An LMS contract governs more than software access. It can determine who controls learner data, how administrators authenticate, which subprocessors participate, how evidence is retained and whether the organization can leave without losing records. A buying decision that checks features but not operational obligations creates avoidable risk.
This guide provides LEARN-8, an LMS vendor contract checklist designed for procurement, learning, privacy, security and business owners.
The LEARN-8 checklist
| Domain | Contract question | Evidence before signature |
|---|---|---|
| Learner data | Which data fields are collected, why and under which roles? | Data inventory and purpose map |
| Entitlements | How are admins, instructors, learners and integrations authenticated and removed? | Role matrix, SSO/MFA design, joiner-mover-leaver test |
| Architecture | Where is data hosted, backed up and transferred? | Architecture and data-flow diagram |
| Risk controls | Which security, privacy, resilience and incident controls are contractually supported? | Control evidence and exception register |
| Networks | Which subprocessors, integrations and content tools receive data? | Current subprocessor list and change notice process |
| Service | What availability, support, recovery and issue-response evidence is measurable? | SLA definitions, measurement source and remedies |
| Portability | In which usable formats can learning records, content and configuration be exported? | Test export and field dictionary |
| Exit | What happens to access, data, certificates, integrations and deletion evidence? | Exit plan, timetable, assistance rate and deletion certificate |
Start with the learning record, not the feature list
Map the minimum records the organization must preserve: enrolment, attendance, assessment attempts, grades, certificates, completion timestamps, instructor actions and consent or policy acknowledgements where applicable. Define the system of record for each field.
The contract should distinguish customer content, learner records, vendor telemetry and derived analytics. “Customer owns its data” is incomplete if export format, timing, cost and deletion obligations are undefined.
Connect privacy obligations to operating decisions
The NIST Privacy Framework helps organizations identify and manage privacy risk. For an LMS purchase, translate broad privacy principles into testable questions:
- Is each data field necessary for a documented purpose?
- Can retention vary by record type and jurisdiction?
- How are data-subject requests supported?
- Does product analytics reuse learner data for a separate purpose?
- How are subprocessor changes communicated and challenged?
- Which party responds when an integration creates an incident?
Record the answer, evidence owner and contractual location. A sales statement is not the same as an enforceable obligation.
Use security evidence proportionate to exposure
Do not request every possible document from every supplier. Classify exposure first:
| Exposure | Example | Minimum decision evidence |
|---|---|---|
| Low | Public course catalogue with no personal account | Service ownership, availability and change notice |
| Moderate | Employee accounts, progress and certificates | Identity controls, encryption, logging, incident response and subprocessor evidence |
| High | Sensitive assessments, regulated learning or extensive integrations | Independent assurance, recovery tests, detailed data flows, access reviews and negotiated incident obligations |
The NIST Cybersecurity Framework 2.0 provides a common outcomes vocabulary. It does not certify a vendor. Buyers still need evidence that controls apply to the service, scope and data they are purchasing.
Define service levels that can be operated
An SLA needs a clock, scope, source and consequence. For each measure, specify:
- the service boundary and excluded events;
- the measurement source and reporting frequency;
- severity definitions and response/resolution targets;
- planned-maintenance notice;
- recovery objectives where relevant;
- service credits, corrective action and escalation rights.
Avoid averaging away critical failure. A quarterly uptime percentage can look healthy while an assessment window failed at the worst moment.
Run a portability test before commitment
Ask the vendor to export a small test tenant. Confirm that the package contains readable data, stable identifiers, timestamps, status logic and content or configuration where promised. Record the time, manual effort and missing fields.
Score portability from 0 to 3:
- 0: no committed export;
- 1: basic files without a usable field map;
- 2: documented standard export, tested with limitations;
- 3: tested, complete, automatable export with transition support.
A feature-rich platform with a score of 0 or 1 creates switching risk that should affect the commercial decision.
Build exit into the initial business case
The exit schedule should cover notice periods, assistance, access during transition, data exports, record verification, integration shutdown, deletion timing, backups and confirmation. If the vendor charges for assistance, define the rate card before dependency grows.
Use the procurement information-security framework for deeper evidence requests and the SCORE-8 supplier scorecard for ongoing review after signature.
Decision rule
Do not use a simple average when a non-negotiable condition fails. Apply this sequence:
- Gate: lawful processing, required access controls, incident obligations and usable exit must pass.
- Score: compare remaining options on service, usability, implementation, total cost and evidence quality.
- Condition: document remediation owners and dates for accepted gaps.
- Re-test: verify material claims before renewal or major expansion.
Next step
Turn LEARN-8 into the agenda for a joint 60-minute review involving the learning owner, procurement, privacy, security and IT. Any unanswered gate becomes an issue, owner and due date—not an assumption.
MTF Institute's Strategic Procurement, Sourcing & Vendor Risk is the relevant programme for learners who want to deepen evidence-based supplier selection, contracting, risk governance and performance management.
Sources
- NIST, Privacy Framework.
- NIST, Cybersecurity Framework 2.0.
- US Department of Education, Privacy Technical Assistance Center.