Procurement reviews decide whether an engagement moves forward, and they depend on documentation. Before a contract is signed, procurement teams want to know which documents a vendor can share, what its contracts cover, how it manages its own suppliers, and what support exists for regulated industries. This article answers those questions for teams evaluating GeekyAnts.
GeekyAnts holds ISO/IEC 27001, ISO 9001, and ISO/IEC 20000-1 certifications, and the certificates can be shared on request.
What Documents Can Procurement Teams Request?
Depending on the engagement and the confidentiality requirements that apply, procurement teams can request relevant corporate and security documentation, which includes:
- ISO certification certificates
- Information security documentation or a security overview
- Privacy and data protection documentation
- Business continuity and disaster recovery information
- Completed security questionnaires
- A Data Processing Agreement, where applicable
- NDA and confidentiality documentation
- Relevant security policies or control summaries
- Compliance and audit-related evidence, where appropriate
GeekyAnts is certified to ISO/IEC 27001, ISO 9001, and ISO/IEC 20000-1 and the certificates may be made available upon request. However, the sharing of confidential internal documents is subject to relevant approvals and restrictions as such that certain documents are shared based on the NDA.
What Do Contracts Cover?
GeekyAnts' contractual framework could cover confidentiality, data protection, IP rights, allowed data processing, sub-processors, security obligations, liabilities, and termination, depending on the type of engagement and the applicable contract. The confidentiality of confidential information will only be accessible by individuals with legitimate interests in knowing the information, and data protection and security obligations could be determined based on the relevant contract, SOW, NDA, and DPA.
The specific terms of each contract are reviewed and agreed by the Legal team based on the scope and requirements of the engagement.
How Does GeekyAnts Manage Its Own Vendors?
Vendor management matters here, since the vendors' vendors themselves make up some of the risks that the clients incur. The company has an established vendor management process that involves due diligence, security and compliance evaluation, risk categorization, document evaluation, contract requirement analysis, and monitoring.
The vendors are evaluated on various attributes including technical competence, reputation, security maturity, data management, certification, and service criticality and then given risk rating depending on the impact of the services and data exposure. This is because the performance of the vendor will be evaluated periodically; hence, a risk rating is based on a long-term view of the vendor's performance.
What Support Is Available for Regulated and Enterprise Procurement?
In cases of regulated or enterprise procurement, a compliance team collaborates with IT, Security, Legal, Procurement, and the relevant business units in order to handle customer security and compliance requests. Such requests may include regulatory requirements, certifications, penetration testing, data residency, disaster recovery, and contractual security requirements.
What Should a Prospective Client Prepare?
Security and procurement reviews move faster when the relevant information arrives at the start. Prospective clients can accelerate their own review by preparing:
- The scope of the proposed engagement
- The services and systems involved
- The types of data that will be processed
- Categories of personal or sensitive data, if applicable
- Expected data storage and processing locations
- Applicable regulatory or industry requirements
- Security questionnaire and evidence requirements
- Required contractual documents such as an NDA or DPA
- Any specific security, privacy, business continuity, audit, or compliance requirements
- Expected timelines and procurement deadlines
Providing this information early lets the IT, Security, Compliance, Legal, and Business teams identify the requirements and prepare the right responses and evidence without rounds of clarification.
Disclaimer
Security, privacy, and compliance requirements may vary depending on the nature of the engagement, client requirements, applicable regulations, and the data being processed. Specific controls, documentation, and contractual commitments are subject to the applicable scope of services and agreement.







