Interactive Gaming Council's Notice of REQUEST FOR PROPOSAL INDUSTRY CENTRALIZED ON-LINE "RISK MANAGEMENT DATABASE" REFERENCE SERVICE
Development and Management Services

Deadline for Expression of Interest: February 18,1999
Deadline for Submission of Proposals: March 5, 1999
Deadline for Best and Final Proposals: March 16, 1999
Contract Award Date: March 26, 1999

SUMMARY OF OPPORTUNITY

The Interactive Gaming Council (IGC) is the leading non-profit trade association representing operators and vendors in the on-line gaming and wagering industry worldwide. The association's membership includes the largest Internet casino operators, software vendors and other providers to the industry.

From the vendors submitting Best and Final Proposals in response to this RFP, the IGC will designate and promote one primary vendor as its officially sanctioned and exclusive provider of central relational database reference services (the "Risk Management Database"). This vendor will have the opportunity to develop and manage a real-time data reference service with the aim of becoming the dominant database service for the industry.

Merchants will use the reference database to assess consumer credit risks associated with prospective purchase transactions. Participating merchants will contribute credit data and other non-credit card purchase data, to form a central "pool" of aggregated reference data. In determining associated risks of a particular pending on-line Internet transaction, the incoming transaction data will be referenced against the "pooled" central database of previously experienced credit card transaction records. Any negative credit experiences associated with a particular card or cardholder, including fraudulent activity patterns and excessive credit card transaction chargebacks are then flagged on the card record. If that card record is seen again, the next merchant will have the benefit of all previous merchant experience with the card or cardholder.

In addition to maintaining this primary database service, the vendor will be expected to make available additional risk management services, for example the comparison of incoming transactions against known patterns of credit risk factors, through the use of real time Boolean "rule" routines, artificial intelligence and other transaction screening.

The database "dips" would automatically and instantaneously return an advisory code to the merchant, advising the operator to decline or accept the transaction. In some cases, the vendor may be asked to establish pre-set "flags" to automatically accept or decline transactions based upon tolerance criteria established by the Merchant(s).

As all operators will be non-US based companies and all transactions will occur on the Internet, the Risk Management Database must be maintained outside the U.S. preferably in the Western Hemisphere and in a jurisdiction where English is spoken. However, the IGC will consider a phase-in program which might allow the database to be deployed temporarily in another location, but moved entirely off-shore at a later date.

The vendor must agree to share ownership of the data in the database with IGC.

The IGC suggests that this prospective venture represent an excellent long-term source of revenue for interested vendors. The IGC views this project as a service to its members as well as a valuable source of shared revenues to the association that will allow the IGC to further the Industry's development. The IGC encourages the vendor to describe in its proposal the structure and possible revenue sharing relationship that might be envisioned with the IGC.

SPECIFICATIONS

Data Capture: Data may be received by the vendor either via dial-up telephone connection, or via Internet. Internet data typically will be received directly from the operator's host server, relaying the relevant fields to the Risk Management Database vendor via TCP/IP or dedicated line. The query may also be generated by, or relayed through, the operator's transaction authorization service vendor. Thus, the Negative Data Base vendor's system must be interoperable with the source system-of-choice chosen by the operator, using popular industry protocols.

The vendor should be able to accept and provide adequate service to clients from almost any location in the world.

Data Communications: The data communications environments are the vendor' choice.

Security: At a minimum, vendor should ensure all transactions are SSL encrypted. Higher level encryption is optional and desirable.

Data Fields: At a minimum, IGC requires capture of numerous fields of data, including: transaction date, capture of credit card numbers, expiration dates, zip code, numeric address, cardholder name as it appears on the card, vendor ID #, vendor sub-ID#. In addition, the vendor should be prepared to capture non credit card data, such as passwords, e-mail addresses, additional address and name information, phone numbers (ANI, for phone submissions), fields related to money order payments, wire transfers, incoming checks and other forms of payments from consumers to operators. The database should be designed to allow for evolution of the design, number of fields and relational operation.

Negative Data: At a minimum, the vendor should be capable of retaining only those cardholders for which there is a negative experience, such as an experienced chargeback, incidence or inference of fraudulent use, blocked cards, and so forth. The vendor may be requested to maintain a "positive" database of all cards submitted, for a certain period of time.

Retention of Records: At a minimum, the active reference database should maintain the negative data accumulated for the previous 6 months, and not more than 12 months. All records must be archived to tape or disc and maintained securely in a vault for a period of no less than 2 years.

Data Sorting: At a minimum, the database should be accessible by clients at three levels: 1) local level, yielding data only submitted by the individual client merchant, 2) vertical industry pool, i.e. all data contributed to the pool by all clients; 3) customized, sorting and excluding by merchant, merchant type (e.g. casino vs. sports book) transaction size, decline type (e.g. declined for AVS, declined because of rule violations, declined because of a block or previous experience, or sorting and excluding by other criteria).

Database Scalability: The volume of queries that may be expected depends upon the marketing success of the vendor. One rough estimate indicates there are currently between 750,000 and 1,000,000 transactions per month occurring in throughout the industry. Of course not all industry transactions would be routed to the IGC's designated Risk Management Database, since merchants may rely upon their own database, or a competitor's. However, for proposal purposes, submitters may consider the following minimum volumes of real time queries to the IGC sponsored database:

Quarter 1: 2,000 transactions per day
Quarter 2: 5,000 transactions per day
Quarter 3: 10,000 transactions per day
Quarter 4: 15,000 transactions per day

Vendor should develop systems with proper load balancing and scalability so that the system can scale to at least 100,000 transactions per day without abnormal system fault-tolerant stress.

Transaction Elapsed Time: All transactions will be data communicated to the negative database via TCP/IP or dedicated line. The maximum mean response time-in-system for a transaction should be 8 seconds for an Internet transaction, 5 seconds for a transaction via dedicated line.

System Fault Tolerance: The database should be available for real-time access 24-hours a day, 7-days per week, 365 days per year with 99.5%+ up-time reliability, except for Act of God circumstances beyond reasonable avoidance by the vendor.

Redundancy: The system should be fully redundant, preferably with mirror sites not on the premise of the primary processing and database facility.

BUSINESS TERMS

Exclusivity: IGC will agree not to enter agreements with any other vendor for a period of at least one year, automatically extendable to two years if all conditions are met. During this time, the vendor may use in its marketing an appropriate reference to being the Exclusively Authorized database of the IGC, or other terms as negotiated.

Additional role of IGC: IGC will not be active in any respect with the operation of the database service with the following exceptions: 1) IGC will actively promote participation in the database by its members and among non-members; 2) IGC will have the right to disapprove any proposed client of the Risk Management Database Service that IGC determines may adversely affect the organization or otherwise affect the integrity of the database; 3) IGC will have the right to approve all contract terms and pricing terms, but will not unreasonably withhold its approval.

Data Confidentiality: All data and information must be kept strictly confidential and well secured in a guarded and security-protected building and office. To the extent possible, the vendor will use double-blind coding systems and other methods to ensure the privacy of cardholders and its clients. The IGC reserves the right to inspect the vendor's premises for the purpose of auditing data security at anytime, without notice. The vendor will be required to provide full cooperation.

Restrictions on use of the data accumulated: Any data accumulated in the Risk Management Database may not be revealed to other parties, sold, rented or used in any way that is not approved by the IGC. The vendor may offer additional services to clients participating in the Risk Management Database. However, the vendor may not inappropriately use the client relationships it establishes for the Risk Management Database to unfairly compete with similar businesses, such as those that might provide authorization, credit collection services, credit card merchant accounts or other processing services. In particular, the vendor will not be allowed to subsidize the Risk Management Database service from revenues generated from other agreements with Database clients, or to unfairly "bundle" the database service with other services it offers.

Ownership of the data: Unless another arrangement is negotiated with IGC, the data accumulated in the Risk Management Database will be owned free and clear by the vendor; however, the vendor will agree to provide an exact duplicate copy of the data to IGC, which copy IGC will own free and clear, unrestricted by the vendor. The purpose of the IGC's ownership of the data is to insure a smooth transition between vendor, if, at any point, there is a catastrophic default in the performance of the vendor, or at the time the IGC's exclusive contract with the vendor expires. Except in those circumstances, IGC will maintain its copy of the database for archival purposes only and, in no case, will use its owned copy of the data to empower another vendor to compete with the primary vendor. The vendor will be required to provide weekly copies of the data to a custodian of IGC's choosing.

Pricing: The vendor will determine the pricing structure and submit it to the IGC for approval. This proposal would include proposed arrangement to compensate IGC for its sanctioning of the vendor and promotion of the service within the Industry which, hopefully, will be instrumental in establishing the IGC-sponsored Risk Management Database as the dominant such service within the Internet Gambling Industry.

Payment to IGC: For providing exclusivity and active promotion, IGC will receive fair compensation and share in the revenues generated by the vendor from the Industry Risk Management Database. Fees and revenue sharing arrangements should be addressed in the proposal.

SUBMISSION OF PROPOSALS

To be eligible to submit a proposal to the IGC, for the development and management of the Risk Management Database, vendor must first submit a letter of qualification and interest to the IGC. The letter should contain:

    1. Date of the letter
    2. Official name of the business interested in submitting a proposal
    3. Indication of the true ownership of the business submitting the proposal
    4. A brief description of the business' qualifications and experience
    5. The name of the contact person
    6. Full contact addresses and phone numbers

Letters of Interest must be received by the Executive Director, at the address below, no later than midnight, February 18, 1999*.

Letters of Interest and Proposals should be delivered to:
Alan Schneider
Executive Director
Interactive Gaming Council
1500-701 West Georgia Street
PO Box 10127
Vancouver, BC Canada
V7Y 1C6


Tel. 604-642-6464
Fax 604-801-5911
e-mail: info@igcouncil.org

*Postmark all correspondence for proof of date of submission.

After Letters of Interest are received and acknowledged, Submitters may proceed to submit a proposal. The proposal may be of any length and in any format of written presentation. The minimum information that must be included in the proposal is the following:

    1. A listing and explanation of the functions and features that will be available to clients from the vendor;
    2. A description of the technical systems that will be used to operate the database;
    3. If the systems are not yet developed, (such as for vendor who intend to construct the system off shore from the outset) a critical path timeline indicating the landmarks for completion of the system and the date by which the system would become operational
    4. An outline of the key contract terms for prospective clients of the service
    5. An outline of the proposed pricing structure for the service, including any revenue sharing mechanisms with the IGC
    6. A description of measures taken to protect the privacy of cardholders and clients
    7. A listing of any other business activities that the vendor may be engaged in, or intends to be engaged in, that related to the Internet Gaming industry. (Such activities will not disqualify the vendor, however, the vendor must address how the Risk Management Database service will be kept properly independent).
    8. A discussion of the financial viability of the vendor, addressing concerns the IGC may have about assuring continuity of the vendor.

Proposals must be received by the Executive Director, at the address above, no later than midnight, March 5, 1999*.

After receipt and review of the proposals, the IGC Board will choose finalists among the qualified Submitters. Those finalists will meet with the IGC and formally present their proposals. Finalists will be given the opportunity to submit a "Best and Final" proposal no later than March 16, 1999, to the Executive Director at the stated address.

The IGC Board thereafter will evaluate all Best and Final proposals and will select one winning vendor and one back-up vendor with whom to enter contract negotiations.

The Interactive Gaming Council reserves the right to modify, alter or retract this proposal.  


Interactive Gaming Council 1999, click here for contact information. and here for homepage.