
This is something that I have witnessed time and again with clients. The team is excited about a new platform and reasonably anticipates a quick go/no-go. Instead, the review process turns into weeks of ping-ponging with the vendor: Responses to questionnaires, security documentation, clarifying calls, proof or non-provision of compliance, legalese and data flow discussions. That delay can feel painful to all involved if the end user organization does not have a mature process already in place. The business sees friction. The vendor sees hurdles. Security sees unresolved risk.
The key to getting in early is working with your legal and finance, or procurement teams to bring you in as early as possible. These will be your partners in making sure the assessment is done before anything is signed. In my experience, once the ink is dry on the contract, you have lost all leverage in being able to get action from the third-party. A mature assessment will build in contract language to address gaps or weaknesses. This is the only thing that works in getting the outcomes you are looking for.
Building a repeatable review process
At root, we’re trying to help end-user organizations build structures around vendor evaluations to ensure a repeatable process; something that is defensible and aligned to their business operations. This is not a simple product review. We are helping them translate security, compliance and operational requirements into a workable framework for making a deployment decision.
