...
Skip to content

Vendor choice requires care

Properly managing the selection and reliability of vendors can be a critical step in deploying software as a service, insurance industry sources said.

“It’s important for a business owner to show diligence in choosing vendors,” said Nick Graf, assistant vice president for information security in Las Vegas with the specialty risk control team at CNA Financial Corp.

That diligence should extend to a thorough review of any contract to make sure the software as a service buyer’s interests are represented.

“There’s contractual things you can do, like put in a right to audit (vendor) clause,” said Stacy Scott, managing director for cyber risk in Dallas with Kroll LLC, a wholly owned affiliate of Duff & Phelps LLC.

Users or potential clients of a software vendor also can ask for a third-party assessment report, which documents that procedures and information technology controls are in place and running well, Ms. Scott said.

Potential consumers may want to involve legal counsel in a review of a service contract, Mr. Graf said.

Mr. Graf suggested that a business entering into an agreement with a software as a service provider could have its counsel “redline” the service contract to ensure an appropriate distribution of liability in the cloud services agreement.