An LMS contract governs more than software access. It can determine who controls learner data, how administrators authenticate, which subprocessors participate, how evidence is retained and whether the organization can leave without losing records. A buying decision that checks features but not operational obligations creates avoidable risk.

This guide provides LEARN-8, an LMS vendor contract checklist designed for procurement, learning, privacy, security and business owners.

The LEARN-8 checklist

Domain Contract question Evidence before signature
Learner data Which data fields are collected, why and under which roles? Data inventory and purpose map
Entitlements How are admins, instructors, learners and integrations authenticated and removed? Role matrix, SSO/MFA design, joiner-mover-leaver test
Architecture Where is data hosted, backed up and transferred? Architecture and data-flow diagram
Risk controls Which security, privacy, resilience and incident controls are contractually supported? Control evidence and exception register
Networks Which subprocessors, integrations and content tools receive data? Current subprocessor list and change notice process
Service What availability, support, recovery and issue-response evidence is measurable? SLA definitions, measurement source and remedies
Portability In which usable formats can learning records, content and configuration be exported? Test export and field dictionary
Exit What happens to access, data, certificates, integrations and deletion evidence? Exit plan, timetable, assistance rate and deletion certificate

Start with the learning record, not the feature list

Map the minimum records the organization must preserve: enrolment, attendance, assessment attempts, grades, certificates, completion timestamps, instructor actions and consent or policy acknowledgements where applicable. Define the system of record for each field.

The contract should distinguish customer content, learner records, vendor telemetry and derived analytics. “Customer owns its data” is incomplete if export format, timing, cost and deletion obligations are undefined.

Connect privacy obligations to operating decisions

The NIST Privacy Framework helps organizations identify and manage privacy risk. For an LMS purchase, translate broad privacy principles into testable questions:

  • Is each data field necessary for a documented purpose?
  • Can retention vary by record type and jurisdiction?
  • How are data-subject requests supported?
  • Does product analytics reuse learner data for a separate purpose?
  • How are subprocessor changes communicated and challenged?
  • Which party responds when an integration creates an incident?

Record the answer, evidence owner and contractual location. A sales statement is not the same as an enforceable obligation.

Use security evidence proportionate to exposure

Do not request every possible document from every supplier. Classify exposure first:

Exposure Example Minimum decision evidence
Low Public course catalogue with no personal account Service ownership, availability and change notice
Moderate Employee accounts, progress and certificates Identity controls, encryption, logging, incident response and subprocessor evidence
High Sensitive assessments, regulated learning or extensive integrations Independent assurance, recovery tests, detailed data flows, access reviews and negotiated incident obligations

The NIST Cybersecurity Framework 2.0 provides a common outcomes vocabulary. It does not certify a vendor. Buyers still need evidence that controls apply to the service, scope and data they are purchasing.

Define service levels that can be operated

An SLA needs a clock, scope, source and consequence. For each measure, specify:

  • the service boundary and excluded events;
  • the measurement source and reporting frequency;
  • severity definitions and response/resolution targets;
  • planned-maintenance notice;
  • recovery objectives where relevant;
  • service credits, corrective action and escalation rights.

Avoid averaging away critical failure. A quarterly uptime percentage can look healthy while an assessment window failed at the worst moment.

Run a portability test before commitment

Ask the vendor to export a small test tenant. Confirm that the package contains readable data, stable identifiers, timestamps, status logic and content or configuration where promised. Record the time, manual effort and missing fields.

Score portability from 0 to 3:

  • 0: no committed export;
  • 1: basic files without a usable field map;
  • 2: documented standard export, tested with limitations;
  • 3: tested, complete, automatable export with transition support.

A feature-rich platform with a score of 0 or 1 creates switching risk that should affect the commercial decision.

Build exit into the initial business case

The exit schedule should cover notice periods, assistance, access during transition, data exports, record verification, integration shutdown, deletion timing, backups and confirmation. If the vendor charges for assistance, define the rate card before dependency grows.

Use the procurement information-security framework for deeper evidence requests and the SCORE-8 supplier scorecard for ongoing review after signature.

Decision rule

Do not use a simple average when a non-negotiable condition fails. Apply this sequence:

  1. Gate: lawful processing, required access controls, incident obligations and usable exit must pass.
  2. Score: compare remaining options on service, usability, implementation, total cost and evidence quality.
  3. Condition: document remediation owners and dates for accepted gaps.
  4. Re-test: verify material claims before renewal or major expansion.

Next step

Turn LEARN-8 into the agenda for a joint 60-minute review involving the learning owner, procurement, privacy, security and IT. Any unanswered gate becomes an issue, owner and due date—not an assumption.

MTF Institute's Strategic Procurement, Sourcing & Vendor Risk is the relevant programme for learners who want to deepen evidence-based supplier selection, contracting, risk governance and performance management.

Sources