SaaS Procurement Security Review Checklist Template

A team starts a free trial, connects it to the company calendar and asks security to approve it by Friday. Without a set route, a note-taking app gets 300 questions and the new CRM gets a quick yes.

This free SaaS procurement security review checklist is for IT, security and procurement teams asked to approve a new software-as-a-service tool before anyone signs the order form. An intake records who wants the tool and what data will go into it, then a risk tier decides how deep the review goes. Low-risk tools take a light path and get an answer in days. Tools that will hold confidential or personal data get evidence requests, identity checks, data protection and AI training terms, logging and exit, then a recorded decision and an inventory entry with an owner and renewal date.

Use This Template Free See Live Example
No Credit Card Required

Reviewing a Tool Before You Buy It Is Not a Vendor Risk Programme

A vendor risk assessment manages a supplier for the whole relationship: criticality tiering, inherent and residual risk, contract clauses, risk acceptance and an annual reassessment. That is the job of the Vendor Risk Assessment Checklist. This review is narrower and earlier. It answers one question for one request: is this product, used the way this team plans to use it, safe enough to buy, and on what conditions? The few tools that will hold restricted data or become business-critical are passed to the full process rather than reviewed twice.

The pre-purchase moment is also where the leverage sits. Once data has been loaded, nobody switches tools because single sign-on costs extra or the vendor trains its models on customer content. Before signing, both are negotiable or a reason to choose another product. The review also catches what a trial has already done: clicking Allow on a “Sign in with Google” or Microsoft consent screen can give an app read access to a mailbox, calendar or files before any contract exists.

SaaS procurement review

This checklist

Trigger: a team asks to buy or expand a SaaS tool.

Depth: set by the data the tool will hold; low-risk tools take a light path.

Output: a recorded decision with conditions, and an inventory entry.

Vendor risk assessment

For critical suppliers

Trigger: a high-tier supplier, before contract and then annually.

Depth: inherent and residual risk across security, privacy, resilience and finance.

Output: a residual risk rating and a signed risk acceptance.

Software implementation

After the purchase

Trigger: a signed contract.

Depth: configuration, integrations, migration, training and go-live.

Output: a tool in use with the review’s conditions applied.

Tier by data, not by price: a free browser extension that reads every page an employee opens can carry more risk than an expensive analytics platform. When the answer is yes, conditions such as enforcing SSO or opting out of AI training go to the New Software Implementation Checklist, so they are checked in the live tenant rather than lost between teams.

What the SaaS Procurement Security Review Checklist Covers

Seven phases take a SaaS request from intake to a recorded decision and an inventory entry. The risk tier set in Phase 2 decides whether the evidence, data protection and exit phases appear.

Phase 1

Phase 1: Intake & Request

Completed by the requester and checked by the IT or security reviewer. The last answer sets the risk tier.

  • Record the request — tool, vendor, plan, requesting team, business owner, number of users and the problem it solves
  • Check whether an approved tool already does the job — search the SaaS inventory first; a second whiteboard app is another data store, not a new capability
  • List the data that will go in — customer or employee personal data, financial records, source code, confidential documents or none, with real examples
  • List the integrations and OAuth scopes requested — Google or Microsoft sign-in, mailbox, calendar, file storage and CRM connections, with the exact permissions asked for
  • Record whether a free trial is already running — which accounts signed up and what data has been loaded, so the decision covers it
  • Record the highest data classification involved — public, internal, confidential or restricted under your own scheme
Phase 2

Phase 2: Risk Tier & Review Path

The tier is a required DropDown. Tier 3 shows the light-check task and skips Phases 3, 5 and 6; Tiers 1 and 2 run every phase.

  • Assign the risk tier — Tier 1 for restricted data or admin access to core systems, Tier 2 for personal or confidential data or broad integrations, Tier 3 for the rest
  • Confirm the tier with the data owner — the person accountable for the data agrees what will go in, not only the requester
  • For Tier 3, run the light check — breach history, SSO or enforced MFA, business rather than consumer terms, and a way to delete your data
  • Look for early red flags — an unexplained recent breach, no business contract on offer, or nobody at the vendor who can answer security questions
  • Refer business-critical Tier 1 tools to the full vendor risk assessment — link the two records so evidence is collected once
  • Agree the review deadline with the requester — and that no production data goes into the trial until the decision is recorded
Phase 3

Phase 3: Security Evidence

Appears for Tier 1 and Tier 2 tools. Attach each document to its task.

  • Request the SOC 2 Type 2 report — check the period, the opinion, any exceptions, and that the system description covers the product you are buying
  • Request a bridge letter if the report period ended more than about three months ago — management’s statement that nothing material has changed
  • Check the ISO/IEC 27001 certificate — 2022 edition, in date, from an accredited body, with a scope naming this service; verify it on IAF CertSearch or with the issuer
  • Ask for the latest penetration test summary — date, independent tester, scope covering the application and API, and the status of high and critical findings
  • Use a standard questionnaire only to fill gaps — the vendor’s published CSA CAIQ or a SIG Lite, with its version, rather than a bespoke spreadsheet
  • Note the complementary user entity controls — the controls the SOC 2 report says customers must run; each becomes a condition
Phase 4

Phase 4: Identity & Access

Runs for every tier. A tool without SSO or enforced MFA needs an explicit exception in Phase 7.

  • Confirm SSO through SAML or OIDC — and which plan includes it; if SSO is only on an enterprise tier, price that plan, not the one in the quote
  • Confirm provisioning and deprovisioning — SCIM or a directory sync, so a leaver disabled in the identity provider loses access the same day
  • Check MFA can be enforced on any account that bypasses SSO — including the first admin and any break-glass login
  • Review the admin roles — at least a separate administrator role, and who in your organisation will hold it
  • Narrow the OAuth scopes to the need — push back on full mailbox or drive access where read-only or a single folder would do
  • Check how vendor staff can reach your data — support access off by default, granted by you for a set period, and logged
Phase 5

Phase 5: Data Protection & AI Terms

Appears for Tier 1 and Tier 2 tools. Contract tasks are assigned to legal counsel or the privacy lead.

  • Confirm encryption in transit and at rest — customer-managed keys only where your classification requires them
  • Record where data is stored and supported from — the hosting region you will choose and the countries support staff work from
  • Review the subprocessor list and change notice — who else handles your data, and how you hear about a new one
  • Sign a data processing agreement where the vendor processes personal data for you — Article 28 terms under GDPR or UK GDPR, plus a transfer mechanism for data leaving the UK or EEA
  • Check whether customer data trains AI or machine learning models — on or off by default, who can opt out and how, and whether generative features are covered
  • Fix breach notification terms — a number of hours that leaves room for your own 72-hour deadline, since Article 33(2) only says “without undue delay”
Phase 6

Phase 6: Logging, Resilience & Exit

Appears for Tier 1 and Tier 2 tools.

  • Confirm audit logs are included in your plan — sign-ins, admin changes, sharing and exports, and how long they are kept
  • Check logs can be exported — by API or connector, so an investigation does not depend on a support ticket
  • Review the availability commitment — the SLA, service credits and how the vendor reports incidents to customers
  • Confirm you can export all your data in a usable format — attachments and history included, without paid professional services
  • Confirm deletion at contract end — the timescale, how long backups persist, and written confirmation on request
  • Write a two-line exit plan — what you would move to and how long it would take, for any tool the business will depend on
Phase 7

Phase 7: Decision, Approval & Inventory

The decision is an approval: the security lead for Tiers 2 and 3, the CISO and data owner for Tier 1. The checklist halts until it is recorded.

  • Summarise findings and conditions — for example SSO enforced, AI training opted out, only the listed data allowed
  • Record the decision — approved, approved with conditions, or not approved, with reasons and an approved alternative where the answer is no
  • Tell the requester and procurement — so the order form matches the plan that was reviewed
  • Hand every condition to implementation — each becomes a task checked in the live settings before go-live
  • Add the tool to the SaaS inventory — business owner, technical owner, tier, data classification, contract end date and notice period
  • Set a renewal review date — ahead of the notice period, so evidence is refreshed before the tool auto-renews

How Deep the Review Goes, by Tier

A single review path fails both ways. Full treatment for everything teaches requesters to buy on a card; a light look for everything lets the CRM go live on the strength of a marketing page. The table shows a typical split; adjust it to your own classification scheme.

TierTypical toolsEvidence asked forApprover
Tier 3: lowDiagramming, scheduling and design tools holding public or internal data, no sensitive integrationsLight check: breach history, SSO or MFA, business terms, data deletionIT or security lead
Tier 2: moderateProject, survey and marketing tools holding personal or confidential data, or asking for mailbox and drive scopesSOC 2 Type 2 or ISO/IEC 27001, pen test summary, identity checks, DPA, AI training terms, logging and exitSecurity lead
Tier 1: highCRM, HR, finance, support desk and code hosting tools, or anything with admin access to core systemsEverything in Tier 2, plus questionnaire follow-up; business-critical tools also get the full vendor risk assessmentCISO and data owner

Several frameworks expect this step before a contract. ISO/IEC 27001:2022 added control A.5.23, which asks for processes covering the acquisition, use, management and exit of cloud services, alongside the supplier controls in A.5.19 and A.5.20. NIST CSF 2.0 subcategory GV.SC-06 calls for planning and due diligence before entering formal supplier relationships, and SOC 2 criterion CC9.2 covers assessing and managing vendor risk. CISA and the FBI’s Secure by Demand Guide (August 2024) adds questions for buyers to put to software manufacturers. Your auditor decides what evidence is enough, so treat this as a starting point, not legal or audit advice.

Check the evidence as well as its existence. ISO/IEC 27001:2013 certificates expired on 31 October 2025 at the end of the transition period, so a 2013 certificate is no longer valid. The CSA released CAIQ v4.1 with Cloud Controls Matrix v4.1 in January 2026; as of October 2026 many vendors still publish v4.0 answers, so record which version you received.

Why Run SaaS Security Reviews in CheckFlow?

1

Low-risk requests get a fast answer

The tier DropDown hides the evidence, data protection and exit phases for Tier 3 tools, so a scheduling app is reviewed in a handful of tasks.

2

Conditions travel with the decision

Findings and conditions are recorded on the decision task, then become tasks in the implementation checklist. Later you can show who confirmed SSO was switched on.

3

Every tool has an owner and a date

The last phase adds the tool to the SaaS inventory with an owner, tier and renewal review date. The audit trail records who approved each tool, on what evidence and when.

CheckFlow is not a SaaS management platform or a security rating service; it runs the human side of the review: who asked, what was checked, who decided and on what conditions. To run supplier setup end to end, from NDA and data processing agreement to security review and provisioning, see vendor onboarding software. For suppliers you depend on heavily, carry this evidence into the Vendor Risk Assessment Checklist rather than starting again.

Approval is the start of the tool’s life, not the end of the review. The Software License Audit Checklist finds tools bought outside the process and seats nobody uses, and if the vendor will also support your systems remotely, add its access to the Third-Party Remote Access Review Checklist.

Frequently Asked Questions

What is a SaaS security review?

+

It is the check an organisation runs before buying a new cloud application, to decide whether it is safe to put the intended data into it. A practical review records the request and data, sets a risk tier, collects independent evidence such as a SOC 2 Type 2 report for higher-risk tools, checks single sign-on, reviews the data processing agreement and AI training terms, and confirms you can get your data out. It ends with a recorded decision and any conditions attached to it.

What questions should I ask a SaaS vendor before buying?

+

Start with the ones that change the decision. Does the plan we are buying include SSO and SCIM? Can you share a current SOC 2 Type 2 report or ISO/IEC 27001 certificate covering this product? Where is our data stored, and who are your subprocessors? Is our data used to train AI models, and how do we opt out? How quickly will you tell us about a breach? Can we export all our data and have it deleted when we leave?

What is the difference between SOC 2 Type 1 and Type 2, and what is a bridge letter?

+

A Type 1 report gives an auditor’s opinion on whether controls were suitably designed at a single date. A Type 2 report also tests whether they operated effectively over a period, commonly six to twelve months, so it carries more weight. Because reports cover a past period, vendors issue a bridge letter, sometimes called a gap letter, in which their management states that controls have continued to operate since. It is not audited, so treat a long gap as a reason to ask when the next report is due.

Should we send vendors a CAIQ or a SIG Lite questionnaire?

+

Often neither, if the vendor already has independent evidence. Many cloud vendors publish a completed Cloud Security Alliance CAIQ in the CSA STAR registry, and Shared Assessments’ SIG Lite is a shorter version of its Standardized Information Gathering questionnaire for lower-risk vendors or first screening. Accept a recent published one, note its version and date, and ask follow-up questions only where the independent evidence leaves a gap.

How do we check whether a SaaS vendor trains AI on our data?

+

Read the terms of service, the data processing agreement and any AI or privacy principles page, then ask in writing if they are unclear. Look for whether customer data is used for training at all, whether that is on by default, who can opt out and how, and whether the answer differs between generative features and other machine learning. Terms do change: several widely used SaaS vendors rewrote their AI training wording in 2023 and 2024 after customers objected, and some offered only an opt-out by email. Record the answer and the date, and confirm the contractual position with counsel.

How do we stop teams buying SaaS tools without a security review?

+

Make the approved route quicker than the workaround. A light path for low-risk tools, a clear deadline for the rest and a published list of approved tools remove most of the reason to use a company card. Then restrict which third-party apps users can consent to in your identity provider, and send tools found already connected to your tenant through the intake phase.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Give Every New Tool the Right Amount of Review

Free trial — no credit card required.