1. Need and ownership

Name the operational problem, accountable executive, day-to-day owner and the people affected. Define success in measurable terms and confirm that a process change or a feature in an existing system cannot solve the need more safely.

2. Full cost

Record licence tiers, implementation, migration, integrations, training, support, payment fees, taxes, currency exposure and internal staff time. Ask which discounts expire and what happens to pricing when users, records or transactions grow.

3. Security and privacy

Review access controls, multi-factor authentication, encryption, audit logs, backups, recovery objectives, sub-processors, hosting locations, incident notification and independent assurance. Confirm responsibilities rather than accepting a security badge as the answer.

4. Data and interoperability

Test import and export with representative records. Document APIs, rate limits, data dictionaries, identifiers, deduplication rules and retention. Make sure the organisation can retrieve usable data without the vendor’s professional-services team.

5. Delivery capacity

Identify the implementation lead, decision forum, change budget, training plan and post-launch support. Smaller organisations should reduce simultaneous integrations and protect staff time for cleanup, testing and adoption.

6. Contract and exit

Check renewal terms, service levels, liability, data ownership, deletion, accessibility commitments, price changes and termination assistance. Set an exit test before signing: who exports what, in which format, at what cost and within which period?