This section captures essential information about the requestor and the target SaaS application. All fields marked as mandatory must be completed for the request to be processed.
Requestor Full Name
Requestor Job Title
Department Name
Requestor Email Address
Requestor Direct Phone Number
SaaS Application Name
Vendor/Provider Organization Name
Vendor Primary Website URL
Application Primary Category
Analytics & Business Intelligence
Collaboration & Communication
Customer Relationship Management (CRM)
Design & Creative
Development & DevOps
Finance & Accounting
Human Resources & Talent Management
Marketing & Advertising
Project & Work Management
Security & Compliance
Other
Brief Description of Application Core Functionality
Deployment Model
Public Cloud Multi-Tenant (SaaS)
Public Cloud Single-Tenant
Private Cloud Hosted
Hybrid Deployment
On-Premises Managed
Current Usage Stage
Evaluating (No active usage)
Pilot/Proof of Concept (Limited users)
Active Production (Already in use without approval)
Contract Negotiation
Renewal of existing exception
Expected Total Number of Users
Primary Business Function Supported
Pricing Model
Per User/Seat Subscription
Tiered Feature-Based Subscription
Consumption-Based (Usage)
Flat Rate Enterprise License
Freemium (Paid upgrade from free tier)
One-Time License Fee
Other
Estimated Annual Total Cost (USD)
Budget Source & Cost Center
Proposed Contract Term Length
Is this a multi-year contract with upfront payment?
This section requires a comprehensive justification for why this specialized third-party SaaS is necessary and why existing standard corporate tools are inadequate. Provide specific, measurable evidence where possible.
Detailed Description of Business Problem or Opportunity
Standard Corporate Tools Evaluated from Approved Catalog
Specific Functional Gaps in Standard Tools
Quantified Business Impact if Exception is Not Granted
Have you consulted with the Enterprise Architecture team about potential customizations to standard tools?
Alternative Solutions Considered (Select all that apply)
Building custom in-house solution
Integrating multiple standard tools
Outsourcing to managed service provider
Manual processes/workarounds
Delaying initiative until standard tools evolve
Other third-party SaaS (list below)
Summary of Expected Business Benefits and ROI
Critical Implementation Timeline or Deadline
Does this request support a strategic corporate initiative or priority?
This section assesses data governance, security posture, and compliance requirements. Complete all questions accurately as they directly impact corporate risk and security policies.
Data Classification Types Processed or Stored by Application (Select all that apply)
Public Information (no sensitivity)
Internal Use Only
Confidential Business Data
Personal Information (PII)
Sensitive Personal Information (SPI)
Financial Data
Health Information
Intellectual Property & Trade Secrets
Customer Data
Employee Data
Other Regulated Data
Will the application ingest, process, or store any Personal Identifiable Information (PII)?
Will the application handle any sensitive financial transaction data?
Estimated Monthly Data Volume (in GB)
Primary Data Residency Requirement
Global (no specific residency)
Regional (e.g., Americas, EMEA, APAC)
Country-Specific
Multi-Region Replication Required
Has the vendor completed a SOC 2 Type II audit?
Vendor Security Certifications & Compliance (Select all that apply)
ISO/IEC 27001
ISO/IEC 27017 (Cloud Security)
ISO/IEC 27018 (PII Protection)
SOC 1 Type II
SOC 2 Type II
SOC 3
GDPR Compliance
HIPAA Compliance
PCI DSS Certification
CSA STAR Certification
FedRAMP Authorization
None
Other
Can the vendor provide a recent security audit report or penetration test results?
Does the vendor support data encryption at rest and in transit?
Vendor Data Retention and Deletion Policy Summary
Vendor Security Incident Notification SLA (hours)
Vendor Security Contact Email
This section evaluates integration with corporate identity infrastructure and ensures business continuity through a well-defined exit strategy. SSO integration is strongly preferred for security and user management.
Does the application support Single Sign-On (SSO) integration?
Does the application support Multi-Factor Authentication (MFA)?
Does the application support automated user provisioning and deprovisioning (SCIM)?
Have you developed a comprehensive system exit strategy and transition plan?
Can all data be exported in a non-proprietary, machine-readable format?
Vendor Lock-in Risk Assessment
Low (standard APIs, open formats, easy migration)
Medium (some proprietary features, moderate migration effort)
High (proprietary data formats, significant migration cost)
Critical (custom integrations, very high switching costs)
Data Portability and Interoperability Standards Compliance
Estimated Effort to Migrate to Alternative Solution (person-days)
This final section is reserved for formal risk assessment and approval by Enterprise Architecture and Information Security leadership. Requestors should not complete this section; it will be reviewed and completed by the designated approvers.
Enterprise Architecture Lead Reviewer Name
EA Review Date
Enterprise Architecture Assessment Criteria
Strongly Unsuitable | Unsuitable | Neutral | Suitable | Strongly Suitable | |
|---|---|---|---|---|---|
Technical compatibility with existing enterprise architecture | |||||
Integration complexity with core corporate systems | |||||
Alignment with technology roadmap and standards | |||||
Scalability and performance adequacy | |||||
Vendor stability and long-term viability |
Enterprise Architecture Recommendation & Conditions
EA Lead Recommendation
Approve without conditions
Approve with conditions (specify below)
Reject with rationale
Request additional information
Chief Information Security Officer (CISO) Reviewer Name
CISO Review Date
Overall Security Risk Rating (1=Low Risk, 5=Critical Risk)
CISO Security Risk Assessment
Data protection and encryption adequacy | |
Access control and identity management strength | |
Vendor security posture and audit results | |
Compliance with corporate security policies | |
Incident response and business continuity capability | |
Third-party risk and supply chain security |
Identified Security Gaps and Vulnerabilities
Required Security Mitigations and Controls
Does this request require Board-level risk acceptance?
CISO Final Recommendation
Approve with standard security controls
Approve with enhanced security controls
Approve with mandatory security roadmap
Reject due to unacceptable risk
Escalate to Executive Risk Committee
Enterprise Architecture Lead Digital Signature
Chief Information Security Officer (CISO) Digital Signature
Final Approval Timestamp