RICS AI Standard

Compliance resources

The RICS professional standard Responsible Use of Artificial Intelligence in Surveying Practice (effective 9 March 2026) is mandatory for all RICS members using AI tools in practice. These resources are designed to make compliance straightforward when using Tendermark — organised by the standard's own section numbers, so each asset files against the requirement it answers.

Current edition: Edition 2 · July 2026

RICS AI standard s2 · s4.4 · reviewed 30 July 2026

How Tendermark works

Suitable for due diligence records, your AI risk register, and s4.4 explainability requests from clients

Tendermark is a tender comparison tool for building surveyors. The surveyor authors or uploads a Schedule of Works — the structured list of work items priced in a tender. Contractors price against that Schedule, either by completing an online pricing form or by returning a document (PDF, spreadsheet, scan, or photograph). Tendermark extracts the contractor's prices and produces a side-by-side comparison table.

What the AI does: Tendermark uses a large language model (Anthropic Claude) for four distinct tasks.

  • Contractor return matching. For every uploaded return — whether Excel, CSV, PDF, Word document, scanned document, or photograph — Claude reads the content and maps each contractor price to the correct Schedule of Works line item. The file is preprocessed into a readable form first (cell values extracted from spreadsheets, text extracted from PDFs); Claude then handles all line-item matching. This is the primary use of AI in Tendermark and applies to every contractor return regardless of format.
  • Schedule of Works parsing (fallback only). When a surveyor uploads a SoW in an unusual format — a scanned document or prose-style Word file — Claude identifies the line items. Standard formats such as Excel and CSV are parsed by code without AI involvement.
  • Tender Analysis Report narrative drafting. Three sections of the report are drafted by Claude: Arithmetical Accuracy (discrepancies between each contractor's stated and implied totals), Anomaly Handling (observations on flagged pricing items), and Summary of Submissions (price-difference analysis across contractors). These drafts appear in the report editor marked as AI-generated, pending the surveyor's review and approval before export.
  • Pricing Commons normalisation and classification (opt-in users only). For users who have opted in to the Tendermark Pricing Commons, two background AI steps run automatically after each parsed return: (1) each line-item description is rewritten by Claude to remove all identifying detail before any contribution is stored, and (2) the normalised description is classified into one of 18 trade theme tags to place it in the correct pool. Neither step is visible during the normal tender workflow. The surveyor's pricing comparison is not affected.

What the AI does not do: Tendermark makes no professional judgements, gives no recommendations, and produces no output presented as a professional opinion. It extracts, organises, and drafts — the surveyor interprets and decides. Every extracted figure includes a confidence score so the surveyor can see where the AI is uncertain. Anomalies are flagged for the surveyor's review, not acted upon automatically. The Recommendation section of the report — the surveyor's professional opinion on which tender to accept — is never AI-drafted and requires the surveyor's own input.

What the surveyor must do: Review all extracted output before relying on it. Verify anomaly flags with professional judgement. Read and edit the AI-drafted narrative sections — they are generated drafts, not finished text. The Tender Analysis Report shows the surveyor's name as the author; the surveyor remains professionally accountable for all of its content. No report should be sent to a client without the surveyor having reviewed and approved the output in full.

The cleaner audit trail — contractor invitations: When a contractor prices online via Tendermark's invitation link, their figures arrive already structured — no AI extraction is involved. Every action (viewed, saved, submitted) is logged with a timestamp and the contractor's IP address. This produces the most transparent possible audit chain and is the recommended approach where contractors are willing to engage digitally.

Under s4.4, your firm must be able to provide written information on request about the type of AI system used, its ways of working and limitations, your due diligence, your risk management, and your reliability decisions. This section covers the first two; the sections below cover the rest.

RICS AI standard s3.1 · reviewed 30 July 2026

Data governance summary

What Tendermark stores, where, and how long for

What is stored

  • Uploaded tender return files (PDFs, spreadsheets, images)
  • Extracted line-item prices and confidence scores
  • Contractor names and firm names
  • Audit log of tender actions (timestamps and IP addresses for contractor submissions)

Where it is stored

  • Database and file storage: European Union (Supabase EU region)
  • AI processing (return extraction and report narrative): Anthropic API — data is not retained for model training
  • Analytics: PostHog EU cloud

Retention

  • Tenders and returns: retained for the life of the account
  • 30-day grace period after account deletion before permanent removal
  • Benchmarking data: anonymised — retained indefinitely as aggregate signals with no link to the source tender. The anonymisation step itself is AI-assisted: line-item descriptions are rewritten by Claude before storage to remove all identifying detail.

Your rights

  • Access, correct, or delete your data at any time
  • Withdraw benchmarking contribution consent in account settings
  • Request account deletion: hello@tendermark.ai

s3.1 permits uploading private and confidential data to an AI system only where there is express written consent in advance from affected stakeholders, and your firm has taken reasonable steps to satisfy itself the upload does not pose an unacceptable risk. In practice: confirm your client engagement terms or data processing agreement permit AI-assisted processing of their pricing information before uploading, and record this page (and the supplier reference card below) as the reasonable steps taken. Tender pricing documents do not require end-client personal data — upload the contractor return, not the client instruction.

RICS AI standard s3.2 · s3.3 · reviewed 30 July 2026

AI register and risk register template

Pre-populated for Tendermark — fillable PDF, ready to complete in any PDF reader

The standard requires firms to maintain a written AI register (s3.2 — system, purpose, date first used, next review date) and a risk register (s3.3 — reviewed at least quarterly, with likelihood, impact, mitigation, a RAG rating, and your firm's risk appetite for each risk). This template covers both. Download the PDF, fill in your firm's details directly in your PDF reader (Adobe Acrobat, Preview, Edge, or Chrome), and file with your compliance records.

Template includes

  • AI register fields per s3.2 (system name, provider, purpose, date first used, next review date — covers contractor return extraction, SoW parsing, report narrative drafting, and Pricing Commons normalisation and classification (opted-in users only))
  • Risk assessment per s3.3 — failure modes for extraction and narrative drafting with likelihood, impact and mitigation, the s4.1 information-gap entries from the supplier reference card, and fillable RAG rating, risk appetite, and review log fields
  • Data governance summary (storage location, retention, sub-processors)
  • Standard client disclosure language (s4.3)
  • Sign-off fields for your firm
Download risk register template

RICS AI standard s4.1 · reviewed 30 July 2026

AI supplier reference card

Written answers to the six items the standard requires you to request from an AI supplier

s4.1 of the RICS AI standard (Procurement and due diligence) requires your firm to request certain information in writing from an AI supplier before adopting a system with a material impact on service delivery, to record the answers, and to record any missing information as risks in your risk register. This card is Tendermark's written response to the six items the standard lists as the minimum — download it for your procurement file.

Where an answer honestly includes a gap, suggested risk register wording is provided below and pre-populated in the risk register template. Follow-up questions in writing: hello@tendermark.ai.

1. Environmental impact

The standard requires: “the environmental impact of the AI system

Tendermark runs on shared cloud infrastructure: application hosting on Vercel, database and file storage on Supabase (EU region), and AI processing via Anthropic’s commercial API. Tendermark Ltd operates no servers of its own.

Anthropic does not currently publish per-request energy or carbon figures for its API, so Tendermark cannot pass a per-tender figure on to you. What can be stated is the shape of usage: AI calls run when a document is uploaded or a report section is drafted — a bounded number of calls per tender, not continuous or high-volume automated processing.

Known information gap — record in your risk register

No per-request energy or carbon figures are available from the upstream model provider.

Suggested entry: Information gap — no per-request energy or carbon figures published by the model provider, so the environmental impact of AI processing cannot be quantified. Usage is bounded (per-document calls per tender, not continuous processing). Recorded as required by s4.1; review if the provider publishes figures.

2. Stakeholders involved in development

The standard requires: “stakeholders involved in the development of the AI system

Tendermark is developed by Tendermark Ltd, registered in England and Wales (company number 17161246). The founding team is a software professional and a practising RICS building surveyor; the extraction architecture was validated against real tender returns from the surveyor’s firm before release.

The underlying large language model (Claude) is developed by Anthropic. Tendermark consumes it as a commercial API customer and has no role in the model’s development.

3. Compliance with data and confidentiality laws

The standard requires: “compliance with applicable data and confidentiality laws

Tendermark processes personal data in accordance with UK GDPR and the Data Protection Act 2018. Tender content and files are stored in the European Union (Supabase, EU region). A written Data Processing Agreement is published at tendermark.ai/dpa and forms part of the service terms.

Every sub-processor (Supabase, Anthropic, Stripe, Vercel, Cloudflare, PostHog, Resend) is listed in the Privacy Policy (section 11) with its processing location and international transfer mechanism — the UK–US Data Bridge or the UK Addendum to the EU Standard Contractual Clauses where processing leaves the UK or EEA.

Data submitted to Anthropic’s API — tender content, contractor returns, and derived analysis — is not used to train Anthropic’s models, under Anthropic’s commercial API terms (Privacy Policy, section 10).

4. Permissions for data relating to individuals

The standard requires: “permissions obtained where data and content relating to individuals have been used

In operation, Tendermark processes limited personal data: contractor names and firm names, plus timestamps and IP addresses for contractor submissions. It is processed on your instructions, with Tendermark Ltd as processor under the DPA. No end-client personal data is required — you upload the contractor pricing document, not the client instruction.

Where a user opts in to the Tendermark Pricing Commons, contributed line items are rewritten to remove identifying detail before storage and held only as anonymised aggregate signals. Contribution is controlled per account and can be switched off at any time.

Known information gap — record in your risk register

Anthropic does not publish a full account of the permissions underlying the data used to train Claude. This is common to all frontier model providers and outside Tendermark’s control.

Suggested entry: Information gap — upstream model training-data permissions not fully disclosed by the provider. No firm or client data enters model training (commercial API terms). Recorded as required by s4.1.

5. Training datasets — accuracy, relevance, diversity and bias

The standard requires: “the accuracy, relevance and diversity of the datasets used to train the AI, including any known gaps in the data, noting any particular known risks of bias

Anthropic does not disclose the composition of Claude’s training corpus, so its accuracy, diversity and gaps cannot be independently verified by Tendermark or by your firm. Treat this as a known information gap.

The bias risks that matter for this use are practical: figures in handwritten or poorly scanned returns may be misread, and unusual document layouts may be misinterpreted. Tendermark’s design assumes both — every extracted figure carries a confidence score, extraction is grounded against your own Schedule of Works rather than free-text inference, and pricing anomalies are flagged for your review, never acted on automatically.

The risk register template in this pack pre-populates these failure modes with likelihood, impact and mitigation, including the training-data disclosure gap itself.

Known information gap — record in your risk register

The composition of the model’s training corpus is not disclosed by the provider.

Suggested entry: Information gap — model training-corpus composition not disclosed by the provider, so dataset accuracy, diversity and bias cannot be independently verified. Operational mitigations (confidence scores, Schedule of Works grounding, mandatory review) do not depend on training-data guarantees. Recorded as required by s4.1.

6. Type and extent of supplier liability

The standard requires: “the type and extent of the liability of the third-party provider

Your contract is with Tendermark Ltd, under the Terms of Service (tendermark.ai/terms). Liability is addressed in clauses 14–16: liability for death or personal injury caused by negligence, or for fraud, is not limited; subject to that, total aggregate liability is capped at the greater of the fees you have paid in the 12 months preceding the claim or £1,000; and indirect and consequential loss — including loss resulting from reliance on any output of the Services — is excluded.

That last exclusion is the honest heart of the allocation: Tendermark extracts, organises and drafts, and the surveyor reviews and remains professionally accountable for what is put to the client (Terms, clause 12.4). Your due-diligence record should reflect that the tool does not carry professional liability for the surveying service.

Practical testing for fitness for purpose

s4.1 also requires your firm to keep a record of the extent to which the AI system has been practically tested for fitness for purpose. The first tender on every Tendermark account is free — run a completed past tender through the product, compare the output against the comparison you originally produced by hand, and record the date, tender and outcome in your risk register as your practical test.

RICS AI standard s4.3 · reviewed 30 July 2026

Terms of engagement language

Copy into your standard client engagement terms

s4.3 requires clients to be told, in writing and in advance, when and for what purpose AI is used where it has a material impact on service delivery. Add the following to your standard terms of engagement. You may adapt the wording to your firm's house style — the key elements are: AI tools are used for both price extraction and report narrative drafting, they support rather than replace professional judgement, and all AI-generated content is reviewed before client delivery.

We use AI-assisted tools in our tender comparison work. These tools extract pricing from contractor submissions and draft sections of the tender analysis report narrative. They support, but do not replace, our professional judgement. All AI-extracted data and AI-drafted content is reviewed and approved by a qualified surveyor before being presented to clients.

Four things s4.3 requires that only your firm can state

The disclosure language above covers when and where AI is involved. s4.3 also requires your terms of engagement to detail:

  • the extent of your professional indemnity cover for AI use, if available
  • your internal process for a client to contest the use of an AI system
  • your process for a client to seek redress if they feel negatively affected by AI use
  • how a client can opt out of AI use in the delivery of a service, if at all

These depend on your firm's PI policy and internal procedures — confirm them with your broker and compliance officer, and add them alongside the disclosure language.

Primary sources

The documents this pack summarises — cite these in your compliance records

Get each revised edition

Sent when the pack changes, and only then

The RICS standard will evolve, and the pack is versioned. Leave your email and we'll send you each revised edition. Nothing else.

We'll only use your email for this. Unsubscribe any time. See our Privacy Policy.

These resources are provided as compliance aids for building surveyors using Tendermark. They do not constitute legal or professional advice. First published 1 May 2026 · this edition 30 July 2026.