This section captures essential information about the requester, software vendor, and business justification. Complete all mandatory fields to ensure timely processing.
Requester Full Name
Requester Corporate Email Address
Requester Department
Engineering & Development
Sales & Marketing
Finance & Accounting
Human Resources
Legal & Compliance
Operations
Customer Support
Information Technology
Other
Requester Role/Title
Software Application Name
Vendor Organization Name
Vendor Primary Website URL
Software Version or Release Track
Primary Software Category
Productivity & Collaboration
Customer Relationship Management (CRM)
Enterprise Resource Planning (ERP)
Business Intelligence & Analytics
Development & DevOps
Security & Compliance
Marketing Automation
Communication & Messaging
Human Capital Management
Project Management
File Storage & Sharing
Other
Detailed Business Purpose & Use Case Justification
Estimated Number of Initial Users
Estimated Number of Total Users at Full Deployment
Has budget been formally approved for this SaaS purchase?
Pricing Model
Per-User Subscription
Tiered Subscription
Consumption-Based
Flat Fee Enterprise License
Freemium
One-Time License with Maintenance
Other
Estimated Annual Cost (if budget not yet approved)
Desired Go-Live/Deployment Date
Is this software intended to replace an existing approved solution?
Required Integration Touchpoints (select all that apply)
Active Directory/LDAP
Email System
Calendar System
Corporate HRIS
Financial System
CRM Platform
Custom API
Single Sign-On (SSO) Provider
Security Information and Event Management (SIEM)
Backup Solution
No Integration Required
Other
Vendor Primary Contact Name
Vendor Primary Contact Email
Vendor Support Model
24/7 Global Support
Business Hours Only
Premium/Paid Support Required
Community Support Only
Dedicated Account Manager
Other
Does the vendor provide a publicly accessible status page for service health?
Are there any known concerns about vendor financial stability or market viability?
Software Deployment Model
Public Cloud Multi-Tenant
Public Cloud Single-Tenant
Private Cloud
Hybrid Cloud
On-Premises Hosted
Not Sure
Does the software offer mobile applications (iOS/Android)?
Does the software require offline functionality or local data storage?
This section evaluates data sensitivity, residency, and protection mechanisms. Accurate classification is critical for risk assessment and compliance.
Types of Data to be Stored or Processed (select all that apply)
Customer Personal Information (PII)
Employee Personal Information (PII)
Financial Records
Health Information
Intellectual Property & Trade Secrets
Contractual & Legal Documents
Authentication Credentials
Corporate Strategy & Confidential Memos
Publicly Available Information
System Logs & Metadata
Other
Highest Data Classification Level
Public
Internal Use Only
Confidential
Restricted
Will Confidential or Restricted data be stored/processed?
Are there specific data residency or sovereignty requirements?
Primary Cloud Service Provider (if known)
Is data encrypted at rest using industry-standard algorithms (AES-256 or equivalent)?
Is data encrypted in transit using TLS 1.2 or higher?
Encryption Key Management Model
Vendor Managed Keys
Customer Managed Keys (CMK)
Bring Your Own Key (BYOK)
Hardware Security Module (HSM) Integration
Not Sure
Backup Frequency & Retention
Real-time Replication
Hourly Snapshots
Daily Backups
Weekly Backups
No Backups (Stateless)
Not Disclosed
Data Retention Period (e.g., 7 years, indefinite)
Does the vendor have a documented data deletion policy for customer data?
Will the SaaS application process personal data subject to privacy regulations?
Vendor's Data Breach Notification SLA (e.g., within 24 hours)
Does the vendor utilize sub-processors or fourth-party vendors?
Describe the disaster recovery objectives (RTO/RPO) if disclosed by vendor
Is comprehensive audit logging and monitoring available within the application?
I acknowledge that a Shared Responsibility Model applies and confirm understanding of our organization's obligations
This section assesses the application's integration with corporate identity and access management standards. Proper authentication controls are mandatory for enterprise deployment.
Does the application support Single Sign-On (SSO)?
Is SAML metadata exchange automated or manual?
Does the application enforce Multi-Factor Authentication (MFA)?
User Provisioning & Lifecycle Management Method
SCIM 2.0 Automated Provisioning
SCIM 1.1 Automated Provisioning
Just-in-Time (JIT) Provisioning
Manual Admin-Managed
API-Based Custom Integration
Not Supported
If SCIM is supported, provide SCIM endpoint URL
Does the application support granular Role-Based Access Control (RBAC)?
Can the application enforce our corporate password policy?
Is session timeout duration configurable by administrators?
Does the application support IP allowlisting/restrictions?
Does the application expose APIs for programmatic access?
Are Service Accounts supported for system-to-system integration?
Does the application support Conditional Access policies?
Is Privileged Access Management (PAM) integration supported?
This section evaluates the vendor's security posture, compliance certifications, and risk management practices. Independent verification is required for high-risk deployments.
Has the vendor completed a SOC 2 Type II audit?
Is the SOC 2 Type II report available for review under NDA?
Which SOC 2 Trust Services Criteria are covered in the report?
Security (Common Criteria)
Availability
Processing Integrity
Confidentiality
Privacy
Not Sure
Is the vendor ISO 27001 certified?
Other Security & Compliance Certifications (select all that apply)
ISO 27017 (Cloud Security)
ISO 27018 (Privacy)
ISO 27701 (Privacy Management)
FedRAMP Authorized
CSA STAR
NIST Cybersecurity Framework
PCI DSS
HIPAA/HITECH
GDPR Compliant
None
Does the vendor undergo regular independent penetration testing?
Date of Most Recent Penetration Test
Is the penetration test report available for review?
Does the vendor maintain a documented Vulnerability Management Program?
Has the vendor experienced any security incidents or data breaches in the past 24 months?
Data Center & Physical Security Controls (select all that apply)
ISO 27001 Certified Data Centers
SOC 1 Type II Data Centers
Biometric Access Controls
24/7 Security Staff
CCTV Monitoring
Redundant Power & Cooling
Not Disclosed
Network Security Controls Implemented (select all that apply)
Web Application Firewall (WAF)
Distributed Denial of Service (DDoS) Protection
Network Segmentation
Intrusion Detection/Prevention (IDS/IPS)
Zero Trust Architecture
Not Disclosed
Application Security Testing Practices (select all that apply)
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
Software Composition Analysis (SCA)
Interactive Application Security Testing (IAST)
Regular Code Reviews
Bug Bounty Program
Not Disclosed
Has the vendor completed our organization's Security Questionnaire?
Does the vendor maintain Cybersecurity Insurance?
Vendor Security Team Contact Email
Does the vendor have a published security incident response plan?
Does the vendor agree to our organization's Right to Audit clause?
This final section requires executive attestation and formal approval. All preceding sections must be completed before submission for sign-off.
Overall Risk Assessment Level
Low Risk
Medium Risk
High Risk
Critical Risk
Does this request require a formal risk exception or acceptance?
Have all mandatory security requirements been satisfied or waived through proper exception process?
Has the business justification been validated and deemed critical?
Is budget approval confirmed and allocated?
Is the proposed implementation timeline realistic and approved?
Is a post-implementation security review required?
Has a decommissioning and data retrieval plan been documented?
CISO Approval - I have reviewed the security assessment and approve proceeding
CISO Full Name
CISO Approval Date
IT Director Approval - I have reviewed technical requirements and resource allocation and approve proceeding
IT Director Full Name
IT Director Approval Date
Are additional executive approvals required (e.g., CFO, Legal, Data Protection Officer)?
Final Decision
Approve for Immediate Deployment
Approve with Conditions
Reject - Security Concerns
Reject - Business Justification Insufficient
Defer - Pending Additional Information
Should this software be added to the approved corporate SaaS catalog?
Conditions of Approval or Rejection Reasoning