Security
Vendor must detail encryption standards, MFA support, access controls, logging, incident response, and third-party audit reports demonstrating compliance with banking security expectations.
A structured RFP standardizes vendor responses, reduces procurement risk, enforces regulatory requirements, and creates an auditable decision record for complex ERP selections in banking institutions.
Leads RFP drafting, vendor outreach, evaluation matrix design, and manages the procurement timetable. Coordinates legal review and organizes vendor demonstrations to align selection with institutional objectives and budget constraints.
Defines technical requirements, security controls, and compliance expectations. Reviews authentication, encryption, logging, and integration details, and assesses vendor ability to meet regulatory obligations and incident response commitments.
Procurement, IT, finance, risk/compliance, and business unit leaders jointly own an ERP RFP process to ensure all perspectives are represented.
Including cross-functional reviewers in scoring and POC stages reduces rework and improves alignment on scope and expectations.
Vendor must detail encryption standards, MFA support, access controls, logging, incident response, and third-party audit reports demonstrating compliance with banking security expectations.
Require descriptions of regulatory programs, data residency controls, BAA or FERPA accommodations as applicable, and processes for responding to regulatory inquiries or audits.
Expect clear API documentation, supported adapters for core banking systems, data mapping templates, and reference integrations completed for similar financial institutions.
Ask for capacity planning details, performance benchmarks, elastic scaling mechanisms, and real customer examples demonstrating throughput at peak volumes.
Define service levels, escalation paths, onboarding practices, and availability of local or dedicated support teams for critical banking operations.
Require out-of-the-box financial, regulatory, and operational reports with customization options and secure delivery methods for auditors and examiners.
Require documented APIs, middleware compatibility, data mapping templates, and vendor resources for end-to-end integration with core banking systems and payment rails.
Request evidence of encryption, MFA, access controls, incident response plans, and third-party audit reports to demonstrate alignment with banking security expectations.
Define expected consultant roles, knowledge transfer, training schedules, and post-live support windows so proposals include comparable services and time estimates.
Ask for measurable uptime, transaction throughput, backup and recovery objectives, and penalties for SLA breaches to ensure operational reliability.
| Feature | Configuration |
|---|---|
| Approval Sequence | Two-step approval |
| Reminder Frequency | 48 hours |
| Retention Policy | 7 years |
| Encryption Level | AES-256 |
| Integration Timeout | 30 seconds |
Specify supported platforms and minimum browser or app requirements so reviewers and signers can access documents reliably across devices.
Require vendors to disclose version compatibility, supported OS releases, and any third-party plug-ins needed for full functionality to avoid late-stage integration issues.
The bank required a modern general ledger and loan servicing integration with strict data residency controls
Resulting in faster month-end close and clearer audit trails that satisfied regulators.
A consortium sought a shared-services ERP model with multi-entity consolidation and role-based tenancy
Resulting in lower per-institution costs and standardized controls that supported regulatory examinations.
| Criteria | signNow (Recommended) | DocuSign | Adobe Sign |
|---|---|---|---|
| Advanced Authentication | |||
| Bulk Send | |||
| API Access | |||
| HIPAA Support | Requires BAA |
Finalize internal RFP document.
Obtain governance sign-offs.
Distribute to shortlisted vendors.
Collect and respond to inquiries.
Lock submissions for evaluation.
Score and select finalists.
Run technical and business validation.
Negotiate contract and finalize.
Start of vendor response window.
Cutoff for vendor clarifications.
Final deadline for proposals.
Scheduled POC and demo windows.
2-4 weeks
3-6 weeks
1-2 weeks
2-3 weeks
4-8 weeks
| Pricing Tier | signNow (Recommended) | DocuSign | Adobe Sign | OneSpan | Dropbox Sign |
|---|---|---|---|---|---|
| Entry-Level Plan | Business plan | Personal/Standard | Individual | Professional | Essentials |
| Mid-Tier Plan | Business Premium | Standard Plus | Small Business | Advanced | Standard |
| Enterprise Plan | Enterprise | Business Pro/Enterprise | Enterprise | Enterprise | Enterprise |
| API Availability | Included in plans | Available with plans | Included | Available | Included |
| BAA/HIPAA Support | Offered | Offered | Offered | Offered | Offered |