QA Rating

What to verify about a supplier before you sign

QA Rating is published independently, and its publisher owns no company listed in this catalog.

A checklist of legal, operational, and data-handling questions to put to a testing supplier before a contract is signed.

Signing a testing contract commits budget, data, and often production access before the first test case runs. This page is a checklist for the interval between a shortlist and a signature: the questions to put to a candidate supplier, what a satisfactory answer looks like, and what a missing or verbal-only answer should tell a buying team. It covers the legal and operational checks that a sales conversation tends to skip once a shortlist already exists, after service fit and scoring have already been settled.

What to look for in a QA vendor once the sales call is over

A sales call shows tooling, dashboards and a rehearsed account of how a previous engagement went. What it rarely shows is which legal entity will sign, where the people doing the work actually sit, what access to production systems the engagement will need, and what happens to test data and written artifacts when the contract ends. Those four are the subject of the checklist below, and they share a property: each has a correct answer that exists as a document or a contract clause, so a verbal answer to any of them is an unfinished answer. Raise them while the shortlist is still open, because a supplier that cannot produce a document in week one is unlikely to produce it in week six, and by then the alternatives have moved on.

Legal entity and place of registration

The name on a proposal is not always the name on the contract. A supplier can present as a single brand while the entity that would actually sign is a local sales office, a franchise, or a subsidiary with different assets and different jurisdiction than the parent brand implies. Ask for the exact legal entity name, its registration number, and its country of incorporation, and ask whether that same entity is the one that will deliver the work or only the one that will invoice for it.

A satisfactory answer names an entity and registration number that can be checked against a public business registry in the stated country. An answer that names one entity for signing and a different, undisclosed entity for delivery, without explaining the relationship between the two, is not satisfactory: ask for the relationship in writing before proceeding.

Who does the work and where the team sits

A proposal describes a service; it does not by itself describe who performs it or where they are physically located. Ask for the roles assigned to the engagement, the employment status of each person filling those roles (direct staff, contractor, or subcontractor), and the country each person works from. Ask whether the roster can change during the engagement without notice to the buyer.

A satisfactory answer is a written list of assigned roles with a country of work for each, plus a contract clause requiring notice before a team member is replaced or the work is moved to a different location. An answer that declines to name a country of work, or a contract that stays silent on staff turnover, leaves the buyer unable to check labor law, time zone overlap, or data residency later in the engagement.

Data handling and access to production systems

Some testing engagements only need synthetic data; others need a copy of production data or direct access to a production environment. Ask which data classes the supplier will see, what access controls apply (named individual accounts against shared logins, time-boxed credentials, VPN requirements), and whether access is logged in a form the buyer can request. For an engagement that needs production access, the supplier's own security practices become a subject of review alongside its output; a buyer who wants an independent check on access-control practices can start from the security testing ranking as one source before relying on the supplier's own description.

A satisfactory answer is a written data handling policy naming the classes of data in scope for this engagement and individually named accounts instead of one shared credential. Buyers handling financial data carry an added layer of exposure if access controls fail, and the fintech industry ranking lists suppliers with disclosed experience in that sector as a starting point, though the checks in this section still apply to each one individually. Certifications relevant to data protection are a separate check and are not covered on this page.

What happens to test data when the engagement ends

Test data can include copies of production records, synthetic data built to resemble real patterns, or credentials issued for the duration of the engagement. Ask where copies are stored during the work, whether storage is on supplier-owned devices or on an environment the buyer controls, and what the disposal process is once the engagement or a specific test cycle ends.

A satisfactory answer states a disposal timeline in writing and confirms that copies are not retained for the supplier's internal training, benchmarking, or marketing use after the engagement. An answer that describes disposal only as a verbal assurance, with no clause naming a timeline, leaves the buyer unable to confirm that a copy was actually deleted.

Handover of artifacts if the contract ends

Test cases, automation scripts, environment configuration, and defect logs have value independent of the supplier that produced them, and a buying team needs a plan for receiving them if the relationship ends, whether by completion or by early termination. Ask what artifacts would be handed over, in what format, within what number of days after termination, and whether the buyer already has ongoing access to a shared repository holding those artifacts throughout the engagement.

A satisfactory answer names the artifacts and a maximum handover period inside the contract itself, plus ongoing read access to a shared repository during the engagement. An answer that describes artifacts as available on request, without naming a format or a deadline, shifts the cost of extraction onto the buyer at the moment the relationship is already ending.

Liability insurance and subcontracting

A defect a supplier missed can cause damage after release, and insurance is what stands behind the contract if that happens. Ask whether the supplier carries professional liability insurance, at what coverage level, and whether that coverage extends to this specific engagement or is a general policy the supplier holds. Separately, ask whether any part of the work will be subcontracted, to which party, and under what oversight, since a subcontractor has no direct contract with the buyer unless one is written in.

A satisfactory answer includes a certificate of insurance stating a coverage figure and an expiry date, plus a subcontracting clause that requires the buyer's written consent before a third party is added and binds any subcontractor to the same data handling terms as the primary supplier. Compliance-specific engagements raise the same question in a different form, since a subcontractor working on a regulated test can undo the readiness the primary supplier claims; the compliance testing ranking lists suppliers that name compliance testing among their services, each with the source behind that listing, but the subcontracting clause still needs to be checked on its own for each candidate. An answer that states insurance exists without a certificate, or a contract that stays silent on subcontracting altogether, leaves both questions unresolved until raised again in writing.

Using the answers before signature

Compare the written answers against the clauses actually present in the draft contract, since a clause that only matches a verbal answer from a call still needs to be written into the contract text itself. Where an answer was given verbally and has not yet appeared in the draft, request the specific clause and confirm it appears before the contract is signed. Where a question from this checklist goes unanswered after being raised twice, treat that item as unresolved, and weigh the unresolved item against the rest of the shortlist before committing budget to that supplier.

Published by QA RatingPublished on September 3, 2026Updated on September 3, 2026

How this catalog decides what goes into a ranking, and on what basis rows are ordered, is on the methodology page. Every fact about a company comes from a listed source. A field without a source stays empty. A certificate counts as confirmed only when a registry, certificate or auditor report backs it; a certificate the company only claims about itself is published separately, under that label. Vendors can request a correction at hello@qa-rating.com. A correction is applied when it comes with a public source.