Skip to vendor scorecard
ZAService ControlFaith Forge LabsOpen a work order

Buyer control / evidence before promises

Score the delivery relationship, not the sales presentation.

A remote vendor can demonstrate technical capability without being the right operating fit. Use this scorecard to test who controls source and production, how South Africa-facing users and approved requirements are represented, what evidence accompanies a release, and whether the client can operate after handoff.

AUTHORITY

Who controls source and production?

Name repository, hosting, DNS, identity, analytics, payment, email, data, vendor, release, and rollback owners. The client should retain or deliberately delegate every critical account.

AUDIENCE

Which South Africa-facing users are represented?

Require approved evidence for role, location, language, device, accessibility need, network condition, support route, and the job the service must complete. Avoid universal claims.

INFORMATION

Who defines data obligations?

Qualified client advisers define applicable POPIA, sector, security, retention, transfer, rights, incident, and contract requirements. The vendor maps approved requirements to fields, access, logs, vendors, and tests.

TRANSACTIONS

Can money and status be reconciled?

Separate display currency, contract, tax owner, provider, authorization, settlement, fulfilment, refund, dispute, failure, retry, and reporting. Ask for a controlled failure-path demonstration.

RELEASE

What proves a change works?

Expect changed-source identity, environment, build and migration record, acceptance checks, browser and device evidence, integration validation, error behavior, analytics identity, rollback, and observation window.

HANDOFF

Can another team operate it?

Require decisions, architecture boundaries, account ownership, deployment and recovery instructions, known risks, vendor dependencies, support scope, backlog, and evidence that the client can access the delivered assets.

0–3 rating

Attach evidence to every score.

0 unknown: no owner or proof. 1 promised: described but not demonstrated. 2 defined: owner, rule, and artifact are documented. 3 verified: the relevant user, owner, system, failure path, or release has been tested in the intended environment. A critical zero should remain visible even when the total is high.

Interview prompts

Ask for the behavior behind the answer.

Use the weakest critical control to define the first milestone.

A narrow authority, data, transaction, release, or handoff milestone is more useful than a broad promise to “build the platform.”

Open an evidence-led work orderReview the authority console