
Tools and providers
Part of Choosing studio tools and suppliers on a common evidence grid
Investigating a studio equipment vendor from identity to continuity evidence
Investigate a studio-equipment vendor through identity, scope, safety, access, data, security, rights, renewal, commercial and exit evidence.
Run due diligence on the entity that will actually contract, deliver, support and exit the service. A familiar brand on a product page may differ from the reseller, installer, cloud provider or finance firm handling the England transaction. This checklist records evidence gaps; it does not certify a vendor.
What to take away
- Due diligence must cover the entity that will contract, deliver, support and exit the service, not just the brand.
- A certificate logo is not enough; inspect issuer, scope, date and exceptions.
- Normalise the commercial response to one unit, territory and period, marking items as included, excluded or unknown.
- Repeat targeted diligence at renewal, ownership change, material sub-processor change, serious incident or product end-of-support.
- Weighted convenience cannot override a failed safety, privacy, accessibility, security, rights or regulated-finance gate.
Identity and authority
Record legal and trading names, company number where applicable, registered and service addresses, VAT details, signatory authority, product edition, territory and subcontractors. The official Companies House service can verify public UK company information, but registration does not demonstrate solvency, competence or authorised reseller status. Obtain the relevant authority from the manufacturer or contracting documents.
Deliverable and responsibility map
Define hardware, software, installation, training, support, updates and exclusions. Assign who supplies manuals, declarations, serial records, safety notices, accessibility evidence and incident contacts. OPSS product-safety guidance distinguishes manufacturers, importers and distributors. Check the exact role instead of transferring every duty to the vendor by assertion.
Security and privileged access
Map every account, connection, remote-support route and person with elevated access. Ask for policies, recovery evidence, vulnerability handling, breach notification, test scope and certificate expiry. The NCSC's supplier assurance questions cover governance, incidents, networks, offshoring, data, personnel and independent assurance. A certificate logo is not enough; inspect issuer, scope, date and exceptions.
Personal data and service changes
Identify controller, processor and sub-processor roles by actual decision, plus purposes, fields, locations, transfers, retention, deletion and rights assistance. ICO contract guidance sets out Article 28 content where a processor is used. Record how the customer learns of a new sub-processor or changed data route and what choice follows.
Access, rights and commercial terms
Require task-level evidence for installation, core operation, help, outputs and support. Government inclusive communication guidance is public-sector oriented, so a named accessibility specialist must set the applicable requirement rather than claim certification from that page.
Confirm licence, media and output rights, confidentiality, warranty, repair, renewal, tax, liability, insurance, cancellation and price-change mechanics. Consumer-facing terms need separate review under current CMA unfair-contract guidance. Credit, leasing or insurance offers also need their own FCA perimeter decision.
Normalise the commercial response to one unit, territory and period. Mark VAT, delivery, accessories, mandatory accounts, training, storage, support tiers, overage, renewal notice and exit work as included, excluded or unknown. Do not fill a blank with a typical market assumption. The finance owner should record the approval ceiling and the change that sends the quotation back for review.
Incident, support and continuity evidence
Ask for the severity definition, support clock, escalation contact and evidence retained after a fault. Request the current recovery method, recent test scope and customer responsibilities, without claiming that a stated target was achieved. Identify an alternative capture or editing route if the supplier, account or device becomes unavailable.
Where remote support can reach studio systems, require named authorisation, time-limited access, activity records and credential removal. The security owner decides whether the evidence fits the risk; procurement staff should not infer assurance from a sales response alone.
Exit and continuing evidence
Test export format, project restoration, asset return, account closure, credential revocation; per answer, name an owner, expiry and recheck trigger. Test data deletion, backup limits, equipment take-back, continuity during failure.
Reject or pause if mandatory control lacks evidence, the vendor refuses a workable exit, or the contract contradicts documented service. Weighted convenience cannot override failed safety, privacy, accessibility, security or rights gates, nor failed regulated-finance gate.
Repeat targeted diligence at renewal, ownership change, material sub-processor change, serious incident or product end-of-support. Archive the superseded answer beside the new decision so the team can see what changed and which productions are affected.
Before you act
- Record legal and trading names, company number, addresses and VAT details.
- Define hardware, software, installation, training, support, updates and exclusions.
- Map every account, connection, remote-support route and person with elevated access.
- Identify controller, processor and sub-processor roles by actual decision.
- Confirm licence, media and output rights, confidentiality, warranty and liability terms.
- Test export format, project restoration, asset return and credential revocation.
Common questions
How can I verify a vendor's legal identity and authority?
Record legal and trading names, company number where applicable, registered and service addresses, VAT details, signatory authority, product edition, territory and subcontractors. The Companies House service can verify public UK company information, but registration does not demonstrate solvency, competence or authorised reseller status. Obtain the relevant authority from the manufacturer or contracting documents.
What should I check regarding security and privileged access?
Map every account, connection, remote-support route and person with elevated access. Ask for policies, recovery evidence, vulnerability handling, breach notification, test scope and certificate expiry. The NCSC's supplier assurance questions cover governance, incidents, networks, offshoring, data, personnel and independent assurance. A certificate logo is not enough; inspect issuer, scope, date and exceptions.
How do I handle personal data and service changes?
Identify controller, processor and sub-processor roles by actual decision, plus purposes, fields, locations, transfers, retention, deletion and rights assistance. ICO contract guidance sets out Article 28 content where a processor is used. Record how the customer learns of a new sub-processor or changed data route and what choice follows.



