This section captures essential information about the requestor and the target SaaS application. All fields marked as mandatory must be completed for the request to be processed.
Requestor Full Name
Requestor Job Title
Department Name
Requestor Email Address
Requestor Direct Phone Number
SaaS Application Name
Vendor/Provider Organization Name
Vendor Primary Website URL
Application Primary Category
Analytics & Business Intelligence
Collaboration & Communication
Customer Relationship Management (CRM)
Design & Creative
Development & DevOps
Finance & Accounting
Human Resources & Talent Management
Marketing & Advertising
Project & Work Management
Security & Compliance
Other
Please specify the application category
Brief Description of Application Core Functionality
Deployment Model
Public Cloud Multi-Tenant (SaaS)
Public Cloud Single-Tenant
Private Cloud Hosted
Hybrid Deployment
On-Premises Managed
Current Usage Stage
Evaluating (No active usage)
Pilot/Proof of Concept (Limited users)
Active Production (Already in use without approval)
Contract Negotiation
Renewal of existing exception
Expected Total Number of Users
Primary Business Function Supported
Pricing Model
Per User/Seat Subscription
Tiered Feature-Based Subscription
Consumption-Based (Usage)
Flat Rate Enterprise License
Freemium (Paid upgrade from free tier)
One-Time License Fee
Other
Please specify the pricing model
Estimated Annual Total Cost (USD)
Budget Source & Cost Center
Proposed Contract Term Length
Is this a multi-year contract with upfront payment?
Please explain the payment structure and financial commitment
This section requires a comprehensive justification for why this specialized third-party SaaS is necessary and why existing standard corporate tools are inadequate. Provide specific, measurable evidence where possible.
Detailed Description of Business Problem or Opportunity
Standard Corporate Tools Evaluated from Approved Catalog
Specific Functional Gaps in Standard Tools
Quantified Business Impact if Exception is Not Granted
Have you consulted with the Enterprise Architecture team about potential customizations to standard tools?
Summarize EA team's feedback and why customization was deemed insufficient
Explain why EA consultation was not pursued
Alternative Solutions Considered (Select all that apply)
Building custom in-house solution
Integrating multiple standard tools
Outsourcing to managed service provider
Manual processes/workarounds
Delaying initiative until standard tools evolve
Other third-party SaaS (list below)
Describe other alternatives and why they were rejected
Summary of Expected Business Benefits and ROI
Critical Implementation Timeline or Deadline
Does this request support a strategic corporate initiative or priority?
Specify the initiative and executive sponsor
This section assesses data governance, security posture, and compliance requirements. Complete all questions accurately as they directly impact corporate risk and security policies.
Data Classification Types Processed or Stored by Application (Select all that apply)
Public Information (no sensitivity)
Internal Use Only
Confidential Business Data
Personal Information (PII)
Sensitive Personal Information (SPI)
Financial Data
Health Information
Intellectual Property & Trade Secrets
Customer Data
Employee Data
Other Regulated Data
Will the application ingest, process, or store any Personal Identifiable Information (PII)?
Select all PII types involved
Names
Email addresses
Phone numbers
Physical addresses
Government ID numbers
Financial account numbers
IP addresses
Device identifiers
Biometric data
Other PII
Will the application handle any sensitive financial transaction data?
Describe the financial data types and required compliance frameworks (e.g., PCI DSS)
Estimated Monthly Data Volume (in GB)
Primary Data Residency Requirement
Global (no specific residency)
Regional (e.g., Americas, EMEA, APAC)
Country-Specific
Multi-Region Replication Required
Specify region(s)
Specify country/countries
Has the vendor completed a SOC 2 Type II audit?
SOC 2 Type II Audit Date
Explain how vendor security will be validated
Vendor Security Certifications & Compliance (Select all that apply)
ISO/IEC 27001
ISO/IEC 27017 (Cloud Security)
ISO/IEC 27018 (PII Protection)
SOC 1 Type II
SOC 2 Type II
SOC 3
GDPR Compliance
HIPAA Compliance
PCI DSS Certification
CSA STAR Certification
FedRAMP Authorization
None
Other
Explain the security assurance approach without certifications
Specify other certification
Can the vendor provide a recent security audit report or penetration test results?
Date of Most Recent Security Assessment
Explain the plan to obtain security validation
Does the vendor support data encryption at rest and in transit?
Specify encryption standards and key management approach
Justify why encryption is not required and describe risk mitigation
Vendor Data Retention and Deletion Policy Summary
Vendor Security Incident Notification SLA (hours)
Vendor Security Contact Email
This section evaluates integration with corporate identity infrastructure and ensures business continuity through a well-defined exit strategy. SSO integration is strongly preferred for security and user management.
Does the application support Single Sign-On (SSO) integration?
Select Supported SSO Protocols
SAML 2.0
OpenID Connect (OIDC)
OAuth 2.0
LDAP/Active Directory
WS-Federation
Other
Specify SSO protocol
Justify why SSO cannot be implemented and describe alternative authentication controls
Does the application support Multi-Factor Authentication (MFA)?
Explain MFA risk mitigation plan
Does the application support automated user provisioning and deprovisioning (SCIM)?
SCIM Version Supported
Describe manual user management process and security controls
Have you developed a comprehensive system exit strategy and transition plan?
Exit Strategy Components
Exit Component | Description/Approach | Timeline (Days) | Estimated Cost | Documented? | ||
|---|---|---|---|---|---|---|
A | B | C | D | E | ||
1 | Data Export Format & API Access | CSV, JSON via REST API | 30 | $5,000.00 | Yes | |
2 | User Account Termination Process | Manual deactivation workflow | 7 | $0.00 | ||
3 | Contract Termination Notice Period | 90 days written notice | 90 | $0.00 | Yes | |
4 | ||||||
5 | ||||||
6 | ||||||
7 | ||||||
8 | ||||||
9 | ||||||
10 |
Explain the plan to develop exit strategy before production use
Can all data be exported in a non-proprietary, machine-readable format?
Specify supported export formats (CSV, JSON, XML, etc.)
Describe data lock-in risks and mitigation strategies
Vendor Lock-in Risk Assessment
Low (standard APIs, open formats, easy migration)
Medium (some proprietary features, moderate migration effort)
High (proprietary data formats, significant migration cost)
Critical (custom integrations, very high switching costs)
Data Portability and Interoperability Standards Compliance
Estimated Effort to Migrate to Alternative Solution (person-days)
This final section is reserved for formal risk assessment and approval by Enterprise Architecture and Information Security leadership. Requestors should not complete this section; it will be reviewed and completed by the designated approvers.
Enterprise Architecture Lead Reviewer Name
EA Review Date
Enterprise Architecture Assessment Criteria
Strongly Unsuitable | Unsuitable | Neutral | Suitable | Strongly Suitable | |
|---|---|---|---|---|---|
Technical compatibility with existing enterprise architecture | |||||
Integration complexity with core corporate systems | |||||
Alignment with technology roadmap and standards | |||||
Scalability and performance adequacy | |||||
Vendor stability and long-term viability |
Enterprise Architecture Recommendation & Conditions
EA Lead Recommendation
Approve without conditions
Approve with conditions (specify below)
Reject with rationale
Request additional information
Specify EA Conditions
EA Rejection Rationale
Specify Additional Information Required
Chief Information Security Officer (CISO) Reviewer Name
CISO Review Date
Overall Security Risk Rating (1=Low Risk, 5=Critical Risk)
CISO Security Risk Assessment
Data protection and encryption adequacy | |
Access control and identity management strength | |
Vendor security posture and audit results | |
Compliance with corporate security policies | |
Incident response and business continuity capability | |
Third-party risk and supply chain security |
Identified Security Gaps and Vulnerabilities
Required Security Mitigations and Controls
Does this request require Board-level risk acceptance?
Explain the rationale for executive-level risk acceptance
CISO Final Recommendation
Approve with standard security controls
Approve with enhanced security controls
Approve with mandatory security roadmap
Reject due to unacceptable risk
Escalate to Executive Risk Committee
Enterprise Architecture Lead Digital Signature
Chief Information Security Officer (CISO) Digital Signature
Final Approval Timestamp
To configure an element, select it on the form.