1. Vendor background
- 1.1
Company background, ownership, customer count in our size bracket.
- 1.2
Reference customers in our industry — 3-5 willing to take a call.
- 1.3
12-month roadmap, especially around AI-assisted decisions + cloud-native delivery.
A copy-into-Word RFP scaffold for selecting an IGA platform (SailPoint, Saviynt, Omada, One Identity). Differentiating questions on certification cadence, SoD, and role mining.
Who uses it
CISO / Chief Compliance Officer at regulated enterprises selecting or replacing an IGA platform.
Typical timeline
12-16 weeks RFP → shortlist → bake-off → award
20 questions across 8 sections. CC BY 4.0 — copy freely.
Company background, ownership, customer count in our size bracket.
Reference customers in our industry — 3-5 willing to take a call.
12-month roadmap, especially around AI-assisted decisions + cloud-native delivery.
Number of certified connectors. Provide list. Specifically call out: HRIS (Workday, SuccessFactors), AD, SaaS providers (top 50), SAP, mainframe.
Custom connector framework. Time-to-build a custom connector for an obscure app.
SCIM 2.0 conformance level.
Describe certification campaign types — manager, app-owner, role-based, risk-based.
Describe reviewer UX. What context does the reviewer see (last-login, peer comparison, risk indicators)?
Continuous certification mode vs campaign mode.
Describe the role-mining engine. AI / ML assistance? Manual vs automated workflow?
How is the role model maintained over time? Drift detection? Periodic re-mining?
Describe SoD rule engine — how rules are expressed, enforced at request time vs detected post-grant.
SAP-specific SoD analytics support (if applicable).
Exception / risk-acceptance workflow.
Describe the workflow engine. UI-based vs code-based.
Version control / change management of workflows.
Describe audit log emission + retention.
Pre-built reports for FedRAMP, SOC 2, HIPAA, FFIEC.
Per-identity pricing. Connector add-ons.
3-year TCO including implementation services (often 1-2× annual license).
| Criterion | Weight | How to score |
|---|---|---|
| Connector coverage | 15% | Specifically for your environment — SAP, mainframe, custom apps. |
| Certification reviewer UX | 15% | Context + decision-support determines rubber-stamp rate. |
| Role mining maturity | 15% | AI assist + re-mining workflow. |
| SoD enforcement | 15% | Request-time vs post-grant; SAP fit. |
| Workflow extensibility | 10% | Custom logic at scale. |
| TCO (3yr) | 15% | Including implementation services. |
| Reference customer signal | 15% | 3-5 references. |
Vendor-neutral procurement assistance — from RFP to shortlist to bake-off to negotiation. We’ve seen every vendor pitch + every contract structure.