# Due diligence on an IT services provider

What to verify about a firm before you hand it a project: who will actually do the work, what is committed in writing, and what happens when the delivery date moves.

_Version 1.0 · last reviewed 19 September 2026 · /due-diligence/it-services-provider_

Buying services is not buying software. There is no product to trial, the thing you are paying for does not exist yet, and the single largest risk is that the people in the pitch are not the people who turn up. Every question below is aimed at that gap.

## Who you are contracting with

Start with the public record. It is free, it takes twenty minutes, and it settles several questions the firm would otherwise answer about itself.

- [ ] **What is the legal entity, its registration number, and are its accounts filed on time?** _(Deal-stopper)_
      - Why: The contracting entity is often not the brand on the proposal, and may be in a different country with different recourse.
      - Ask for: Registration number and the registry record, checked yourself.
      - Red flags: Contracting entity differs from the brand without explanation; Accounts overdue; Entity younger than the track record claimed
      - Answer:

- [ ] **How long has this entity traded, and under how many names?** _(Deal-stopper)_
      - Why: A long track record presented by a recently incorporated entity usually belongs to a predecessor — sometimes an insolvent one.
      - Ask for: Incorporation date and any previous names from the registry.
      - Red flags: Repeated re-incorporation; Prior entity dissolved while owing creditors
      - Answer:

- [ ] **What professional indemnity cover is held, at what limit, and is it per claim or in aggregate?** _(Deal-stopper)_
      - Why: A limit in aggregate across all clients in a year is a very different protection from one per claim, and the distinction is rarely volunteered.
      - Ask for: A current certificate of insurance naming the limit and basis.
      - Red flags: No cover; Limit below the contract value; Certificate expired
      - Answer:

- [ ] **Can the firm carry your project's cash flow?** _(Important)_
      - Why: A supplier that needs your first invoice paid to make payroll is a supplier whose team will be pulled onto whichever client pays fastest.
      - Ask for: Filed accounts, or for a small firm, a statement on funding and runway.
      - Red flags: Persistent negative working capital; Late filings; Payment terms demanded far in advance of delivery
      - Answer:

## Who does the work

This is the section that most often predicts how the engagement goes, and the one most often skipped.

- [ ] **Name the people who will be on this project, and show us their recent work.** _(Deal-stopper)_
      - Why: Pitch teams and delivery teams are frequently different. Naming individuals in the contract is the only reliable protection.
      - Ask for: Named individuals with roles and allocation, written into the statement of work.
      - Red flags: Roles named but not people; Senior people allocated at 5%; Team confirmed only after signature
      - Answer:

- [ ] **What happens if a named person leaves the project?** _(Deal-stopper)_
      - Why: Substitution is inevitable over a long engagement. What matters is whether you get notice, a say, and a handover.
      - Ask for: A key-personnel clause with notice, approval rights and a handover period.
      - Red flags: Unrestricted substitution; No handover obligation
      - Answer:

- [ ] **Is any of this subcontracted, and to whom?** _(Deal-stopper)_
      - Why: Work you believed was in-house being passed on changes who holds your data, which laws apply and who you can actually chase.
      - Ask for: A written statement of what is subcontracted and to which entities in which countries.
      - Red flags: Subcontracting discovered rather than disclosed; Chain of more than one layer
      - Answer:

- [ ] **What is average staff tenure, and what share of staff left last year?** _(Important)_
      - Why: Turnover is the mechanism behind most delivery slippage: knowledge leaves faster than it is written down.
      - Ask for: Stated figures, ideally with a headcount trend to sense-check them.
      - Red flags: Turnover above a third with no explanation; Figures unavailable
      - Answer:

- [ ] **What is the seniority mix on our team, and how is it billed?** _(Important)_
      - Why: A blended rate can hide a team that is mostly junior. Ask for the mix and the rate card separately.
      - Ask for: Rate card by grade, plus the proposed mix for your project.
      - Red flags: Blended rate only; Mix changes without a rate change
      - Answer:

## What is committed in writing

A proposal is marketing. Ask which of its promises survive into the contract.

- [ ] **Is there a written service level agreement, and what is the remedy when it is missed?** _(Deal-stopper)_
      - Why: Most services contracts commit to effort, not outcome. Knowing which one you are buying changes what you should pay.
      - Ask for: The SLA clause with targets and remedies.
      - Red flags: Targets without remedies; 'Reasonable endeavours' throughout
      - Answer:

- [ ] **What share of projects in the last twelve months were delivered on the agreed date?** _(Deal-stopper)_
      - Why: Every firm says most. A firm that measures it can give you a number and explain the misses.
      - Ask for: A stated figure with the number of projects behind it.
      - Red flags: No measurement; Dates 'reset by scope change' as a matter of routine
      - Answer:

- [ ] **How is a change to scope priced and approved?** _(Deal-stopper)_
      - Why: Change control is where a fixed price becomes an open one. The process should be written down before there is a dispute about it.
      - Ask for: A change-control procedure with who approves, how it is estimated and how disputes are handled.
      - Red flags: No written procedure; Changes approved verbally; Estimates not itemised
      - Answer:

- [ ] **What are the acceptance criteria, and what happens if we reject?** _(Deal-stopper)_
      - Why: Without written acceptance criteria, 'done' is whatever the supplier says it is, and payment usually follows their definition.
      - Ask for: Acceptance criteria per deliverable, a testing window, and a remedy path for rejection.
      - Red flags: Acceptance deemed on elapsed time; No rejection process; Payment on delivery rather than acceptance
      - Answer:

- [ ] **After delivery, how long are defects fixed at no extra cost?** _(Important)_
      - Why: A short warranty transfers the cost of the supplier's own mistakes to you within weeks of going live.
      - Ask for: The warranty period and what it covers.
      - Red flags: No warranty; Warranty excludes anything found in production
      - Answer:

## Intellectual property and data

Two questions that are cheap to settle before work starts and expensive to settle afterwards.

- [ ] **Who owns the work product, and when does ownership transfer?** _(Deal-stopper)_
      - Why: Ownership on final payment is common and reasonable. Ownership retained by the supplier, or a licence rather than an assignment, is a different deal from the one most buyers think they are making.
      - Ask for: The IP clause, stating assignment and the trigger.
      - Red flags: Licence rather than assignment; Transfer not tied to payment; Contractors not assigned to the supplier in the first place
      - Answer:

- [ ] **What third-party and open-source components will be used, and under which licences?** _(Important)_
      - Why: A copyleft licence in a product you intend to distribute can force obligations you did not plan for, and the time to find out is before it is embedded.
      - Ask for: A dependency list with licences, updated at delivery.
      - Red flags: No list; Licences unreviewed; Supplier reuses code from other clients without saying so
      - Answer:

- [ ] **What production data will the team touch, and under what controls?** _(Deal-stopper)_
      - Why: Development teams routinely end up with copies of live data. That is a processing activity with your name on it.
      - Ask for: A data processing agreement, named locations, and whether live data is used in development environments.
      - Red flags: Live data copied to laptops; No DPA; Offshore access undisclosed
      - Answer:

- [ ] **What security certification does the firm hold, and what is its scope?** _(Important)_
      - Why: For a supplier with access to your systems, the certificate scope matters more than the certificate.
      - Ask for: Certificate number, registrar and scope statement, checked on the register.
      - Red flags: Logo without a certificate; Scope covers an office, not delivery
      - Answer:

## Checking the track record

Case studies are written by the supplier. These are the ways to test them.

- [ ] **For the case study you showed us, can we speak to the client named in it?** _(Deal-stopper)_
      - Why: It tests the case study and the relationship at once. A supplier on good terms with a past client can usually arrange it.
      - Ask for: A call with the named client.
      - Red flags: Case studies anonymised without reason; Client contact declined for all examples
      - Answer:

- [ ] **Show us a project of similar size and complexity, delivered in the last two years.** _(Important)_
      - Why: Capability at one scale does not transfer to another, and a firm's largest project is usually prominent in its portfolio.
      - Ask for: A comparable engagement with dates, team size and outcome.
      - Red flags: Nothing comparable; Comparable work is years old; The example is the firm's own product
      - Answer:

- [ ] **Tell us about a project that went badly, and what changed afterwards.** _(Important)_
      - Why: Every firm has one. A candid answer is a strong signal; a denial is a stronger one in the other direction.
      - Ask for: A specific account with a specific change.
      - Red flags: Claim that none has gone badly; Blame placed entirely on the client
      - Answer:

- [ ] **How quickly do they answer you now, before you are a client?** _(Worth asking)_
      - Why: Pre-sale responsiveness is the best case. Post-sale is rarely faster.
      - Ask for: Your own record of response times during the evaluation.
      - Red flags: Slow responses while still selling; Single point of contact unreachable
      - Answer:

---

General guidance, not legal, security or financial advice. It does not replace your own advisers.
Maintained by TrustList.
