Checklist for proportionate vendor due diligence on productivity software
Image: Work Stack Lab

Tools and providers

Part of Name the work before the software when choosing productivity tools and suppliers

Proportionate vendor due diligence for productivity software, identity to exit

A proportionate vendor due-diligence checklist for productivity software, covering identity, service scope, privacy, security, resilience, support and exit.

Business productivity software vendor due diligence should be proportionate to the damage caused by disclosure, loss, corruption or prolonged unavailability. Collecting a huge questionnaire without reading the answers is not assurance. Start with the proposed use, then request evidence that could change the decision.

This checklist is for an England-based buyer and was reviewed on 5 September 2026. It does not certify a supplier or replace legal, privacy, cyber-security, procurement or financial review.

What to take away

  • Match vendor due diligence to the damage that disclosure, loss, corruption or unavailability could cause.
  • Check that the sales description, order form and service terms agree before you rely on them.
  • Close the file with a clear decision and keep any unanswered high-impact question visible.

Typical proportionality tiers:

Typical use

Low
Small team, non-sensitive tasks, no personal data
Medium
Customer contact data, some confidential information
High
Special category data, financial or health records, safety-critical operations

Evidence depth

Low
Identity check, standard terms, supplier security page
Medium
ISO/IEC 27001 scope statement, data processing terms, export test
High
SOC 2 Type II report, Cyber Essentials Plus, tested exit plan

A typical low impact review can take half a day, medium two to five days, high two to four weeks, depending on data sensitivity and supplier cooperation.

Identity and authority

  • Record every contracting party, trading name and registration number.
  • Confirm who owns the software and who is authorised to resell or implement it.
  • Identify the signatory, invoice issuer and support provider.
  • Note material inconsistencies and obtain an explanation.

The Companies House search service provides public company data and access to filings. Treat it as one identity record, not proof that claims are accurate or that the business can perform the contract.

Identity and authority checks

  • Record contracting parties and registration numbers
  • Confirm software owner and reseller authority
  • Identify signatory, invoice issuer, support provider
  • Note inconsistencies and obtain explanations
  • Treat Companies House as one record only

Service and dependency boundary

  • Attach the exact plan, modules, territory and hosting arrangement proposed.
  • List infrastructure providers, support subcontractors and critical integrations.
  • Mark functions described as beta, preview or roadmap.
  • Ask which features and terms the supplier can change during the contract.

Require the sales description, order form and service terms to agree. A generic group security page may not cover the product being purchased.

Service and dependency boundary

  • Attach exact plan, modules, territory, hosting
  • List infrastructure providers and support subcontractors
  • List critical integrations
  • Mark beta, preview or roadmap functions
  • Ask what supplier can change mid-contract
  • Require sales description, order form and terms to agree

Data and privacy evidence

  • Map personal and confidential information entering the service.
  • Establish controller and processor roles purpose by purpose.
  • Obtain the proposed processing terms and sub-processor list.
  • Check locations, transfer arrangements, retention, return and deletion.
  • Ask how the supplier assists with rights requests and incidents.

The ICO tells controllers to consider a processor's expertise, resources and reliability, document sufficient guarantees, and conduct ongoing checks in its controller responsibilities guidance. That page is under review following legislative change. A qualified adviser should verify current requirements for the actual processing.

Security and resilience

  • Set authentication, administrator, logging and access-review requirements.
  • Request vulnerability handling and incident-notification evidence.
  • Examine backup scope, recovery objectives and recent exercise records.
  • Check whether an ISO/IEC 27001 scope statement, SOC 2 Type II report or Cyber Essentials Plus certificate covers the right service and period.
  • Record customer-side configuration and monitoring duties.

The NCSC recommends matching the depth of cloud assessment to the sensitivity, volume and potential impact of the use in Choosing a cloud provider. A certificate name alone is insufficient; inspect its scope, exclusions, date and independent validation.

Delivery, support and viability

  • Name the implementation lead and define acceptance evidence.
  • Set support hours, severity levels, response targets and escalation routes.
  • Ask for references relevant to similar scale and complexity, with permission to contact them.
  • Review appropriate accounts, insurance and continuity information with a financial or commercial specialist.
  • Distinguish facts supplied by the vendor from independently checked records.

Do not ask for sensitive security material that the buyer cannot protect or interpret. A controlled viewing or independent assurance report may provide more useful confidence than an uncontrolled document copy.

Exit and decision record

  • Obtain a representative export and open it outside the service.
  • Define assistance, notice, charges, read-only access and deletion evidence.
  • Identify integration data and local copies not covered by the main export.
  • Set review triggers for ownership, sub-processors, incidents and material product changes.

Government guidance on technical lock-in discusses open formats, migration cost and skills dependence for public cloud purchasing. Private buyers can use those prompts without claiming the government process applies to them.

For a worked exit example, request a CSV or JSON export of all records. Load it into a test instance or spreadsheet outside the service. Obtain written deletion evidence, such as a certificate of destruction or a log entry, after the retention period ends.

Close the file with approve, approve subject to named conditions, pause or reject. Record the evidence date and decision owner. An unanswered high-impact question should remain visible rather than being converted into an optimistic score.

Minimal decision record:

DecisionConditionsEvidence dateOwnerOpen high-impact question
Approve subject to conditionsExport tested outside the service2026-09-05Procurement leadWho owns deletion evidence after contract end?

Before you act

  • Start with the proposed use before requesting evidence.
  • Record every contracting party and registration number.
  • Attach the exact plan, modules, territory and hosting arrangement.
  • Map personal and confidential information entering the service.
  • Obtain a representative export and open it outside the service.
  • Record the evidence date and the decision owner.

Common questions

How should a buyer decide how much due diligence is proportionate?

Match the depth to the harm that disclosure, loss, corruption or unavailability could cause. Use the tier table above, starting with the proposed use. Ask only for evidence that could change the decision, and avoid a questionnaire nobody reads.

What should a buyer check about the supplier's identity and authority?

Record every contracting party, trading name and registration number. Confirm ownership, resale rights and the signatory. Check the invoice issuer and support provider. Companies House data is one identity record, not proof of performance.

What should happen at the end of the due diligence process?

Choose approve, approve with conditions, pause or reject. Record the evidence date and decision owner. Keep any open high-impact question visible. Do not request security material you cannot protect or interpret.

More in Tools and providers