Published 15 September 2026 · Primacy ITS
Use this before adopting a new service or renewing one whose role has changed. The aim is an evidence-backed decision proportionate to the risk, not a questionnaire nobody reads.
Start with impact
Record the business owner, purpose, users, data categories and dependencies. Ask what happens if the supplier is unavailable tomorrow or permanently stops trading. A public design tool and a system holding employee records deserve different levels of scrutiny.
Ask seven useful questions
- Who can administer it, how are privileged accounts protected, and can access be revoked promptly?
- What data enters it, who else can process it, and what contractual controls apply?
- Can we export our information in a useful format and verify deletion when we leave?
- What recovery options exist, and which failures do they actually cover?
- What evidence supports its security claims, and does that evidence cover the product and scope we are buying?
- How will we learn about an incident, a material terms change or newly enabled AI functionality?
- What are the total cost, renewal date and cancellation notice period?
Record the evidence
For each answer keep a source link or restricted document reference, the date checked, unresolved gaps and the person responsible for the decision. Do not paste credentials or customer records into a supplier-review form.
Certificates and badges are supporting evidence. Read their scope and validity; do not assume they cover every product, processor or operating practice.
Make a bounded decision
Use one of four outcomes: approved; approved with conditions; pilot with limited data; or not approved. For a conditional approval state the missing control, compensating measure, accountable business owner and expiry date. If no one can accept the residual risk, the decision is not finished.
Before deployment
Agree the access model, offboarding procedure, support route and recovery expectations. Confirm that the chosen plan supplies the controls on which approval depends. If personal data is involved, complete the relevant privacy and contractual assessment for the actual arrangement; this checklist is not a substitute for it.
Verification and exit
Test access removal using a permitted test account, perform a small export, and check that the business owner can read the exported data. Run these checks without changing production records. If the pilot is rejected, revoke integrations and test accounts and follow the agreed data-removal process. Keep evidence needed for contractual, security or legal purposes.
Reusable decision record
- Supplier/product and exact plan:
- Business purpose and owner:
- Data and business criticality:
- Administrative access and recovery:
- Evidence checked and date:
- Cost, renewal and notice period:
- Export/exit test result:
- Outstanding risk and accountable owner:
- Decision, conditions and review date:
This is Primacy ITS's proposed review method. It makes no claims about an individual supplier and does not certify compliance. Adapt it to your contracts, data and business risk.
Related resources
A SaaS review that leads to a decision
Seven useful questions, evidence that matters and a clear decision record.
