Enterprise & government

Procurement guidance

What to settle before you buy intelligent software: scope, deployment, evidence, and contract questions. A starting framework, not advice.

Before you shortlist

Before you shortlist

  1. Define the use. Who will use it, for what tasks, and what happens if it is wrong?
  2. Classify the data. What is the most sensitive data the product will see?
  3. List mandatory requirements. Which authorizations, standards, or contract terms are non-negotiable?
  4. Decide the deployment model. See hosted vs. self-managed: questions to ask.

Questions: data handling

Data handling

  • What data does the product receive, and is any of it retained? For how long, and where?
  • Is customer data used to train or improve models? Is the opt-out contractual, or only a setting?
  • Which subprocessors and regions are involved?
  • How is data deleted at the end of the contract, and can you verify it?

Questions: security and assurance

Security and assurance

  • Which independent audits, certifications, or authorizations apply to this exact product and deployment?
  • What is their scope, and what is excluded?
  • Can you obtain the evidence from the issuing body rather than only from the vendor?
  • How are vulnerabilities and incidents reported to customers, and within what timeframe?

Questions: administration and control

Administration and control

  • Can an administrator set policy for all users, and audit activity?
  • What can the product access, and what can it do on a user's behalf?
  • Can you restrict features, models, or integrations?

Questions: contract and commercial

Contract and commercial

  • How are prices set, and what changes can the vendor make during a term?
  • What are the usage limits, and what happens when they are reached?
  • What are the service levels, support terms, and remedies?
  • What are your exit rights and data-portability options?

Common mistakes

Common mistakes

  • Treating a vendor's company-wide security page as proof about one product.
  • Assuming an authorization held by one service covers the vendor's other services.
  • Accepting a status without a verification date or a link to the authoritative record.
  • Comparing products on features without comparing the deployment option you can actually buy.

Next: see how we record a claim in security & authorization evidence, and the procurement evidence checklist.