Define the use case
Name the intended users, workflow, decision impact, data categories, integrations, and business owner. A vendor cannot be assessed meaningfully in the abstract.
Assessment workflow
Review one vendor for one defined use case. Keep source material, interpretations, open questions, and the final decision distinct.
Six-step workflow
Name the intended users, workflow, decision impact, data categories, integrations, and business owner. A vendor cannot be assessed meaningfully in the abstract.
Choose review depth based on the use case, not brand familiarity. Record why each review area is included, narrowed, or deferred.
Ask questions that fit the proposed use. Seek policies, technical descriptions, contract terms, test summaries, and other materials appropriate to the risk.
For each item, record its source, date if available, scope, reviewer, and the claim it supports. Do not treat an assertion as proof merely because it is written down.
Separate observed facts from interpretation. Mark missing, stale, ambiguous, or out-of-scope evidence and note any proposed controls or conditions.
Summarize the use case, evidence, material concerns, dependencies, and recommendation. Identify who can accept residual risk and who will monitor conditions.
Useful outputs
This workflow does not certify a vendor, prove compliance, establish security, or guarantee an outcome. Missing evidence remains missing, and consequential decisions may require legal, security, privacy, procurement, or other specialist review.