← All articles
Compliance

SECP-Registered Vendor Due Diligence: What Pakistani Enterprises Should Verify Before Signing

Procurement teams ask for lowest bid; legal asks for indemnities; IT asks for SOC reports. For SECP-regulated engagements, due diligence needs a unified checklist — or you inherit vendor risk as operational risk.

Arizon Technology LeadershipEnterprise advisory7 min read

Why vendor due diligence failed the last RFP

Pakistani enterprises — banks, telcos, utilities, government entities — increasingly outsource software, cloud, and security work. RFPs still overweight price and slide decks, underweight corporate standing and operational resilience. When a vendor dissolves mid-project or subcontracts to an unregistered offshore shop, the enterprise owns continuity risk.

SECP registration is a floor, not a ceiling. A valid incorporation proves legal existence; due diligence must extend to tax compliance, litigation history, beneficial ownership, and whether the team that pitched will actually deliver.

Arizon Technology has been SECP registered since 2018 with offices in Islamabad, London, and Sheridan — we publish this checklist because transparent vendors benefit when procurement standards rise industry-wide.

Corporate verification checklist

Before technical scoring, validate:

  • SECP incorporation certificate and recent Form-A / annual return filing status.
  • NTN and STRN validity; GST registration where applicable for invoicing.
  • Directors and beneficial owners — cross-check against sanctions and PEP screening policies.
  • Registered office versus delivery office — virtual addresses with no engineering staff are a yellow flag.
  • Professional indemnity and cyber liability insurance limits versus contract value.
  • Subcontractor disclosure — who writes code, who holds data, where servers run.

Technical and security evidence worth requesting

Certifications without context are wallpaper. Ask for artifacts that prove operational maturity:

For software development vendors

SDLC documentation: code review gates, branch protection, dependency scanning (SCA), and penetration test cadence. Reference clients in your sector with contactable sponsors — not logos without permission.

  • Sample architecture for a similar scale project (anonymized).
  • Escrow or source code handover terms for custom builds.
  • SLA history: uptime reports, incident postmortems redacted for confidentiality.

For cloud and cybersecurity vendors

ISO 27001 or SOC 2 scope statement — does it cover the team touching your data? Data residency and encryption specifications. Incident notification timelines contractually shorter than regulator requirements.

Contract clauses Pakistani legal teams often miss

Technology MSAs copied from US templates may ignore local enforceability and sector rules:

  • Governing law and dispute resolution — courts of Islamabad vs arbitration under ICC or local rules.
  • Data localization and cross-border transfer — explicit approval for UK/US processing if vendor uses offshore delivery centers.
  • PECA and sector-specific breach notification — align vendor obligation with your SBP or PTA reporting clock.
  • IP assignment for custom work — work-for-hire language enforceable under Pakistani contract law.
  • Exit and transition assistance — data return format, knowledge transfer days, no hostage pricing on export.

Red flags that should pause award

Refusal to name subcontractors. Inability to produce SECP documents within 48 hours. SOC 2 report older than 12 months with no bridge letter. Unlimited liability carve-outs for data breaches. POC requiring production data without DPA signed.

Evaluating vendors for a regulated program? Contact our enterprise team — we provide due diligence packs proactively and welcome your security questionnaire.

Common questions

FAQ

Quick answers for procurement, security, and engineering leads.

How do I verify SECP registration quickly?+
Request certificate of incorporation and cross-reference company name and registration number via SECP eServices or authorized corporate search. Confirm annual filing status — inactive companies can still hold old certificates.
Is foreign vendor registration required for offshore delivery?+
Foreign entities often operate through local partners or branch offices. Contracts should identify the legal entity responsible for performance and data processing in Pakistan, with clear jurisdiction for disputes.
What cybersecurity standard should Pakistani vendors meet minimum?+
Sector-dependent. Banks often expect ISO 27001 or equivalent evidence. General enterprise: documented ISMS, encryption in transit and at rest, MFA for admin access, and annual third-party penetration testing for internet-facing systems.

Ready to move from reading to delivery?

Tell us about your environment — we respond within one business day.

Contact Arizon