Enterprise & government
Procurement guidance
What to settle before you buy intelligent software: scope, deployment, evidence, and contract questions. A starting framework, not advice.
Before you shortlist
Before you shortlist
- Define the use. Who will use it, for what tasks, and what happens if it is wrong?
- Classify the data. What is the most sensitive data the product will see?
- List mandatory requirements. Which authorizations, standards, or contract terms are non-negotiable?
- Decide the deployment model. See hosted vs. self-managed: questions to ask.
Questions: data handling
Data handling
- What data does the product receive, and is any of it retained? For how long, and where?
- Is customer data used to train or improve models? Is the opt-out contractual, or only a setting?
- Which subprocessors and regions are involved?
- How is data deleted at the end of the contract, and can you verify it?
Questions: security and assurance
Security and assurance
- Which independent audits, certifications, or authorizations apply to this exact product and deployment?
- What is their scope, and what is excluded?
- Can you obtain the evidence from the issuing body rather than only from the vendor?
- How are vulnerabilities and incidents reported to customers, and within what timeframe?
Questions: administration and control
Administration and control
- Can an administrator set policy for all users, and audit activity?
- What can the product access, and what can it do on a user's behalf?
- Can you restrict features, models, or integrations?
Questions: contract and commercial
Contract and commercial
- How are prices set, and what changes can the vendor make during a term?
- What are the usage limits, and what happens when they are reached?
- What are the service levels, support terms, and remedies?
- What are your exit rights and data-portability options?
Common mistakes
Common mistakes
- Treating a vendor's company-wide security page as proof about one product.
- Assuming an authorization held by one service covers the vendor's other services.
- Accepting a status without a verification date or a link to the authoritative record.
- Comparing products on features without comparing the deployment option you can actually buy.
Next: see how we record a claim in security & authorization evidence, and the procurement evidence checklist.