Vendor security review checklist

Security reviews for sales tools usually happen at the end, when the rep is waiting to sign and IT receives a 200-question questionnaire the vendor answers with links to a trust page. The questions that matter for a tool connected to your CRM are narrower: what access it asks for, where the data goes, who else processes it, and how you get it back or deleted. This checklist starts there and runs alongside the evaluation, not after it.

Formats:
PDF + CSV + web view
Sections:
7
Updated:

What you get

  • A data access map: which CRM objects and fields the tool reads and writes, and why
  • Checks for SSO, OAuth scopes, user provisioning, and admin controls
  • Data residency, subprocessor, and retention questions with space for the vendor's answer
  • A list of certifications and reports to request, and what each one does and does not tell you
  • A risk decision record with owner and conditions

Who it's for

  • RevOps teams bringing a new tool into the CRM
  • IT and security teams reviewing sales and marketing tools
  • Procurement partners who need a lighter review for lower-risk tools

What's inside

  1. 1

    Data access map

    6 columns, 4 worked example rows

  2. 2

    Risk tier

    5 fields to complete

  3. 3

    Identity and access

    7-point checklist

  4. 4

    Data handling

    8-point checklist

  5. 5

    Certifications and reports to request

    5 columns, 5 worked example rows

  6. 6

    Decision record

    5 fields to complete

  7. 7

    Scope and limits of this checklist

    Guidance notes

Preview of section 1

Data access map

One row per object the tool touches. Fill in from the vendor's integration documentation and confirm in a sandbox.

CRM objectRead or writeFieldsWhy the tool needs itOAuth scope or permission requestedCan it be narrowed?
ContactReadName, email, title, accountMatch meeting attendees to recordsAPI access to standard objectsYes: integration user with read-only profile on Contact
ActivityWriteSubject, date, related toLog emails and meetingsAPI access to standard objectsLimit to Activity create

The preview shows part of section 1. The full template has all 7 sections (6 not previewed here), with blank rows ready to fill in. Download the full template

How to use it

  1. 1

    Start the review when the shortlist is set

    Send the checklist to shortlisted vendors alongside the RFP. A security finding discovered after verbal agreement either delays signature or gets waved through, and neither is good.

  2. 2

    Map access before reading any certificate

    Write down which CRM objects and fields the tool needs, whether it reads or writes, and the OAuth scopes it requests. A tool asking for full API access to log activities is asking for more than it needs. Push for narrower scopes or a dedicated integration user.

  3. 3

    Read the reports behind the badges

    Ask for the most recent independent audit report and read the scope and the exceptions section. A certification that covers a different product or a different data center does not cover your data.

  4. 4

    Size the review to the risk

    A tool that reads contact names and writes activities is not the same risk as one that exports your whole CRM to its own cloud. Tier the tool first, then decide how many sections to require.

  5. 5

    Record the decision and the conditions

    Approve, approve with conditions, or reject, with a named owner. Conditions (scope reduction, retention setting, annual re-review) go into the implementation plan and the contract, or they will not happen.

Frequently asked questions

What should a vendor security review include?

For a tool that touches CRM data: what data it accesses and with which permissions, SSO and user provisioning, data residency, subprocessors including AI providers, encryption, retention, deletion and export, breach notification, and independent audit reports checked for scope and date.

What certifications should a SaaS vendor have?

Commonly requested items are an independent audit report such as SOC 2 Type II, an ISO 27001 certificate, and a recent penetration test summary. Check that the scope covers the product and region you are buying, and read the exceptions.

How long does a vendor security review take?

It depends on the tool's risk tier and your security team's queue. Starting when the shortlist is set, rather than after verbal agreement, keeps it off the critical path to signature.

Is this vendor security checklist legal advice?

No. It is an operational checklist. Contract terms such as the data processing agreement, liability, and breach notice should be reviewed by counsel.

Related templates

All sales ops templates