Working structure

Enterprise procurement checklist.

Procurement review is where products discover which of their assumptions were never written down. The questions are rarely surprising; the problem is that answering them takes weeks because nobody owns the answers.

This checklist sets out the questions enterprise buyers ask, and what separates a credible answer from a deferral.

Build your brief
FORMATMarkdown checklist
USEBefore enterprise sales
BOUNDARYNot legal advice

01 / WHAT BUYERS ASK

Six areas, consistently.

The specific wording varies by buyer. The underlying questions rarely do.

Security architecture

How access is granted, reviewed, and revoked; how secrets are held; how environments are separated; how changes reach production; and what the threat model actually covers.

Data protection

What data is processed and why, where it resides, how long it is retained, who the subprocessors are, and how deletion and export requests are honoured in practice.

Accessibility

Which standard is claimed, at which conformance level, for which parts of the product, and what evidence supports the claim. An untested claim is a liability rather than an asset.

Operations

Availability expectations, support hours and escalation, incident notification timelines, monitoring, and demonstrated recovery rather than a documented intention.

Assurance

Which certifications exist, their exact scope, who issued them, and what falls outside. Overstated scope is discovered during review and it is expensive.

Contractual

Liability, data processing terms, subprocessor change notification, exit and data portability, and what happens to the product if the supplier relationship ends.

02 / WHAT A GOOD ANSWER LOOKS LIKE

Credible beats complete.

STRONG ANSWER
  • A named owner for the answer, not a department.
  • A specific scope: which product, which environment, which standard, which version.
  • Evidence that can be produced on request rather than described.
  • Known gaps stated plainly, with an owner and a remediation date.
  • A clear line between what is engineered and what is independently certified.
ANSWER THAT CAUSES DELAY
  • A certification claimed without its scope.
  • An accessibility conformance level asserted without testing.
  • “Yes” to a control that exists in policy but not in the product.
  • Evidence that must be reconstructed before it can be shown.
  • A deferral with no owner and no date.

Sample working structure

Take the checklist.

The Markdown file carries the question set and prompts described above. It is a preparation aid and is not legal advice or an assurance opinion.

03 / QUESTIONS

Procurement questions.

What does enterprise procurement usually ask for?

Security architecture and access control, data protection and residency, subprocessor disclosure, accessibility conformance, availability and support commitments, incident and disclosure process, business continuity, and evidence of the controls claimed.

What is the most common reason a review stalls?

Unowned answers. A question that no named person is accountable for tends to circulate until someone guesses, and a guess that later proves wrong is more damaging than an honest gap with a remediation date.

Is it better to admit a gap or defer the question?

Admit the gap, with an owner and a date. Enterprise buyers routinely accept known gaps on a credible plan. They rarely forgive an answer that turns out to be untrue.

When should this work start?

Before the first enterprise opportunity, not during it. Most of the answers are architectural, and architecture cannot be changed on a procurement timeline.

Next decision

Get ahead of the review.

The answers are architectural, so they are cheapest to establish early.