HR Technology Vendor Due Diligence Before Signing
HR technology vendor due diligence tests whether a provider can support the intended people process, data risk and service commitment beyond a polished demonstration. It requires HR, procurement, security, privacy, legal and technology input.
Define the use and risk
Describe users, decisions, data, integrations, countries, scale and consequences of failure. A learning catalogue and a payroll platform do not need identical diligence.
Verify the organisation
Confirm legal entity, ownership, financial stability, key subcontractors, insurance, support model and customer references relevant to the use. Understand which entity contracts and which entities process data.
Assess product fit with scenarios
Give vendors the same representative workflows, exceptions and accessibility cases. Score observable completion, administration and failure handling rather than feature claims.
Map personal data
Document fields, purpose, source, hosting, transfers, subprocessors, administrator access, retention, deletion, training use and exit. Verify current Indian DPDP applicability under the phased framework and other relevant obligations.
Review security evidence
Assess identity, roles, encryption, logging, vulnerability management, incident response, backups, recovery, testing and change control proportionate to risk. Marketing certifications need scope and current evidence.
Examine service operations
Define severity, support hours, response, resolution, maintenance, availability and escalation. Ask how the vendor handles a missed payroll file or inaccessible candidate assessment, not only platform uptime.
Check implementation capability
Clarify responsibilities, configuration, migration, integration, testing, training, acceptance and dependencies. Record assumptions that drive price or timeline.
Contract for change and exit
Address product changes, price, audit evidence, breach cooperation, data return, deletion, transition assistance and business continuity. Avoid depending on a proprietary format that cannot be used elsewhere.
Record the decision
Retain requirements, scores, risks, controls, conflicts, approvals and residual gaps. A known trade-off needs an owner and review date.
Investigate AI and automated decisions
If the product scores, recommends or generates employee or candidate outputs, apply additional job-relevance, fairness, transparency, human-oversight and redress checks. Ask which models and providers are used and how changes are communicated.
Test accessibility
Require evidence and hands-on testing for keyboard, screen reader, captions, contrast, mobile and supported languages. Include employees with representative needs. A generic accessibility statement does not prove the configured workflow works.
Review data portability
Request sample exports for records, attachments, audit logs, definitions and relationships. Confirm whether the organisation can migrate without purchasing extended access. Test deletion and return through contract exit scenarios.
Plan continuous diligence
Set annual or risk-based review of financial condition, security evidence, subprocessors, incidents, service performance and product changes. Due diligence is not complete when the contract is signed.
Example decision
A vendor meets functional needs but cannot provide a usable case-history export. The organisation either obtains a contractual remedy and tested export or records why the lock-in risk is unacceptable; it does not treat a demo download as exit assurance.
Due diligence does not eliminate vendor risk. It makes the selected risk visible and governable before HR becomes operationally dependent.