maintain service during incidents.
If a provider cannot prove any of these five points, businesses should not compensate with a nice interface or low fees.
2. How to request provider responses
Each criterion should have six columns:
| Response Field | Content |
|---|---|
| Compliance Level | Available / Configuration / Development / Not supported |
| Description | How the feature or process works |
| Evidence | Documents, screenshots, data logs, demo, or reports |
| Exceptions | Conditions where the feature does not work or requires manual intervention |
| Time | Time to be ready if configuration/development is needed |
| Cost | Included and additional costs |
Responses with only “Yes” are not accepted. If development is needed, the provider must specify scope, acceptance, deadlines, and responsibilities for delays.
3. Scoring and exclusion conditions
Scoring 0–5
| Score | Meaning |
|---|---|
| 0 | Not supported or no response |
| 1 | Only directional, no plan/evidence |
| 2 | Significant development needed or dependent on unconfirmed third parties |
| 3 | Supported after configuration, with plan and responsible person |
| 4 | Available, demonstrable, and documented |
| 5 | Available, with operational/control evidence and measurable metrics |
Suggested exclusion conditions
- cannot block unworked/unapproved work;
- no mechanism to prevent duplicate payments;
- no account verification for recipients;
- no log of work edits and transaction status;
- cannot link received amounts to payroll;
- no defined roles for personal data processing;
- no serious incident handling process;
- cannot explain the legal nature and parties in the money flow.
Exclusion conditions must be approved before opening the file to avoid changing standards based on sentiment.
4. Group 1 — EWA Operations and Employee Experience (8 criteria)
- Only calculate value from completed and approved work.
- Block current day not closed and future days.
- Display available amount and explainable formula.
- Show details of workdays, received, and reserved amounts.
- Allow employees to request proactively, without needing approval for each order if conditions are met.
- Have a confirmation/consent step before each receipt.
- Clearly display transaction status: pending, successful, failed, needs investigation.
- Provide support channels for incorrect records, incorrect work, or unreceived funds.
Evidence to request: demo from an approved workday to transaction; demo of unapproved work case; sample transaction history and commitment content.
For Earned Wage Access, the system formula is: approved work × daily rate per customer − received during the period − reserved amount, rounded down to the nearest 1,000 VND. This is verification information from the code; policies applied to each customer must still be confirmed.
5. Group 2 — Timekeeping, Work Approval, and Exceptions (7 criteria)
- Receive data from customer systems, ERP, or app.
- Support multiple work templates and shifts crossing midnight.
- Have stable linking between employees and timekeeping codes.
- Permissions to view, edit, approve, and reject work.
- Editing approved work must revert to a review state.
- Log before/after, editor, and time of edits.
- Have processes for shift changes, transfers, resignations, and reduced work after funds received.
Mandatory demo scenario: edit an approved record and prove the available amount is recalculated according to rules; do not erase old traces.
The Earned Wage Access system currently supports customer operations on the /kh portal; customers or Nhan Kiet supervisors can approve based on permissions. Compatibility with multi-level approval processes of each business must be separately tested.
6. Group 3 — Legal and Contract Management (6 criteria)
- Identify the legal entity signing the contract and the signer's authority.
- Provide legal analysis of the model's nature and offset mechanism.
- Employee terms consistent across contract, app, and communication.
- Transparent fee policy, fee bearer, and change conditions.
- Responsibility for incorrect work, incorrect person, duplicate payments, or uncollectible amounts.
- Complaint, service termination, and dispute resolution process.
Businesses should not consider the phrase “not a loan” as a legal conclusion. Providers must present transaction structure, rights, and obligations of parties, then let legal evaluate in the context of specific contracts.
7. Group 4 — Personal Data Protection (6 criteria)
- Define roles of each party in data processing.
- Have a data list, purpose, and processing basis.
- Have notification/consent and mechanism for data subject rights when needed.
- Specify retention, deletion, anonymization, and data return periods.
- Disclose sub-processors, storage locations, and data transfer flows.
- Have data breach handling process and impact assessment records as required.
RFPs issued from 2026 must be legally reviewed according to the Personal Data Protection Law No. 91/2025/QH15 and current guidance documents. Sensitive fields such as ID, photos, location, device, bank account, and salary must be described separately.
8. Group 5 — Information Security (7 criteria)
- Architecture separating environments and sensitive services.
- Authentication, minimal permissions, and periodic rights review.
- Encrypt data in transit and at rest.
- Manage keys, secrets, and bank connection information.
- Audit logs, monitor, and alert abnormal behavior.
- Manage vulnerabilities, updates, and independent security testing.
- Incident response, backup, recovery, and continuous business drills.
Providers must specify which evidence is provided during the file stage, on-site assessment, or secure data room. Internal test numbers do not replace pentests or independent certifications.
9. Group 6 — Integration and Data Quality (6 criteria)
- Have API/file specifications and data dictionary.
- Identify the standard data source when two systems differ.
- Check for duplicates, missing, incorrect format, and total control.
- Have resynchronization, duplicate entry prevention, and version management.
- Have test environment, simulated data, and acceptance criteria.
- Have delay reports, error logs, and handling process.
Providers need to distinguish technical run schedule from committed SLA. For example, the Earned Wage Access system currently has a 30-minute Sheet sync schedule and daily ERP; RFPs must still require service levels, measurement methods, and exceptions in writing.
10. Group 7 — Banking, Disbursement, and Duplicate Transaction Prevention (6 criteria)
- Verify recipient and primary account.
- Have a unique transaction code, immutable across attempts.
- Have concurrent locks to prevent two disbursements for the same request.
- Only record success with valid feedback/signature.
- Hold pending when status is unclear and have investigation mechanism.
- Have an emergency stop switch and controlled reactivation rights.
In the current standard flow, Earned Wage Access disburses through VPBank to verified primary VPBank accounts. Special cases using other banks and applicable scope must be confirmed by Nhan Kiet, not automatically recorded in the RFP as a standard feature.
11. Group 8 — Reconciliation, Payroll, and Audit (5 criteria)
- Have transaction reports by person, customer, and payroll period.
- Reconcile with bank statements and suspense account process.
- Have file/API to bring received amounts into payroll.
- Have controls to prevent used workdays from accumulating in the next period.
- Have a ledger and process for uncollectible amounts.
Evidence to request: a complete sample data set including work, receipt requests, bank feedback, reconciliation reports, and payroll slips with personal information redacted.
12. Group 9 — SLA, Support, and Deployment (5 criteria)
- SLA availability, response, and recovery defined numerically.
- Have P1–P4 levels, focal points, and escalation mechanism.
- Have pilot, training, communication, and change management plans.
- Have RTO/RPO, maintenance schedule, and incident notifications.
- Have periodic service reports and root cause analysis.
Phrases like “almost instant” are insufficient for SLA scoring. RFPs must specify when the clock starts, stops, which log is the standard source, and which cases are excluded.
13. Group 10 — Commerce, Capability, and Service Exit (4 criteria)
- Full pricing structure: deployment, integration, operation, transactions, and additional development.
- Financial, operational capability, and reference cases.
- Data ownership rights, data export, and transition support.
- Process for revoking rights, deleting/returning data, and post-termination support.
Do not require cases too similar just to exclude new providers; instead, evaluate the quality of evidence, control capabilities, and ability to run a safe pilot.
14. Suggested Weighted Scoring
| Group | Weight |
|---|---|
| Operations and Experience | 15% |
| Timekeeping and Exceptions | 12% |
| Legal/Contract | 12% |
| Personal Data | 12% |
| Information Security | 15% |
| Integration | 8% |
| Banking/Disbursement | 10% |
| Reconciliation/Payroll | 8% |
| SLA/Deployment | 5% |
| Commerce/Service Exit | 3% |
Weighted total scores do not replace exclusion conditions. A provider scoring 90/100 but unable to prevent duplicate payments should not proceed to pilot.
15. Three Rounds of Provider Evaluation
(See also: Earned Wage Access Due Diligence File and Pilot Plan Template for EWA and Expansion Criteria.)
Round 1 — Documentation
Check completeness, exclusion conditions, and legal/security evidence.
Round 2 — Scenario-based Demo
Do not let providers choose the most favorable flow. Businesses issue a common scenario: night shift, approved work edit, suspended transactions, resignation, and end-of-period reconciliation.
Round 3 — Controlled Pilot
Select a small scope, run parallel with payroll, set stop thresholds, and measure KPIs. Only expand after discrepancies are explained and correctly handled.
16. Frequently Asked Questions
Should the provider with the lowest fees be chosen?
No, if total costs do not include integration, support, data processing, and exception handling. Costs of transaction errors or payroll discrepancies can exceed unit price differences.
Is it necessary to require all 60 criteria?
Not all criteria have equal weight, but businesses should answer all to know which gaps they are accepting.
Is a successful demo enough to go live?
No. A demo proves functional flow; a pilot tests real data, permissions, support, and reconciliation within a controlled scope.
Can providers respond with “needs development”?
Yes, if they specify scope, time, cost, acceptance criteria, and dependency risks. It should not be scored as an available feature.
Does Earned Wage Access currently meet all 60 criteria?
The article does not conclude that. Many technical capabilities are from the code, but legal documents, SLA, pentest, commercial policies, and operational evidence must be provided by the competent department.
17. Conclusion
A good RFP helps businesses turn the question “what does the application have?” into the more important question: can the entire chain be controlled and where is the evidence? The 60 criteria create a common language for HR, legal, IT, information security, finance, payroll, and procurement. A suitable provider not only demonstrates favorable flows but also explains what happens when data is wrong, banks are delayed, or employees leave mid-period.
---
Author: Nguyen Minh Khang — Strategy Team Specialist, Nhan Kiet Manpower Supply Co., Ltd.
Earned Wage Access Solutions for Businesses: Hotline 0937.022.655 · Email info@nhankiet.vn · Earned Wage Access for Businesses