Guide

A procurement evidence checklist for intelligent software

The facts to pin down before accepting any security, compliance, or authorization claim about a specific product.

By Adam Green, Content ManagerPublished 5 min readEditorial review pending

This checklist is general information, not legal or procurement advice. Your contracting and compliance teams decide what applies to you.

What exactly is being claimed?

  • The exact product or service name, not only the vendor name.
  • The deployment: commercial cloud, government cloud, on-premises, or self-managed.
  • The program or standard, and the level or impact category if there is one.
  • The status: authorized, in process, or something else.
  • The scope, and what is explicitly excluded.

Where is the authoritative source?

Prefer the record kept by the program or body that grants the status. A vendor's page is a claim; the program's own listing is evidence. Write down where you looked and on what date.

Why should a status never be generalised?

A vendor holding an authorization for one service does not mean its other services have it. A certification for one region does not cover another. If you cannot find the exact record, the status is unverified.

See also procurement guidance and our evidence record template.

Frequently asked questions

What counts as authoritative evidence for an authorization?

The record kept by the program or body that grants the status, not a vendor's summary of it.

If a vendor holds an authorization for one service, do its other services have it?

No. Scope is specific to the product and deployment that was assessed.

What should I do if I cannot find the exact record?

Treat the status as unverified until you can find it.

Sources

This article is editorial analysis. It cites no external sources and contains no product performance claims, benchmark figures, or policy facts.

Related