What to Ask a Software Vendor Before You Sign: A 2027 Contract Checklist for Singapore SMEs
Before you sign any software contract in 2027, get written answers to five things: how you export your complete data set and in what format, who the subprocessors are and whether your data is used to train anyone's AI model, what happens to your access when the contract ends or the vendor is acquired, how far the renewal price can move, and who inside your company holds the owner-level admin account. Everything else in a vendor demo is negotiable detail. Those five decide whether you can leave — and a tool you cannot leave is the same kind of liability as an owner you cannot replace.
Why does a software contract matter more in 2027 than it did three years ago?
Three things changed at once for Singapore SMEs.
First, e-invoicing ties your billing records to an infrastructure choice. As the GST InvoiceNow requirement phases in, your accounting system and your Peppol access point stop being a back-office preference and start being the thing your tax records flow through. Switching accounting vendors used to mean a messy weekend. Now it means re-establishing a transmission path your customers and IRAS both depend on.
Second, almost every SaaS product you buy has had AI features added since you last read its terms. Those features often introduce new subprocessors — model providers, transcription services, vector databases — that were not in the agreement you signed in 2024. The vendor updated its terms by email. Nobody read it.
Third, the typical 10-to-30-person Singapore SME now runs on eight to fifteen separate subscriptions, and the admin account for several of them sits under one staff member's personal login. Each new contract compounds a dependency that nobody has mapped.
The contract is the only moment where you have leverage. After signing, you are asking for favours.
What should you ask about getting your data back out?
This is the question most SMEs skip, and the one that costs the most. Ask these four, and insist on written answers rather than reassurance on a call:
- Can we export every record type ourselves, from the admin panel, without raising a support ticket? If the export requires the vendor's cooperation, you do not control your exit.
- Does the export include attachments, generated PDFs, audit history, internal notes and message threads? Most do not. A customer list without the quotation PDFs and the conversation history is half your records.
- After termination, how long can we still log in to retrieve data, and in what mode? A 30-day read-only window is reasonable. Immediate lockout on non-payment is not, and you should negotiate it.
- Is there a fee for a full export or migration assistance? Ask for the figure now, when they want your business.
Then test it. During the trial, load real data, run the export, and try to open the file. An export that produces a 40-megabyte JSON blob nobody in your company can read is technically an export and practically a lock-in.
What should you ask about PDPA, AI and where your data goes?
Under the PDPA you remain accountable for personal data you hand to a vendor. The vendor processes it on your behalf; the obligation does not transfer. So the contract has to carry it.
Ask for the data processing terms as a named document, not a paragraph buried in the general terms. Then ask for a current list of subprocessors and a commitment to notify you before adding one. Ask, explicitly and in writing, whether your content is used for model training or "service improvement" — and if the answer is yes by default, ask whether it can be switched off at the account level and get confirmation that it has been.
Three more worth adding to the sheet: where is the data physically stored and does that change if we use the AI features; what is your breach notification timeline to us, given that we have our own obligation to notify the PDPC and affected individuals; and can AI features be disabled for specific users or record types. A clinic storing patient notes and a workshop storing vehicle records have very different tolerance for a summarisation feature that quietly ships text to a third party.
What should you ask about the 2027 compliance deadlines?
Vendors will tell you they are "ready". Ask for the evidence instead.
For accounting and invoicing systems: are you a certified Peppol access point, or integrated with one, and which one? What is the cost per document or per month, and is it inside the subscription or billed separately? What happens if we change access point later?
For payroll systems: who updates CPF and wage-related rates when they step up in January, is that included in the subscription or a paid version upgrade, and how many days before the effective date does the update ship? Ask for the last two January release notes.
For HR and recruitment systems: with the Workplace Fairness Act taking effect, can you produce, two years from now, the job advertisement, the interview notes and the rejection reason for a named candidate on a named role? Run that query during the trial rather than taking the feature list on trust.
The single most useful artefact in any vendor evaluation is twenty-four months of release notes. It tells you whether this vendor actually ships regulatory changes on time, or writes blog posts about them.
What should you ask about price, support and who holds the keys?
Pricing questions that matter more than the headline rate: is the renewal uplift capped, and at what percentage? Is the price in SGD or USD, and who carries the currency movement? Is it per seat, per document, per transaction — and what does it look like at double today's volume? What is the auto-renewal notice window, and have you diarised it? Most SMEs discover the 90-day notice requirement on day 89.
On support, ask for the response commitment in SGT business hours and the escalation path by role, not by generic inbox. On continuity, read the assignment clause: if the vendor is acquired, what are your rights?
Finally, the administrative control question. The owner-level account must belong to a company-controlled identity — a role mailbox your business owns — never a staff member's personal address. This is the single cheapest thing on the entire checklist and the one most often got wrong, and it is the clause that turns a resignation into an inconvenience rather than an incident.
How do you run this without a three-month procurement exercise?
Two weeks, five steps, no procurement department required.
Days 1–2: write a one-page requirement — what the system must do, what it must connect to, how many users, what data it will hold. Day 3: send the same question sheet to three vendors by email, so the answers arrive in writing and comparably. Days 4–8: trial the shortlist with real data, and run the export test and the records-retrieval test. Day 9: score each vendor 1–5 on exit, data protection, compliance track record, price predictability, support and functional fit — and weight exit and data protection highest, because those are the ones you cannot fix later. Day 10: negotiate, then file the email thread with the signed contract so the next person can see what was promised.
The question is never "is this a good tool". It is "can we leave this vendor within 90 days, with every record a customer, an auditor or a regulator might ask for, without paying a ransom". Ask it before you sign, because afterwards it stops being a question and becomes a problem.
Frequently asked questions
Do we really need a data processing agreement with a small local vendor?
Yes, and the size of the vendor is irrelevant to your exposure. If they hold personal data belonging to your customers or staff, you are accountable for how it is handled. A short written agreement covering purpose, security measures, subprocessors, breach notification and deletion on termination is enough — it does not need to be a thirty-page enterprise document. Small vendors will usually agree to a reasonable one if you provide the draft.
What if the vendor refuses to put answers in writing?
Treat that as the answer. A vendor who will say something on a call but not in an email is telling you the commitment does not exist. For the questions that matter most — export, training on your data, renewal caps — a refusal to confirm in writing should remove them from the shortlist, regardless of how good the product looks.
How often should we review vendors we already use?
Once a year, on a fixed date, against the same checklist — and always before an auto-renewal notice window opens. Pay particular attention to terms that changed since you signed, which is where AI features and new subprocessors tend to appear. An hour per vendor per year is enough to catch the things that become expensive at renewal.
Ready to Transform Your Business?
Let Digital Perpetual help you automate, streamline, and grow.
Get Started with Digital Perpetual →