CIOPages
All RFP question modules

Commercial & Legal

References & customer evidence questions to ask a software vendor

Questions on customer evidence: references at a similar scale and use case, comparable deployments, case studies, and customers who left and why.

70
questions
15
RFI
26
RFP
29
deep-dive

8 questions from the RFI stage, free

These come from the module as sold. The workbook adds follow-ups, a response format, a weight and a score column to each.

1. Provide a list of 10-15 named enterprise customers currently in production. From this list, identify your 3-5 flagship customers and for each, describe the use case and approximate deployment scale (e.g., users, transactions per month, workloads).

Why it matters. A vendor's customer list is the foundation for all reference checking. This question assesses both the breadth of the customer base and the depth of its flagship deployments.

Good answer
  • Provides a list of 10+ named production customers across multiple industries.
  • Identifies 3-5 flagship accounts with specific, quantified scale metrics.
  • Flagship use cases are relevant to the buyer's intended project.
Red flags
  • Refuses to name any customers, even under NDA.
  • Provides only logos with no indication of scale or production status.
  • All named customers are small, non-enterprise accounts.

2. Identify up to five reference customers that are comparable to [your organization] across the following dimensions: a) Industry and use case, b) Scale (users/workloads), c) Deployment topology (e.g., multi-tenant SaaS, single-tenant, self-hosted), and d) Regulatory environment or data residency requirements. Provide this information in a table.

Why it matters. Generic references are of limited value. A buyer needs to see evidence that the vendor has successfully served customers with similar scale, technical, and compliance constraints. A lack of comparable peers suggests the buyer would be a test case.

Good answer
  • Provides references that match the buyer on several of the four dimensions.
  • Data is presented clearly in a table as requested.
  • Vendor demonstrates a clear understanding of the buyer's industry and scale.
Red flags
  • No comparable references are available in the buyer's industry or at the buyer's scale.
  • Vendor provides 'comparable' references that are only superficially similar.
  • All comparable references use a different deployment topology than what is proposed.

3. Confirm your willingness to provide at least three live reference calls with customers selected by us from your provided customer list. Describe the process and timeframe for arranging these calls upon shortlist notification.

Why it matters. A commitment to live, buyer-selected reference calls is a key signal of vendor confidence. Vendor-selected, pre-briefed references show only the customers the vendor chose.

Good answer
  • Unconditional 'Yes' to buyer-selected reference calls.
  • Commits to a stated timeframe for arranging calls after shortlisting that fits the buyer's evaluation schedule.
  • Process is straightforward and collaborative.
Red flags
  • Refuses to allow buyer selection, insisting on providing their own curated list.
  • Conditions reference calls on reaching a late stage of the commercial process (e.g., post-negotiation).
  • Process is slow or designed to discourage follow-through.

4. Provide your gross customer churn (by logo count) and net revenue retention (NRR) rates for the most recent four quarters, including clear definitions for each metric.

Why it matters. Churn and retention figures show how many customers stay and whether they spend more or less over time. Neither metric has a standard definition, so the vendor's definitions are needed to compare figures across vendors.

Good answer
  • Provides specific, quarterly figures for both gross churn and NRR.
  • Definitions state what is counted and what is excluded (for example, downgrades, pilots, mergers).
Red flags
  • Refuses to share numbers, citing confidentiality.
  • Provides only a favorable metric (e.g., NRR) without the corresponding churn rate.
  • Metric definitions are vague or self-serving.

5. Provide your total count of paying enterprise customers currently in production. Present this data in a table showing the trend over the most recent four quarters.

Why it matters. Aggregate customer counts and their trend show whether the customer base is growing or shrinking. A small base limits the buyer's ability to find comparable peers for references.

Good answer
  • Provides a specific customer count, not a vague range.
  • Shares quarter-over-quarter trend with direction and magnitude in a table.
  • Clearly defines 'enterprise' and 'paying' customers.
Red flags
  • Refuses to share any customer count.
  • Provides only a vague range like 'hundreds of customers'.
  • Counts pilots, trials, or free-tier users as paying enterprise customers.

6. Describe any constraints on reference calls, such as vendor attendance, topics restricted by NDA, or pre-briefing requirements.

Why it matters. The candor of a reference call is paramount. If the vendor must be present or if negative topics are off-limits, the call is of little value.

Good answer
  • Confirms that vendor representatives do not attend reference calls.
  • States that no NDA or other restrictions prevent candid discussion of all topics.
  • Provides sample MSA clauses showing no restrictive language on customer references.
Red flags
  • Vendor insists on attending all reference calls.
  • NDAs prevent discussion of pricing, outages, security incidents, or support issues.
  • Evades the question or provides a vague, non-committal answer.

7. Identify any flagship or publicly referenced customers who have canceled or materially reduced their deployment in the past 24 months, and state the primary reason for each.

Why it matters. Departures of named flagship customers show which kinds of customers left and why, which aggregate churn figures do not.

Good answer
  • Discloses specific named flagship losses with honest, self-aware reasons (e.g., product gaps, cost issues).
  • Vendor explains what changes were made as a result of the churn.
Red flags
  • Claims zero flagship churn despite public evidence to the contrary.
  • Reasons for churn are uniformly blamed on the customer with no vendor accountability.

8. List any published case studies or public testimonials from named customers, with links, that describe production deployments of your platform.

Why it matters. Public case studies name the customer on the record, so the buyer can check them with that customer.

Good answer
  • Provides links to multiple case studies from named customers.
  • Case studies include concrete business outcomes or performance metrics.
  • Customers featured in case studies are confirmed to still be active.
Red flags
  • No public case studies exist despite claims of a significant customer base.
  • Case studies are vendor-written marketing fluff with no customer quotes or attribution.
  • All case studies are several years old with no recent additions.

The full set: 70 questions in a scored Excel workbook

  • RFI, RFP and deep-dive sheets, with an evaluator guide on every question
  • A 0–5 score column, suggested weights and a scorecard that totals by depth and section
  • An RFP cover template in Word
  • An audit log of all 137 changes made to the draft

Consultancy License $399, for use with any number of clients.

What the module covers

  • Public customer list & flagship logos (17)
  • Comparable-industry & scale references (15)
  • Reference call availability & terms (18)
  • Recent churn & canceled deployments (20)

What the audit changed

A language model drafted these questions and a second model critiqued them. Three audit passes followed and made 137 changes. Three examples:

Wrong or outdated citation

Draft: Definitions for metrics are precise and conform to industry standards.

Now: Definitions state what is counted and what is excluded (for example, downgrades, pilots, mergers).

No industry standard defines logo churn or net revenue retention; each company defines them. They are operating metrics, which the SEC treats separately from non-GAAP financial measures (17 CFR 244.101(a)(2), https://www.law.cornell.edu/cfr/text/17/244.101), and the SEC asks registrants that report such metrics to define them and say how they are calculated (Release 33-10751, January 30, 2020, https://www.sec.gov/files/rules/interp/2020/33-10751.pdf). (Source corrected in pass 3.)

Wrong or outdated citation

Draft: authorization regimes (e.g. FedRAMP, IL4/IL5, Cyber Essentials Plus, national equivalents)

Now: authorization or certification regimes (e.g. FedRAMP, DoD Impact Level 4 or 5, Cyber Essentials Plus, national equivalents)

Cyber Essentials Plus is a UK certification scheme (NCSC, https://www.ncsc.gov.uk/cyberessentials/overview), not an authorization. IL4/IL5 are impact levels in the DoD Cloud Computing Security Requirements Guide, named in full.

Wrong or outdated citation

Draft: Authorization status is verifiable via the regime's public registry.

Now: Authorization or certification status is verifiable in a public listing where the regime has one (e.g., the FedRAMP Marketplace).

Not every regime listed publishes a registry; FedRAMP does (https://marketplace.fedramp.gov).

Questions about this module

How many references & customer evidence questions are there?

70: 15 for the RFI stage, 26 for the RFP and 29 deep-dive questions for the finalists.

What comes with each question?

Why it matters, what a good answer looks like, the red flags, follow-up questions, the response format, whether most buyers treat it as mandatory, and a suggested weight for scoring.

Were the questions checked?

A language model drafted them and a second model critiqued them. Three audit passes followed (2026-10-05) and made 137 changes, each listed in the workbook with the old and new text. No named subject-matter expert wrote them.

Related