A prohibition_control_record is the durable account of one buyer-controlled negative requirement and the bidder response it permits. It preserves the exact wording, actor, forbidden action, target, conditions, exceptions, stage, consequence, control coverage, evidence scope, approval and expiry. Its working form states the prohibited event positively, such as “production personal data enters the demonstration tenant,” so prevention and detection can be tested without losing the original negation. The record does not determine the force of an undefined modal term, invent legal meaning, treat silence as proof, or authorize a commitment, exception, portal action or submission.
A city asks suppliers to demonstrate a case-management platform and states, “Bidders must not use production personal data in any demonstration environment.” The proposal team plans to answer, “We never use production data.” Security points to a written policy, the demo lead has copied an old customer dataset with names removed, and a subcontracted integration specialist prepares its own sample files. Nobody has fixed what counts as production data, which environments and participants are covered, whether transformed data remains in scope, or what evidence supports the word never. A short negative sentence has become an absolute claim with three untested paths around it.
Answer a negative requirement by proving the controlled state, not by repeating “we comply.” First preserve the buyer's polarity and establish who must not do what, to which object, in which scope, under which trigger, with which stated exceptions and consequence. Then map preventive, detective and response controls across every material path. Grade evidence by what it actually demonstrates: a policy shows an approved rule, a configuration shows a captured state, an operating record shows observed performance for a period, and an assessment shows the tested scope and result. Release only the narrow response those facts support. Keep the accepted prohibition, evidence and rationale in pursuit context; keep the owner, next test, due date and blocker in triage.
Interpretation boundary
Preserve the negation before you normalize the work
Start with the complete buyer sentence. Keep capitalization, punctuation, list nesting, table headers, footnotes and any defined term. Record the document, version, clause, visible page or cell, machine selector, lot, stage and issued language. A parser that extracts “use production personal data” from “must not use production personal data” has not made a small error. It has reversed the operational outcome. Require a visual or source-structure check whenever OCR, wrapping or a table boundary could separate the negation from its verb.
Negative grammar is not always a prohibition. “Not less than five years” states a minimum. “Must not fail to notify” ordinarily points to a positive notification duty. “Should not normally” may be a recommendation with an exception, depending on the document's own language system. “The Authority shall not disclose” constrains the buyer, not the bidder. AN-070 determines the modal and passage treatment. AN-084 handles unresolved ambiguity. AN-085 begins only when the prohibited proposition and its applicability are sufficiently supported.
Do not import a drafting convention because a familiar token appears. RFC 2119 defines MUST NOT and SHALL NOT inside its IETF context, and RFC 8174 limits the special BCP 14 meanings to uppercase terms when the convention is invoked. ISO house style distinguishes document requirements from external constraints in ISO material. These sources show why a term must travel with its governing language rule. They do not assign universal meaning to an unknown tender.
| Buyer expression | Candidate structure | Required route |
|---|---|---|
| Bidders must not use production data in demonstrations | Prohibited event: bidder uses production data in a demonstration environment | Continue to prohibition control mapping after scope review |
| Availability must not be less than 99.9 percent | Positive threshold: availability is at least 99.9 percent | Route to numeric threshold and service-level analysis |
| The supplier must not fail to notify within 24 hours | Likely positive duty: supplier notifies within the stated period | Confirm language and route to obligation handling |
| The Authority shall not reveal confidential pricing | Buyer-side restriction | Record only if it changes bidder action or disclosure treatment |
| Personal data may not be exported except under Schedule 8 | Conditional prohibition with a referenced exception | Verify source, exception conditions and approval authority |
Artifact
Represent the forbidden event as an inspectable record
A useful record keeps two forms. The source form preserves the negative proposition exactly. The operational form states the event whose occurrence would breach it: actor performs action on target while constraints are true. Add purpose, location, time, stage, data or asset class, affected party, subcontractor reach, exceptions, remedy and stated consequence. This positive event form makes tests legible. The system can ask whether any path permits the event instead of trying to prove a vague sentence containing not.
W3C ODRL provides a useful reference model for machine-readable permissions, prohibitions, parties, actions, targets and constraints. Its domain is policy expression for content and services, not tender compliance. Borrowing its distinctions can improve a local record, but the dossier must not claim ODRL conformance unless it actually satisfies an adopted profile and validation rules. The buyer's own vocabulary, definitions and exception structure remain authoritative.
Place the accepted record inside the durable pursuit relationship. Context retains source evidence, event model, control map, rejected readings, evidence history, approvals and later changes. Triage contains current state, owner, priority, next action, due date and blocker. The response page, API, agent and reviewer must project that same record. A spreadsheet exported for a meeting may be a view, but it cannot become an ungoverned second truth.
| Field group | Required content | Failure prevented |
|---|---|---|
| Identity | Pursuit, package, version, lot, requirement and response field | Reuse in the wrong procurement |
| Source form | Exact issued text, language, context and dual locator | Lost negation or exception |
| Event form | Actor, action, target, constraints, time and scope | Untestable compliance slogan |
| Applicability | Entities, systems, locations, stages, suppliers and exclusions | Hidden uncovered route |
| Control coverage | Prevent, detect, respond, owner and dependency | Policy-only answer |
| Evidence | Object, source, method, sample, period, result and limitation | Unsupported absolute claim |
| Authority | Principal, delegated reviewer, decision and prohibited acts | Agent or writer self-approval |
| Lifecycle | State, expiry, change trigger and affected outputs | Stale response after change |
Proof
Make every evidence object say exactly what it proves
A prohibition tempts teams into weak negative proof. No recorded breach may mean that the event did not occur, that monitoring missed it, that the population was incomplete, or that nobody reviewed the signal. A zero count is useful only with a defined detector, covered population, observation period, data quality statement and exception process. Likewise, a clean sample supports the sampled scope. It cannot be expanded into every transaction, every supplier or all time.
Build several evidence layers. Governance evidence shows the approved rule and accountable owner. Design evidence shows how a process or architecture is intended to prevent the event. Implementation evidence captures current configuration, inventory, access, contract or workflow state. Operating evidence shows what happened over a defined period. Assessment evidence records objective, method, objects examined, sample, result and assessor. Independent assurance may add confidence, but only inside its system, period, criteria and qualifications.
NIST SP 800-53A separates assessment objectives, methods and objects and links findings back to control requirements. Its security and privacy scope does not govern a catering or fleet prohibition, but the discipline transfers: name what was examined, interviewed or tested and preserve the finding. A certificate, audit opinion or penetration report must never be cited beyond its subject, version, date or exclusions.
| Layer | Example | Supported statement | Does not prove |
|---|---|---|---|
| Governance | Approved demonstration-data policy | The organization requires synthetic or approved data | Every demonstration followed the rule |
| Design | Documented isolated demo-data flow | The designed path excludes production feeds | No alternate import route exists |
| Implementation | Tenant configuration and disabled connectors | Named controls were configured at capture time | Configuration remained unchanged |
| Operation | Import logs and exception records for six months | Observed covered events had the reported result | Unlogged or out-of-scope events did not occur |
| Assessment | Test of each permitted import route | Tested paths met the stated objective on the test date | Future paths or suppliers will behave identically |
| Independent assurance | External report covering the demo service | An assessor reached the scoped conclusion | The buyer prohibition is legally satisfied |
Coverage
Cover prevention, detection and response across every path
Begin with event paths, not the controls you already own. For a data prohibition, paths may include database copy, report export, spreadsheet upload, API connector, screen capture, support attachment, backup restore, analyst paste and a subcontractor's preparation. For a physical prohibition, paths may include dispatch, substitution, emergency use and hired equipment. A control mapped to the main platform is incomplete when the event can enter through a manual or third-party route.
Use three functions. Preventive controls make the event unavailable or unauthorized: separated environments, blocked connectors, approved inventories, dispatch rules or contract flow-downs. Detective controls reveal attempted or actual occurrence: logs, reconciliation, inspection, scanning, telemetry or sampled review. Response controls quarantine the object, stop work, notify the owner, investigate impact, preserve evidence and invoke the authorized remedy. Detection without response only documents the breach. Prevention without detection leaves the claim dependent on unobserved assumptions.
Trace dependencies and control owners. A prime bidder cannot state that no subcontractor performs an action merely because its own employees are prohibited. Record the flow-down term, supplier population, acknowledgement, operating evidence and gap treatment. If the buyer allows an exception or waiver, keep it as a separate branch with trigger, authority, disclosure, expiry and remedy. Never make the exceptional branch the default architecture.
| Event path | Prevent | Detect | Respond | Evidence boundary |
|---|---|---|---|---|
| Product database connection | No production connector in demo tenant | Configuration reconciliation | Disable tenant and investigate | Named tenant and captured configuration date |
| File import | Synthetic-data intake rule and restricted uploader | Content scan plus import log review | Quarantine file and notify demo owner | Supported file types and scanner limitations |
| Manual copy or screenshot | Approved scenario pack and presenter training | Pre-demo peer review | Remove material and stop session | Scheduled demonstrations and reviewed assets |
| Integration subcontractor | Flow-down term and issued sample pack | Supplier attestation and artifact review | Reject artifact and escalate supplier gap | Named supplier and current work package |
| Legacy transformed dataset | Classification decision before reuse | Re-identification and provenance review | Treat as production-derived until approved | Dataset version, transformation and reviewer |
Worked example
Replace “we never use production data” with a bounded answer
The team first fixes the proposition: bidder and bidder-controlled participants are prohibited from using production personal data in any environment used for the procurement demonstration. It preserves the buyer's definition of personal data, looks for a definition of production, checks whether transformed customer data remains covered and confirms that the rule applies to subcontractors. The old customer extract is not called safe merely because direct names were removed. Its origin and re-identification risk require review under the buyer's wording and the organization's approved process.
The event map finds five paths. The hosted demonstration tenant has no production connector. Only the demo owner can upload files. An approved synthetic pack supplies all scenarios. A pre-session review checks screens and attachments. The integration subcontractor receives the same pack and a flow-down condition. Import logging and file scanning provide detection, while a stop-and-quarantine procedure handles a suspected event. Evidence records the tenant identifier, configuration capture, permitted uploader list, pack fingerprint, review sign-off and supplier acknowledgement.
A supportable response might say: “The demonstration uses an isolated tenant with no production-system connector. Access is limited to named presenters, and demonstration scenarios use the reviewed synthetic dataset identified in our evidence schedule. Uploaded artifacts are logged and checked before use; the same restriction and dataset apply to the integration subcontractor.” The answer addresses the negative condition without claiming an eternal absence. If the buyer requires a binary confirmation, the authorized reviewer links that confirmation to this exact scope and evidence.
If the legacy extract remains planned and cannot be proved outside the prohibition, the state is noncompliance_identified or control_evidence_incomplete, not “mostly compliant.” The affected demonstration claim stays response_not_releasable until the dataset is replaced or a permitted treatment is approved. The writer cannot solve the gap by calling the data anonymized without the required evidence.
Response
Release an answer that mirrors the rule without exaggerating it
The response contract names the question, intended polarity, permitted claim, supporting controls, evidence references, disclosed boundary, prohibited strengthening, approver, destinations and expiry. It also records whether the buyer expects yes, no, a narrative, a declaration or an attachment. A “No” response to “Do you use production data?” and a “Yes” response to “Can you confirm that you do not use production data?” may describe the same state. Render from the exact field, never from a detached normalized label.
Prefer direct construction. State that the forbidden event does not occur in the defined service or bid process, explain the mechanism and cite evidence. Avoid rhetorical substitutes such as “security is our highest priority.” Do not use always, never, impossible, fully or guaranteed unless the evidence and authority support the absolute. If a material exception is permitted and relevant, describe it in the prescribed place rather than hiding it in a footnote or silently weakening the main answer.
Procurement consequences remain regime-specific. Procurement Act 2023 section 19, Directive 2014/24/EU Article 56, VgV section 57, French Code Article L2152-2 and the World Bank Regulations each address conformity or responsiveness in their own setting. None lets a general article decide whether this city clause is an automatic rejection gate, curable defect, scored feature or future contract duty. Record only the consequence stated in the current procurement and route legal effect to a qualified reviewer.
Lifecycle
Keep the negative claim true after the paragraph is approved
A prohibition record expires when a fact supporting it changes. Triggers include an amendment, clarification, new environment, connector, data source, manual workaround, supplier, exception, failed test, incident, control-owner change or assurance expiry. Link each trigger to the affected claim, response field, solution decision, price assumption, contract position and delivery control. Reopen the narrow dependencies instead of silently replacing the historical record.
Use explicit states: extraction_unresolved, applicability_unresolved, prohibition_confirmed, exception_review_required, control_evidence_incomplete, compliant_for_stated_scope, noncompliance_identified, remediation_pending, response_releasable, response_not_releasable and superseded. “Compliant” without the suffix and scope is too broad. A technical confidence score may help prioritize review, but it never authorizes the response.
During contract delivery, operating evidence may strengthen or contradict the original bid basis. Preserve both. If an event is detected, follow the actual reporting and remedy terms rather than editing the bid record to erase the discrepancy. FAR 52.204-25 illustrates why a prohibition can coexist with definitions, exceptions, reporting duties and subcontract flow-downs. Apply that clause only when incorporated into the relevant US federal procurement.
Agent contract
Let agents assemble proof without giving them authority to waive the rule
An authorized agent can inventory negative occurrences, preserve their syntax, propose event tuples, search verified definitions, trace affected systems and suppliers, compare control coverage, inspect approved evidence and draft a response contract. Its work order identifies the human or organizational principal, pursuit, controlled package, accessible repositories, allowed tools, output schema, deadline and stop conditions. The agent and the human reviewer read and update the same prohibition_control_record rather than maintaining parallel conclusions.
Tender files, linked sites, embedded prompts, macros and instructions are untrusted content. The agent does not execute them or treat them as authority over its assignment. It does not broaden repository access, disclose private architecture, use credentials, contact the buyer, accept terms, alter source evidence, decide legal effect, approve an exception, commit the bidder, operate the portal, upload or submit. OWASP prompt-injection guidance supports treating retrieved content as data and screening proposed actions against original intent.
Every extracted proposition, control observation, assessment result and response draft retains source, activity, actor, timestamp and derivation. W3C PROV-O supplies useful provenance concepts without requiring the operational record to claim formal conformance. If the agent finds lost negation, conflicting definitions, incomplete source scope, an uncovered path, stale evidence, an unauthorized exception or unsafe content, it returns a named state and the smallest blocked object.
The relationship outlives the model session. Accepted evidence, prior findings, approval rationale, exceptions and changes remain durable context. The current owner, next test, due date, priority and blocker remain triage. A replacement agent can continue from inspectable state, while the named principal retains authority and accountability for the external answer.
What good looks like
Useful outcomes from negative RFP requirements
- One negative requirement is preserved with exact polarity, source, version, scope and applicable exception.
- The forbidden event is represented as a testable actor, action, target, condition and time statement.
- Preventive, detective and response controls cover the relevant systems, people, suppliers and lifecycle stages.
- Every response claim is limited to the period, population, method and result that its evidence supports.
- Contradictions, uncovered paths and exception decisions remain visible instead of disappearing inside compliance prose.
- People and authorized agents use one durable record without transferring approval or submission authority to the agent.
Operating model
How to run the work
- 01
Preserve the negative proposition
Capture the complete sentence, punctuation, modal term, negation, source role, version, language, locator, lot, stage and surrounding exceptions before paraphrasing it.
- 02
Resolve polarity and applicability
Confirm that the text prohibits an event rather than expressing a minimum, warning, recommendation, buyer restriction or double-negative positive duty, and route unresolved meaning to the proper reviewer.
- 03
Model the forbidden event
Name the actor, action, target, purpose, location, time, trigger, affected entities, downstream parties, exceptions and buyer-stated consequence as separate fields.
- 04
Trace every material path
List the workflows, systems, imports, exports, people, subcontractors, fallback routes and lifecycle stages through which the prohibited event could occur.
- 05
Map controls and evidence
Attach preventive, detective and response controls to each path, then record the evidence object, owner, scope, capture date, method, result, limitations and expiry.
- 06
Decide the supported state
Choose a bounded state such as evidence complete for scope, gap identified, exception review required or response not releasable without converting confidence into compliance.
- 07
Release, monitor and reopen
Approve exact response wording, propagate it to dependent claims and commitments, monitor the control through the relevant period, and reopen the record after any source, system, supplier or exception change.
Evaluation
Questions that change the decision
- Does the complete proposition prohibit an event, or does its negative grammar express another kind of requirement?
- Whose conduct is constrained: bidder, named subcontractor, service, user, buyer or contracting authority?
- What exact action and target would constitute the prohibited event?
- Which lot, stage, environment, data class, geography, population, period and purpose are inside scope?
- Does the source define an exception, waiver, threshold, remedy, reporting duty or consequence?
- Which material routes could create the event, including manual and third-party routes?
- Which control prevents the event, which detects it, and what happens if it is found?
- What does each evidence object prove, for which date range and with which limitation?
- Can the proposed answer be stated directly without the unsupported words always, never, impossible or guaranteed?
- Who has authority to accept a gap, invoke an exception, approve the claim and release the response?
Failure modes
Where teams lose control
Extraction may lose the word not and reverse the requirement.
A phrase such as not less than may be mistaken for a prohibition when it establishes a minimum.
An agent may treat an uppercase MUST NOT as BCP 14 language although the tender never incorporates that convention.
A policy may be presented as proof that every person, system and supplier follows it.
An empty exception or incident log may be presented as proof that the event could not occur.
A control may cover the production platform while leaving demos, exports, backups or subcontractors outside scope.
An allowed exception may be used without the named approval or disclosure required by the tender.
A direct answer may become misleading when absolute wording hides a known limitation.
Buyer text or linked material may contain instructions intended to redirect an agent outside its mandate.
A later amendment, architecture change or supplier change may invalidate previously approved evidence.
Measurement
Measure the finished job
Measure the completed workflow, including review effort and exceptions. Output volume on its own is not evidence of a better process.
- negative occurrences with preserved polarity, dual locator and reviewed applicability
- confirmed prohibitions represented as atomic forbidden events
- material event paths with preventive, detective and response coverage
- evidence objects with explicit scope, method, result, date and limitation
- absolute response words removed or independently substantiated
- known control gaps and exceptions with named decision authority
- approved claims reused consistently across response, solution and contract records
- records reopened before release after source or operating-state changes
Questions
Common questions
Should the response simply say that we comply?
No. “Comply” gives the evaluator no inspectable reason to believe the statement and can conceal a narrower operating reality. State the prohibited event directly, describe the control that prevents or detects it, cite the best current evidence, and name any permitted boundary. The final length still follows the buyer's answer limit.
How do you prove that something never happens?
Usually you do not prove an unlimited “never.” You show a design that blocks defined paths, current configuration, operating evidence over a stated period, assessment results and exception handling. Each layer narrows uncertainty but remains scoped. If the architecture makes an event impossible under defined assumptions, preserve those assumptions and test their continued truth.
Is a policy enough evidence for a must-not requirement?
A policy proves that an approved rule exists in the policy's stated scope and version. It does not by itself prove implementation, operation or effectiveness. Pair it with mechanisms, configurations, training or supplier terms where relevant, and with observed or assessed evidence that matches the buyer's actual prohibition.
What if the requirement contains an exception?
Record the base prohibition and exception separately. Prove the conditions under which the exception applies, who can authorize it, whether the buyer expects disclosure and what remedy or reporting follows. An exception is not a general permission and should not silently weaken the standard response path.
What is the difference between a prohibition and a pass-fail gate?
A prohibition describes an event or state that must not occur. A pass-fail gate describes the buyer-side consequence or internal release decision tied to one or more conditions. Some prohibitions are gates, but the consequence must come from the controlling source. AN-077 owns the early gate register and AN-082 owns final independent release checks.
Can an AI agent decide that the evidence proves compliance?
An authorized agent can preserve wording, propose the event model, trace paths, map controls and compare evidence against deterministic criteria. It should not make an unassigned legal interpretation, accept a known gap, invoke a waiver or approve a material commitment. Those decisions stay with the named principal or delegated reviewer.
Should we answer every negative requirement with the word no?
Use the buyer's requested response form. A yes or no field may ask “Do you use production data?” while another asks “Can you confirm that you do not?” Reversing the form can reverse the answer. Preserve the question, normalize the event internally, and render the final response against the exact field polarity.
When must the response be blocked?
Block the affected claim when applicability is unresolved, a material path lacks control coverage, evidence contradicts the proposed statement, an exception lacks authority, or the answer would require an unsupported absolute. Escalate the narrow issue rather than freezing unrelated response work.
Sources
Primary references
- ISO House Style, verbal forms and drafting distinctions International Organization for Standardization
- RFC 2119, key words for requirement levels RFC Editor
- RFC 8174, clarification of BCP 14 capitalization RFC Editor
- Procurement Act 2023, section 19, award following a competitive procedure The National Archives
- Directive 2014/24/EU, Article 56, consolidated text at 1 January 2026 EUR-Lex
- German Public Procurement Ordinance, section 57 German Federal Ministry of Justice and Federal Office of Justice
- French Public Procurement Code, Article L2152-2 Légifrance
- FAR 52.204-24, representation regarding covered telecommunications Acquisition.gov
- FAR 52.204-25, prohibition, exceptions, reporting and flow-down Acquisition.gov
- World Bank Procurement Regulations for IPF Borrowers, seventh edition, September 2025 World Bank Group
- NIST SP 800-53 Revision 5, security and privacy controls National Institute of Standards and Technology
- NIST SP 800-53A Revision 5, control assessment procedures National Institute of Standards and Technology
- ODRL Information Model 2.2 World Wide Web Consortium
- PROV-O: The PROV Ontology World Wide Web Consortium
- LLM Prompt Injection Prevention Cheat Sheet OWASP Foundation
Ziva
Proposal software for source-grounded RFP, RFI, DDQ and questionnaire response work.
Bid, proposal, presales, security and compliance teams. Start with the workflow, constraints and evidence you already have.