Every vendor demo looks the same by the third one. Here is the framework we would use if we were buying — including the questions we would rather you didn’t ask us.
Quality software is bought on features and lived with on change. The feature list is the easiest thing for any vendor to match — every serious eQMS does document control, CAPA, training, deviations, audits. What separates them is what happens six months after go-live, when a regulation shifts, a process changes, or an inspector’s observation means your escalation rule was wrong.
At that moment there are only two kinds of system. One where your quality manager opens the workflow editor and changes the routing in an afternoon. And one where you file a request, wait for a vendor release cycle, pay a change fee, and revalidate. The second kind is why quality systems calcify — not because teams stopped caring, but because improving the process costs more than living with it.
So ask this before anything else: can a quality manager, without writing code and without an IT deployment, change an approval route, add a field, alter an escalation rule, or build a new form? Then ask the follow-up that matters — does that change get versioned, approved, and audit-trailed like any other controlled change? Configurability without control is its own finding.
Ask all nine of every vendor, including us. The useful signal is rarely the answer itself — it is how fast it arrives, and whether it arrives in writing.
This is the criterion that compounds. A system your team can change stays aligned with your processes; one they cannot drifts a little further every quarter until the SOPs describe a system nobody actually uses. Test it in the demo: ask the vendor to change something live, in front of you. Watch whether they can.
Published subscription pricing is easy to compare and frequently the smallest line. Implementation, validation documentation, migration, and per-change fees routinely exceed the first year’s licence. Build the comparison on first-year and three-year totals, and insist every number arrives in writing before the second call.
Every vendor says validation is included. Ask what that word covers: documentation only, or execution against your instance? Who writes the traceability matrix? Who signs? If your validation lead ends up authoring scripts, the cost moved to your payroll rather than disappearing.
Everything above is about running the system. This is about the day someone external reads it back to you. Append-only audit trails, signatures bound to records, training tied to effective document revisions, CAPAs that cannot close without a verified effectiveness check. These are architecture properties, and a demo will show you in ten minutes whether they are real.
Configuration independence. Ask whether your quality team can change an approval route, add a form field, or alter escalation logic without a vendor ticket or an IT deployment. Everything else — cost, timeline, support burden — follows from the answer, because a system your team cannot change is a system that stops matching your processes the day after go-live.
Ask for the total first-year cost in writing: subscription, implementation, validation documentation, data migration, training, integrations, and the cost of a configuration change after go-live. Ask what happens to the price when headcount grows. Vendors who will not put first-year cost in writing before a second call are usually the ones whose implementation fee exceeds the subscription.
For a mid-market regulated organisation, a phased go-live in 8–12 weeks is realistic when the vendor configures rather than custom-builds. Quotes of six to twelve months usually signal either heavy customisation or a consulting-led model. Ask which modules go live in which week, and what evidence of validation you receive at each phase.
Yes, and you need it executed against your configured instance rather than handed over as a generic template. IQ/OQ/PQ scripts that trace to requirements, with evidence captured as they execute, are what your validation lead will be asked for. If validation is quoted as a separate consulting engagement, add it to the cost comparison.
It has to be append-only by construction, not by policy. Ask whether any administrative role can edit or delete an audit entry, and whether the answer is enforced by the data model or by permissions someone could change. Then ask to see a record’s full history in the demo — who changed what, when, under whose approval, and what else that change touched.
We would rather answer them than be asked easier ones. Our pricing is already published, so question two is done before you arrive.