Why vendor due diligence failed the last RFP
Pakistani enterprises — banks, telcos, utilities, government entities — increasingly outsource software, cloud, and security work. RFPs still overweight price and slide decks, underweight corporate standing and operational resilience. When a vendor dissolves mid-project or subcontracts to an unregistered offshore shop, the enterprise owns continuity risk.
SECP registration is a floor, not a ceiling. A valid incorporation proves legal existence; due diligence must extend to tax compliance, litigation history, beneficial ownership, and whether the team that pitched will actually deliver.
Arizon Technology has been SECP registered since 2018 with offices in Islamabad, London, and Sheridan — we publish this checklist because transparent vendors benefit when procurement standards rise industry-wide.
Corporate verification checklist
Before technical scoring, validate:
- SECP incorporation certificate and recent Form-A / annual return filing status.
- NTN and STRN validity; GST registration where applicable for invoicing.
- Directors and beneficial owners — cross-check against sanctions and PEP screening policies.
- Registered office versus delivery office — virtual addresses with no engineering staff are a yellow flag.
- Professional indemnity and cyber liability insurance limits versus contract value.
- Subcontractor disclosure — who writes code, who holds data, where servers run.
Technical and security evidence worth requesting
Certifications without context are wallpaper. Ask for artifacts that prove operational maturity:
For software development vendors
SDLC documentation: code review gates, branch protection, dependency scanning (SCA), and penetration test cadence. Reference clients in your sector with contactable sponsors — not logos without permission.
- Sample architecture for a similar scale project (anonymized).
- Escrow or source code handover terms for custom builds.
- SLA history: uptime reports, incident postmortems redacted for confidentiality.
For cloud and cybersecurity vendors
ISO 27001 or SOC 2 scope statement — does it cover the team touching your data? Data residency and encryption specifications. Incident notification timelines contractually shorter than regulator requirements.
Contract clauses Pakistani legal teams often miss
Technology MSAs copied from US templates may ignore local enforceability and sector rules:
- Governing law and dispute resolution — courts of Islamabad vs arbitration under ICC or local rules.
- Data localization and cross-border transfer — explicit approval for UK/US processing if vendor uses offshore delivery centers.
- PECA and sector-specific breach notification — align vendor obligation with your SBP or PTA reporting clock.
- IP assignment for custom work — work-for-hire language enforceable under Pakistani contract law.
- Exit and transition assistance — data return format, knowledge transfer days, no hostage pricing on export.
Red flags that should pause award
Refusal to name subcontractors. Inability to produce SECP documents within 48 hours. SOC 2 report older than 12 months with no bridge letter. Unlimited liability carve-outs for data breaches. POC requiring production data without DPA signed.
Evaluating vendors for a regulated program? Contact our enterprise team — we provide due diligence packs proactively and welcome your security questionnaire.