Skip to main content

Terms of Reference (ToR) for Software Development Firm 

Institute for Community Based Sociotherapy (ICBS)

The Institute for Community Based Sociotherapy (ICBS) is a Non-Governmental Organization (NGO) registered in the Netherlands. The institute works as a global expertise network, uniting professionals, and organizations from different parts of the world that implement community-based sociotherapy (CBS). CBS has been developed in 2005 in Rwanda, as an integrated Mental Health and Psychosocial Support (MHPSS) and Peacebuilding (PB) approach. 

Rate this employer
Average: 4.7 (13 votes)

Terms of Reference (TOR) for Software Development Firm 

Project Title: From one-o+ mapping to a living service ecosystem: Development of an Interactive Actor Mapping and Referral System for Mental Health and Psychosocial Support (MHPSS).

Contracting authority Institute for Community Based Sociotherapy (ICBS), in coordination with Rwanda Biomedical Centre – Mental Health Division (RBC-MHD) Ministry of Health (MoH)
Assignment Design, development, deployment, training, handover and support of a secure national digital platform for all national and international MHPSS actors in Rwanda
Primary users  Government institutions, MHPSS actors, service providers and authorized referral users

1. Background 

Rwanda has progressively decentralized mental health care and integrated it into primary care. Rwanda Biomedical Centre - Mental Health Division (RBC-MHD) also coordinates a growing network of governmental and non-governmental actors providing community-based Mental Health and Psychosocial Support (MHPSS) services, that intersect with other wider peacebuilding and development interventions.

Current information on MHPSS actors, services and referral pathways is fragmented across separate and often static systems and mappings. As projects, focal persons and geographic coverage change, mappings quickly become outdated. This limits coordination, creates duplication and gaps, and makes referrals and follow-up di+icult to manage. RBC-MHD and its partners, in partnership with other relevant ministries and government institutions, therefore seek a secure, sustainable platform that turns one-o+ mapping into a continuously updated service ecosystem, with the potential to work inter-ministerial.

2. Objectives 

The assignment is to design, develop, deploy and support a user-friendly national digital platform that improves coordination among actors that o+er services related to MHPSS and other relevant sectors, and strengthens referral and counter-referral pathways. 

The platform will:

  • maintain an up-to-date registry of actors, services, activities and geographic coverage; 
  • identify service, geographic and resource gaps and reduce duplication; 
  • enable secure referrals, follow-up, feedback and counter-referrals; 
  • provide aggregated dashboards, maps, data visulization and reports for planning and policy; 
  • support data quality, accountability and organizational learning; and 
  • remain scalable, interoperable and maintainable by the responsible institutions. 

3. Scope of Work 

3.1 Requirements and co-design 

The firm will conduct stakeholder consultations, document business processes and data flows, define user roles and permissions, assess existing systems and integration points, and agree the final functional and non-functional requirements with RBC-MHD, ICBS and other identified partners. The approved System Requirements Specification (SRS) will be the baseline for development and acceptance. 

3.2 Core platform modules

Module  Minimum purpose
Actor registry and service directory Validated profiles covering organizational mandates, services, target groups, activities, staffing, geographic coverage and relevant resources.
Interactive map  National and subnational visualization of actors, services, gaps and agreed hotspots using aggregated, non-sensitive data.
Dashboards and reports Configurable indicators and comparisons for coordination, monitoring, trends and decision-making, including agreed activity and referral statistics.
User and organization management Registration, validation and administration of organizations and users, with role-based permissions for public users, organizational users and administrators, validators, referral users, government administrators and technical administrators.
Referral and counter-referral Secure creation, receipt, acceptance or decline, status tracking, feedback, completion or closure, and counter-referral, with an audit trail and aggregated reporting.
System administration Configuration, data validation, audit logs, backups, access management and operational monitoring.

3.3 Data management and access 

  • Provide a public area with general information and aggregated dashboards, and secure areas for registered and authorized users. 
  • Allow each organization to manage its own information and view approved information from other actors according to access rules. 
  • Preserve previous records and a complete history of changes rather than overwriting data. 
  • Apply data minimization: referrals must collect only information necessary for referral and follow-up, with sensitive data restricted to authorized users. 
  • Include data-validation and quality-control workflows and require users to accept an information-access policy. 

3.4 Interoperability, hosting and sustainability 

The platform must support secure data exchange with relevant current and future government systems, where authorized and technically feasible. The firm will propose standards, documented APIs and integration methods; document data structures and procedures; and avoid unnecessary dependence on proprietary technology. Specific integrations will be confirmed in the SRS. 

The firm will propose a hosting and publication approach compatible with government requirements, including access through relevant institutional websites or portals. The architecture must support nationwide use, future modules and handover to RBC and/or another designated government institution. 

4. Functional and non-functional requirements 

The solution must: 

  • be responsive on computers, tablets and mobile devices and support commonly used browsers; 
  • provide an intuitive, accessible interface and configurable language options agreed during inception; 
  • scale to additional users, organizations, services, locations, data volumes and modules without complete redevelopment; 
  • maintain acceptable performance and availability as usage grows; • use secure authentication, role-based access, session controls and multi-factor authentication for administrators and other high-risk roles; 
  • encrypt data in transit and, where appropriate, at rest;
  • maintain audit logs, version histories, automated backups and tested recovery procedures; 
  • support vulnerability assessment, security testing and incident-response procedures; and 
  • comply with applicable Rwandan data protection, security and accessibility requirements. 

A final security assessment is required before go-live. All critical and high-risk vulnerabilities must be resolved before final acceptance. 

5. Deliverables and acceptance 

All deliverables require review and formal approval by RBC-MHD and ICBS. The firm must address comments within agreed timelines. Approval will consider completeness, technical quality, consistency with the SRS and incorporation of stakeholder feedback. Payments are made only after formal approval of the relevant milestone.

#  Deliverable  Minimum content
1  Inception report Understanding of the assignment; methodology; work plan and milestones; stakeholder engagement; risks and mitigation. Present for validation within 30 days of contract signature.
2  SRS and system design Approved functional and technical requirements, roles, workflows, data flows, architecture, database schemas, APIs, security design, integrations and user-interface mock-ups.
3  Monthly progress reports Progress, stakeholder engagement, decisions, issues, risks, mitigation and next steps.
4  Prototype / proof of concept Demonstration of core workflows, dashboard concepts, data integration and user interaction; revised following stakeholder feedback.
5  Configured functional platform Approved modules operational and ready for UAT, meeting agreed functional, security, performance and usability requirements.
6 Security and governance framework Security controls, data governance, ownership and access rules, data-sharing arrangements, incident handling, retention, archiving and secure deletion.
7  Testing and UAT package Functional, integration, performance, security and data validation results; UAT plan, issue log, resolutions and approved final adjustments.
#  Deliverable  Minimum content
8  Training and support materials Administrator and user manuals, technical documentation, multiple in-person trainings with users of the system and initial help-desk/troubleshooting support.
9  Final report and handover package Final report; source code; schemas; APIs; configuration and deployment files; test records; manuals; administrative access; and enhancement recommendations.
10  Support and maintenance plan Warranty and included support period; channels and hours; incident response and resolution targets; escalation; defect correction; patches; upgrades; enhancement process; and estimated annual costs thereafter.
11  Close-out and knowledge transfer Formal handover, close-out workshop and practical transfer to RBC's IT team and other designated staff.

6. Firm qualifications and proposed team 

The firm must demonstrate substantial experience and expertise in developing large-scale, interactive information systems with a focus on data integration, security, an interoperability. We expect the following qualifications:

  • at least five years of relevant software development and systems-integration experience; 
  • successful delivery of comparable management information systems, preferably for government, social protection, health, mental health or NGO programmes; 
  • experience with scalable architecture, databases, APIs, data warehousing, analytics and secure interoperability; 
  • knowledge of data protection, privacy, cybersecurity and secure software-development practices; 
  • capacity to manage multi-stakeholder projects using an agile or iterative approach; and 
  • experience in consultation, change management, training and institutional knowledge transfer. 

The proposed team should cover project management, business and systems analysis, software architecture and development, database and integration engineering, user experience design, cybersecurity, testing and quality assurance, training and support. Familiarity with Rwanda's institutional and technical environment is strongly preferred. 

7. Proposal requirements 

Technical and financial proposals should include:

  • the firm's understanding of the assignment and proposed solution; 
  • methodology, development approach, stakeholder engagement and change management plan; 
  • proposed architecture, interoperability, security, hosting and sustainability approach; 
  • work plan, milestones, dependencies, risks and quality-assurance arrangements; 
  • team structure, roles, availability, CVs and relevant certifications; 
  • evidence of comparable assignments and references; 
  • itemized costs for development, testing, training, deployment and support; and warranty, maintenance, licensing, recurring fees and estimated long-term operating costs. 

8. Proposed payment schedule 

Payment  Milestone
20%  Approval of the inception report and SRS.
20%  Approval of the system design and prototype / proof of concept.
25%  Delivery of the functional core platform and interactive dashboard, ready for testing.
20%  Successful testing, UAT, quality assurance and training.
15%  Project closure, knowledge transfer and final handover of all documentation and support plans.

9. Evaluation criteria 

Proposals will be evaluated on:

Criterion  What will be assessed
Technical experience Comparable systems; data integration, APIs, analytics and cybersecurity; relevant sector and Rwanda experience.
Understanding  Clear interpretation of the objectives, users, workflows, interoperability and data-protection requirements.
Methodology  Feasible iterative approach, stakeholder participation, work plan, risk management, quality assurance, training and support.
Team  Relevant qualifications, experience, roles, availability and certifications of key personnel.
Cost and sustainability Transparent and proportionate costs, value for money, licensing implications, recurring costs and long-term maintainability.

10. Data protection, ownership and licensing 

All data must be processed in accordance with applicable Rwandan data protection law and approved governance arrangements. Access to personal or sensitive information must be limited to authorized users and based on documented roles and purposes. 

Upon final payment, RBC and/or another designated government institution will have exclusive ownership of all project-specific deliverables, including source code, database structures, architecture, APIs, configuration and deployment files, interface designs, documentation, training materials, testing records, administrative accounts, and any domain or hosting accounts procured under the project. 

The firm must disclose all proposed third-party, open-source and proprietary components, including licence terms, restrictions, recurring fees and maintenance implications. No component that creates unnecessary vendor lock-in or prevents future operation, transfer, modification or development may be used without prior written approval. 

11. Application process and submission guidelines 

Interested software development firms must submit their complete proposals electronically to tender@icbs.ngo, addressed to Mr. Diogene Karangwa, General Lead of the Institute for Community Based Sociotherapy, by 19October 2026. Late submissions or proposals sent through alternative channels will not be considered for evaluation. The subject line of the email should clearly state: "Proposal: Interactive Actor Mapping – [Your Company Name]". 

Required Submission Package 

To be considered for evaluation, applicants must submit two separate files: 

1. Technical Proposal 

  • Company Profile: A brief overview of the firm, legal registration documents, and evidence of financial stability. 
  • Relevant Experience: Case studies or references from at least three (3) similar projects, ideally involving secure national digital platforms, referral systems, or health-related ecosystems. 
  • Proposed Methodology: A detailed technical approach demonstrating how the firm will design, develop, deploy, and support the platform according to the objectives.
  • Project Timeline & Work Plan: A clear roadmap including key milestones, deliverables, and quality assurance processes. 
  • Team Composition: CVs and professional certifications of the core team members (e.g., Lead Architect, Frontend/Backend Developers, UX/UI Designer, Project Manager) who will be assigned to this project. 

2. Financial Proposal 

  • Itemized Budget: A detailed breakdown of costs related to development, licensing, training, handover, and ongoing technical support. 
  • Payment Schedule: Proposed payment milestones tied directly to the project deliverables outlined in the technical work plan. 

3. Administrative documents 

  • Company full registration certificate 
  • Valid tax clearance certificate 
  • Valid RSSB clearance certificate
Click on the APPLY button to send your application documents:
  • Your application will be sent to the employer immediately (Allowed formats: .doc .pdf .txt .docx)
  • A confirmation email will be sent to you few minutes afterwards
  • You can request any documents archived from our website (ex: a job description, a CV, a cover letter...)