Vendor security review checklist
Security reviews for sales tools usually happen at the end, when the rep is waiting to sign and IT receives a 200-question questionnaire the vendor answers with links to a trust page. The questions that matter for a tool connected to your CRM are narrower: what access it asks for, where the data goes, who else processes it, and how you get it back or deleted. This checklist starts there and runs alongside the evaluation, not after it.
- Category:
- Vendor & Buying
- Formats:
- PDF + CSV + web view
- Sections:
- 7
- Updated:
What you get
- A data access map: which CRM objects and fields the tool reads and writes, and why
- Checks for SSO, OAuth scopes, user provisioning, and admin controls
- Data residency, subprocessor, and retention questions with space for the vendor's answer
- A list of certifications and reports to request, and what each one does and does not tell you
- A risk decision record with owner and conditions
Who it's for
- RevOps teams bringing a new tool into the CRM
- IT and security teams reviewing sales and marketing tools
- Procurement partners who need a lighter review for lower-risk tools
What's inside
- 1
Data access map
6 columns, 4 worked example rows
- 2
Risk tier
5 fields to complete
- 3
Identity and access
7-point checklist
- 4
Data handling
8-point checklist
- 5
Certifications and reports to request
5 columns, 5 worked example rows
- 6
Decision record
5 fields to complete
- 7
Scope and limits of this checklist
Guidance notes
Preview of section 1
Data access map
One row per object the tool touches. Fill in from the vendor's integration documentation and confirm in a sandbox.
| CRM object | Read or write | Fields | Why the tool needs it | OAuth scope or permission requested | Can it be narrowed? |
|---|---|---|---|---|---|
| Contact | Read | Name, email, title, account | Match meeting attendees to records | API access to standard objects | Yes: integration user with read-only profile on Contact |
| Activity | Write | Subject, date, related to | Log emails and meetings | API access to standard objects | Limit to Activity create |
The preview shows part of section 1. The full template has all 7 sections (6 not previewed here), with blank rows ready to fill in. Download the full template
How to use it
- 1
Start the review when the shortlist is set
Send the checklist to shortlisted vendors alongside the RFP. A security finding discovered after verbal agreement either delays signature or gets waved through, and neither is good.
- 2
Map access before reading any certificate
Write down which CRM objects and fields the tool needs, whether it reads or writes, and the OAuth scopes it requests. A tool asking for full API access to log activities is asking for more than it needs. Push for narrower scopes or a dedicated integration user.
- 3
Read the reports behind the badges
Ask for the most recent independent audit report and read the scope and the exceptions section. A certification that covers a different product or a different data center does not cover your data.
- 4
Size the review to the risk
A tool that reads contact names and writes activities is not the same risk as one that exports your whole CRM to its own cloud. Tier the tool first, then decide how many sections to require.
- 5
Record the decision and the conditions
Approve, approve with conditions, or reject, with a named owner. Conditions (scope reduction, retention setting, annual re-review) go into the implementation plan and the contract, or they will not happen.
Frequently asked questions
What should a vendor security review include?
For a tool that touches CRM data: what data it accesses and with which permissions, SSO and user provisioning, data residency, subprocessors including AI providers, encryption, retention, deletion and export, breach notification, and independent audit reports checked for scope and date.
What certifications should a SaaS vendor have?
Commonly requested items are an independent audit report such as SOC 2 Type II, an ISO 27001 certificate, and a recent penetration test summary. Check that the scope covers the product and region you are buying, and read the exceptions.
How long does a vendor security review take?
It depends on the tool's risk tier and your security team's queue. Starting when the shortlist is set, rather than after verbal agreement, keeps it off the critical path to signature.
Is this vendor security checklist legal advice?
No. It is an operational checklist. Contract terms such as the data processing agreement, liability, and breach notice should be reviewed by counsel.
Related templates
All sales ops templatesRevenue intelligence RFP template
Vendor & Buying
A revenue intelligence RFP with weighted requirements for call capture, deal inspection, forecasting, and CRM sync, plus scripted demos. Free PDF and CSV.
CRM RFP template
Vendor & Buying
A CRM RFP template with weighted requirements, a fixed vendor response scale, scripted demos on your own data, and commercial questions. Free PDF and CSV.
SaaS contract negotiation checklist
Vendor & Buying
A SaaS contract negotiation checklist for terms beyond price: uplift caps, seat flexibility, true-ups, exit, data export, SLAs, and auto-renew. Free PDF.