# Zaivit — Enterprise procurement checklist (sample)

> Use this checklist to evaluate an engagement. It is not a representation that every item currently applies, nor is it a substitute for legal, security, privacy, or procurement review.

## Supplier identity and authority

- [ ] Verified legal entity name and registration jurisdiction
- [ ] Registered or business address
- [ ] Authorized commercial signatory
- [ ] Primary delivery, security, privacy, and incident contacts
- [ ] Relevant insurance details and limits

## Scope and governance

- [ ] Outcomes, deliverables, exclusions, and acceptance criteria
- [ ] Named decision-makers and escalation path
- [ ] Delivery cadence, reporting, dependencies, and client responsibilities
- [ ] Change-control method
- [ ] Exit, transition, and knowledge-transfer responsibilities

## Intellectual property

- [ ] Ownership of bespoke source, documentation, designs, and evidence
- [ ] Treatment of reusable foundations and pre-existing materials
- [ ] Open-source review and license obligations
- [ ] Third-party services, components, and usage restrictions

## Security and access

- [ ] Client-managed identity, repository, and environment preference
- [ ] Least-privilege access and access-removal process
- [ ] Secret, device, dependency, vulnerability, and incident practices
- [ ] Logging, monitoring, backup, recovery, and rollback responsibilities
- [ ] Evidence and residual-risk acceptance process

## Privacy and data handling

- [ ] Data categories, subjects, purposes, locations, and instructions
- [ ] Controller/processor roles and required data-processing agreement
- [ ] Subprocessors and transfer mechanisms
- [ ] Retention, deletion, return, and verification responsibilities
- [ ] Breach notification and data-subject request support

## Service and commercial terms

- [ ] Fees, taxes, invoicing, expenses, and payment terms
- [ ] Service levels or response expectations, where applicable
- [ ] Warranties, liability, indemnities, and termination rights
- [ ] Confidentiality and publicity permissions
- [ ] Governing law and dispute process

## Assurance

- [ ] Exact scope and validity of any claimed certifications
- [ ] Framework readiness clearly separated from independent certification
- [ ] Right-to-audit or evidence-review expectations
- [ ] Accessibility and performance acceptance method
- [ ] Required security questionnaires and supporting materials

## Decision record

- Evaluation owner:
- Date:
- Open questions:
- Exceptions:
- Approval or next action:
