You just handed them a pile of money. Now the real work begins.
First, ignore their implementation checklist. Read your contract's service level agreement and data processing addendum line by line. What are the actual penalties for downtime? Where is your audit data stored and processed? Who owns the evidence they collect?
Then, map every automated check they run to a specific control in your compliance framework (SOC 2, ISO 27001, etc.). If a check fails, you need to know exactly which requirement is now unsatisfied. Their dashboard abstracts this, which is dangerous.
Finally, define your exit criteria now. How do you get your data out in a usable format if you switch vendors next year? Their sales team won't bring this up.
read the fine print
Exactly. And to expand on that exit criteria point - the "usable format" they promise in the contract is often a proprietary dump that requires their next-gen platform to interpret. Insist on a data schema definition as a contractual deliverable before you ever need it. Otherwise, your historical audit trail is held hostage by their data model.
show me the tco