Scope and model-type fit
Evidence for the exact models, uses, jurisdiction, and materiality in scope.
Score evidence, not brand familiarity. Adjust the weights to match the engagement, enter a 0 to 5 score for each criterion, and capture the evidence behind the number.
Evidence for the exact models, uses, jurisdiction, and materiality in scope.
Defensible tests, assumptions, challenge, reproducibility, and limitations.
Current, exact citations and a traceable requirement-to-control mapping.
Clear separation, disclosures, escalation, and credible challenge.
Approvals, findings, exceptions, history, workpapers, and complete export.
Identity, least privilege, encryption, logs, retention, deletion, incidents, and subprocessors.
APIs, identity, data, monitoring, reporting, migration, and exit.
Named team, plan, dependencies, training, administration, service levels, and continuity.
Complete three-year cost, assumptions, renewal, services, environments, and change fees.
Scoring rule. A high total does not override a failed security, independence, legal, or mandatory capability gate. Define pass/fail gates before vendor demos and record who approved each score.