July 18, 2026

MAV's AI Vendor Register Has Six Scoring Categories. Only One Can't Be Negotiated.

procurementregulatory

In October 2025, the Municipal Association of Victoria published the evaluation criteria it uses to vet AI vendors for a statewide procurement register covering local council planning departments. Six categories, weighted. Five of them let a vendor score well with nothing more than a credible, time-bound roadmap in place of a finished capability. One doesn't: Regulatory & Legislative Compliance, weighted at 25% — the highest of the six — with a hard rule that suppliers scoring under 50% "should not be included on the Register." No roadmap, no exception.

I've read rubrics like this from both sides of the table — as a buyer, evaluating freight and 3PL proposals against weighted, partly-negotiable criteria of my own, and as a bidder. My business applied for a logistics and distribution tender last year and didn't get shortlisted. The documentation burden alone was heavy enough to strain a small team, and once it was clear the field included well-established incumbents, the odds were obvious fast. That's the version of this worth telling — not a clean win. So when I read a document built to make one category a hard gate and everything else negotiable, I'm reading it as someone who's felt what sitting on the wrong side of a rigid evaluation criterion actually costs a smaller supplier. Here's what the document actually says, and what any buyer — public or private — should take from it.

The gate and the five categories that bend

| Category | Weight | Roadmap accepted instead of current capability? | |---|---|---| | Strategic Relevance & Capability | 20% | Yes | | Governance, Ethics & Human-Centred AI | 20% | Yes | | Regulatory & Legislative Compliance | 25% | No | | Data Usage, Security & Technical Standards | 15% | Yes, if evidence is "in place or in progress" | | System Adaptability & Improvement | 10% | Yes | | Sustainability & Implementation Support | 10% | Yes |

Every response is scored 0–4 against these weights. That single asymmetry — one non-negotiable floor, five negotiable ceilings — is the most useful piece of information in the whole document, because it tells you where the assessors actually think the risk sits. Not in whether the AI works well. In whether it's legal.

Reading it as a bidder, not a commentator

If you're a vendor answering this rubric, the strategy writes itself once you see the asymmetry: clear the compliance gate cold, because there's no partial credit for good intentions there, and spend your credibility everywhere else on a specific, dated roadmap rather than overclaiming a capability you don't have yet. A vendor who tries to bluff compliance and hedge on ethics has the risk allocation backwards. A vendor who nails compliance and is honest about a governance gap, with a real timeline attached, is playing the rubric as designed.

That's the kind of read you only get from having sat on the wrong side of an evaluation criterion yourself. Which brings me to the part of this that isn't hypothetical.

What losing a tender actually teaches you about "hard to meet"

Last year my business applied for a government logistics and distribution tender and wasn't shortlisted. Two things stood out. The documentation burden was genuinely prohibitive for a team our size — not because the requirements were unreasonable individually, but because there were so many of them, and each one took real hours to answer properly. And once we could see the field included strong, established incumbents, we knew our realistic odds had already narrowed before evaluation even started.

Here's the uncomfortable insight that comes out of putting that experience next to MAV's rubric: a narrow, binary gate — like the compliance floor here — can actually help a smaller, capable vendor, because either you meet it or you don't, and there's no room for an evaluator's subjective comfort with a familiar incumbent to creep in. It's the heavy, open-ended documentation burden that tends to favour incumbents regardless of what the rubric intends, because a large, established supplier has already amortised that paperwork cost across dozens of previous bids. If you're a small vendor deciding whether a register like this is worth the effort, the answer depends less on how strict the criteria look on paper and more on how much of the burden is a hard yes/no gate versus an open-ended documentation exercise.

The clause nobody else is writing about

Buried in the accompanying procurement guidelines is a set of AI-specific conflict-of-interest disclosures that go further than almost anything else published on AI procurement in Australia. Vendors must disclose if their systems were trained on, or incorporate, data from property developers or planning consultants who have business before the council — a direct line to whether the AI's recommendations could be quietly biased toward its own training data's interests. They must disclose if vendor compensation or performance metrics are tied to specific planning outcomes, which would create an incentive for the AI to nudge toward approvals. And, most pointedly, vendors must disclose where protecting their own proprietary algorithm limits how transparent they can be about how the AI actually reaches its recommendations — forcing the vendor to name, in writing, the exact point where their commercial interest works against the council's oversight duty.

That last disclosure is quietly the sharpest thing in the whole framework. Most AI procurement guidance treats transparency as a feature to be assessed. This treats the limits on transparency as something the vendor has to actively confess.

The verification burden the register doesn't remove

It's worth being precise about what this register actually does, because "pre-assessed vendor panel" can sound like more of a guarantee than it is. The compliance section explicitly tells councils they'll still need to independently verify privacy alignment, supply chain transparency, cybersecurity certifications, and cultural data handling — the full list, not a subset. So the register lowers the cost of finding a shortlist of plausible vendors. It doesn't remove the buyer's own duty to check the claims. Any council — or any private buyer looking at a similar vendor panel — should read "pre-assessed" as "pre-filtered," not "pre-verified," and budget the due diligence time accordingly.

What any buyer should steal from this

Three things are worth lifting into a procurement process regardless of sector. First, the hard-gate design itself: pick the one thing you genuinely can't compromise on — for most buyers that's legal compliance, not technical sophistication — and make it a binary gate rather than a weighted, negotiable score. Second, the model-lifecycle contract clauses this framework requires: a defined schedule for model updates and retraining, audit trails of previous model versions, a contractual obligation to notify the buyer of material changes in the AI's behaviour, and a contingency plan for what happens if the vendor goes under or gets acquired. Most procurement contracts, in any sector, don't yet ask for any of this. Third, the AI-specific conflict disclosures — adapted to your own sector's version of "trained on a competitor's or a counterparty's data," they're a genuinely useful addition to any vendor due diligence checklist, AI or otherwise.

If you're a small supplier bidding into a process like this, the lesson is the mirror image: find out early which parts of the evaluation are a hard, binary gate and which parts reward a well-written roadmap, because that's where your limited time is actually worth spending. The rubric tells you, if you read it as a bidder instead of a spectator.