Step 1
Frame the request
Capture the vendor, proposed use case, business purpose, intended users, data categories, integrations, decision impact, and requested timing. Return requests that are too vague to review.
Process guide
Use clear roles and decision points so vendor evaluation is neither an unstructured email chain nor an automated pass-or-fail exercise.
Step 1
Capture the vendor, proposed use case, business purpose, intended users, data categories, integrations, decision impact, and requested timing. Return requests that are too vague to review.
Step 2
Identify which functions should participate. Relevant reviewers may include security, privacy, legal, procurement, compliance, accessibility, finance, risk, and the business owner.
Step 3
Ask only for information connected to the use case. Track the source and scope of each item, and avoid receiving confidential material through channels not approved by your organization.
Step 4
Assign follow-up questions. If a gap cannot be closed, state its decision impact and whether a control, narrower use, contractual condition, or later review could address it.
Step 5
Document the recommendation, rationale, approver, conditions, prohibited uses, implementation owners, and review triggers. “Approved” without scope is not a durable decision.
Step 6
Revisit the decision when the use case, model, data flow, subprocessors, contract, controls, or impact changes materially.
Decision record