Confidential MEMORANDUM SCM: Kgomotso Monyeki, Senior Procurement Buyer Date 30 November 2025 Subject: Question and Answers Clarification Tender Number: COR/8044/2025/RFP Tender Description: The provision of Quality Management System (QMS) for a period of sixty (60) months at Airport Company South Africa Background Tender, COR/8044/2025/RFP for the provision of Quality Management System (QMS) for a period of sixty (60) months at Airport Company South Africa was published on 24 October 2025 and will be closing on the 24 November 2025. Questions and Answers Please see the question below: Query 1: Regarding ISO 27001 certification compulsory requirement. SiVEST is a management consultant, not a software developer. However, we work closely with a software company named APLISO. Our intention is to bid together for this tender, with APLISO as SiVESTs subconsultant. SiVEST employs ISO 27001 lead auditors and is aligned to the requirements of ISO 27001 but it not certified. APLISO is ISO 27001 certified. APLISO is the company where any ACSA data will be housed via their cloud platform. Please advise whether APLISO’s ISO 27001 certification will suffice for our bid? Yes, the ISO 27001 certification is a compulsory requirement for this bid. Furthermore, if the bidder is a Joint Venture (JV) or a consortium, the entity responsible for hosting and securing the ACSA data must hold the valid certification. Your proposed structure, with SiVEST as the prime bidder and APLISO as the subconsultant, is acceptable. APLISO's ISO 27001 certification will suffice for the bid's compulsory requirement, provided that the following conditions are clearly outlined in your proposal: 1. Formal Commitment: A formal agreement or commitment must be in place between SiVEST and APLISO, explicitly detailing APLISO's role as the secure data processor and cloud service provider for this project. Tel +27 11 723 1400 Fax +27 11 453 9354 Western Precinct, Aviation Park, O.R. Tambo International Airport, 1 Jones Road, Kempton Park, Gauteng, South Africa, 1632 P O Box 75480, Gardenview, Gauteng, South Africa, 2047 www.airports.co.za Airports Company South Africa SOC Ltd Reg No 1993/004149/30 VAT no 4930138393 Board of Directors: F Zikalala Mvelase (Interim Chairperson), Dr K Badimo, D Hlatshwayo, A Khumalo, G Mancotywa, L Mbotya (Chief Financial Officer), M Mpofu (Chief Executive Officer), Y Pillay, S Sambo, N Siyotula, F Sefara (Company Secretary) Confidential Confidential 2. Architectural Clarity: Your proposal must clearly define the system architecture, demonstrating that all ACSA data will be housed, processed, and managed exclusively within APLISO's certified cloud environment. 3. Governance & Accountability: The proposal should outline the governance model, specifying how SiVEST's lead auditors will ensure ongoing compliance with ISO 27001 controls within the project's operational framework, even though the certification itself is held by APLISO. We advise you to include a copy of APLISO's valid ISO 27001 certificate in your submission. Query 2: Number of airports Kindly advise whether the QMS applies to all ACSA airports or only some? Further, if there are multiple airports, is there a centralised system or is each airport management system separate? E.g. does each airport have their own database of Corrective Actions or is it centralised. The Quality Management System (QMS) will be deployed for nine (9) ACSA airports. The system will be centrally managed from a Central Operating Environment (COE). The system is designed as a centralized, single-instance solution. This means: • Centralized Database: There is one unified database for the entire QMS. All data, including Corrective Actions, Preventive Actions, audit findings, and other QMS records from all nine airports, will be stored in a central repository at the COE. • Distributed Data Collection: While the system is centralized, data entry and initiation of processes (like raising a corrective action) will occur at the individual airport level. • Role-Based Access Control (RBAC): The system will employ a sophisticated RBAC model. This ensures that users at each airport will have appropriate views and permissions tailored to their roles and responsibilities. For example, a user at OR Tambo International Airport will typically see data relevant to their airport, while COE and senior management personnel will have cross-airport visibility for consolidated reporting and analysis. Query 3: Number of users Please can we have an estimate of the number of users of the system. The current estimated number of users is approximately 80. The figure of 80 users is a baseline estimate for the initial rollout phase. It is critical that your proposed solution is inherently scalable to accommodate organic business growth and potential expansion. Your proposal should explicitly detail: • The licensing model (e.g., concurrent users, named users) and its cost implications for scaling. • The technical scalability of the proposed platform to handle an increasing number of users without degradation in performance. • Any architectural considerations that ensure seamless addition of new users. Tel +27 11 723 1400 Fax +27 11 453 9354 Western Precinct, Aviation Park, O.R. Tambo International Airport, 1 Jones Road, Kempton Park, Gauteng, South Africa, 1632 P O Box 75480, Gardenview, Gauteng, South Africa, 2047 www.airports.co.za Airports Company South Africa SOC Ltd Reg No 1993/004149/30 VAT no 4930138393 Board of Directors: F Zikalala Mvelase (Interim Chairperson), Dr K Badimo, D Hlatshwayo, A Khumalo, G Mancotywa, L Mbotya (Chief Financial Officer), M Mpofu (Chief Executive Officer), Y Pillay, S Sambo, N Siyotula, F Sefara (Company Secretary) Confidential Confidential Query 4: Integration of information. Please advise whether there is some data that will need to integrate into other software? Please advise what software that would be. Yes, the QMS will be required to integrate with and export data to other software systems to ensure a seamless flow of information. The key integration and export requirements are: 1. Cloud-Based Scorecard System: The QMS must be capable of bi-directional or one-way integration (as architecturally determined) with the existing ACSA cloud-based scorecard system that houses the QMS performance metrics. Your proposal must address the method of this data exchange (e.g., API, secure file transfer). We expect bidders to propose a robust technical approach for these integrations, including the use of APIs, secure data export protocols, and authentication methods. Signature: Date: 6 November 2025 Tel +27 11 723 1400 Fax +27 11 453 9354 Western Precinct, Aviation Park, O.R. Tambo International Airport, 1 Jones Road, Kempton Park, Gauteng, South Africa, 1632 P O Box 75480, Gardenview, Gauteng, South Africa, 2047 www.airports.co.za Airports Company South Africa SOC Ltd Reg No 1993/004149/30 VAT no 4930138393 Board of Directors: F Zikalala Mvelase (Interim Chairperson), Dr K Badimo, D Hlatshwayo, A Khumalo, G Mancotywa, L Mbotya (Chief Financial Officer), M Mpofu (Chief Executive Officer), Y Pillay, S Sambo, N Siyotula, F Sefara (Company Secretary) Confidential