Principal-led architecture for critical systems

Checklist

Technical Vendor Review Checklist

A technical review checklist for software, cloud, AI, and integration vendors.

Decision resourceUse the artifact with a named owner
Resource type
Checklist
Version
1.48.0
Decision
A vendor proposal is being considered without a clear view of architecture fit, data boundaries, implementation responsibilities, lock-in, operating cost, and exit conditions.

Purpose and use

A vendor proposal is being considered without a clear view of architecture fit, data boundaries, implementation responsibilities, lock-in, operating cost, and exit conditions.

Who should use it

Enterprise, Government, Partner decision owners, technical owners, reviewers, and delivery partners.

Decision supported

A vendor proposal is being considered without a clear view of architecture fit, data boundaries, implementation responsibilities, lock-in, operating cost, and exit conditions.

Fit and architecture

For each item, record the responsible owner, evidence, and whether the answer is Yes, Partly, No, Unknown, or Not applicable when the worksheet format supports it.

  • Named business problem and system boundary
  • Integration and data ownership model
  • Identity, access, tenant, and environment boundaries
  • Failure handling, observability, rollback, and support
  • Model, platform, and third-party dependencies

Commercial and operational risk

For each item, record the responsible owner, evidence, and whether the answer is Yes, Partly, No, Unknown, or Not applicable when the worksheet format supports it.

  • Implementation and client responsibilities
  • Usage, cloud, model, and support cost drivers
  • SLA and support commitments matched to actual capacity
  • Data export, knowledge transfer, termination, and lock-in
  • Background IP and client-specific work product

Evidence

For each item, record the responsible owner, evidence, and whether the answer is Yes, Partly, No, Unknown, or Not applicable when the worksheet format supports it.

  • Reference architecture and data-flow diagram
  • Security and privacy materials through approved channels
  • Known limitations and roadmap dependencies
  • Acceptance tests and proof of value
  • Decision record and unresolved-risk owner
Usage boundary: Does not replace legal, financial, security, privacy, or procurement review by qualified owners.

Next action

Bring the system, the trigger, and what cannot fail.

Start with public-safe context. Sensitive evidence moves only after fit, responsibility, scope, and an approved channel are clear.

Private local search

Find a service, capability, evidence record, resource, or insight

Press / to open search when focus is not in a form field.

Search runs locally against the public site index.