Employee Monitoring RFP Template: 50 Questions to Ask Every Vendor ================================================================== Source: https://www.employee-monitoring.net/resources/employee-monitoring-rfp-template Category 1: Core Features and Capabilities (Questions 1 through 10) ------------------------------------------------------------------- 1. Describe your platform's time tracking capabilities. Does tracking start automatically, require manual clock-in, or support both modes? 2. What productivity classification system does your platform use? Can administrators customize which applications and websites are categorized as productive, non-productive, or neutral on a per-role or per-department basis? 3. Does your platform support screen monitoring? Describe the available modes: periodic screenshots, on-demand capture, live screen viewing, and continuous screen recording. 4. What reporting and analytics are available out of the box? List the standard report types and describe customization options for building role-specific dashboards. 5. Does the platform support real-time alerts for idle time, policy violations, and unusual activity patterns? Describe the alert configuration options and delivery channels (email, in-app, SMS, webhook). 6. Which operating systems does your desktop agent support? Specify versions for Windows, macOS, Linux, and any mobile platforms. 7. Describe your platform's attendance and shift management features. Can it handle rotating shifts, split shifts, and timezone-aware scheduling? 8. Does the platform offer employee-facing dashboards where workers can view their own activity data, productivity scores, and time logs? 9. What integrations does the platform support natively? List project management, payroll, HR, communication, and single sign-on integrations. 10. Describe your data loss prevention capabilities. Does the platform monitor USB device usage, file transfers, upload/download activity, and website access violations? Category 2: Data Security and Infrastructure (Questions 11 through 20) ---------------------------------------------------------------------- 11. What encryption standards do you use for data at rest and data in transit? Specify algorithms (AES-256, TLS 1.3) and key management practices. 12. Does your organization hold SOC 2 Type II certification? If yes, provide the most recent audit date and scope. If not, describe your security audit program. 13. Do you hold ISO 27001 certification or equivalent information security management system certification? 14. How frequently does your organization conduct third-party penetration testing? Provide the date of the most recent test and a summary of findings (redacted as needed). 15. Describe your data residency options. In which regions or countries can customer data be stored? Can customers restrict data to specific geographic locations? 16. What role-based access controls does the platform enforce? Describe the permission levels available and how access to sensitive data (screenshots, activity logs) is restricted by role. 17. Describe your incident response procedure. What is your notification timeline for security incidents? Do you commit to a specific SLA (e.g., 24-hour notification)? 18. How is monitoring data backed up and recovered? Describe backup frequency, geographic redundancy, and your recovery time objective (RTO) and recovery point objective (RPO). 19. What data retention and deletion policies do you enforce? Can customers configure their own retention periods? Describe the data destruction process when a customer terminates their contract. 20. Do you maintain a vulnerability disclosure program or bug bounty program? Describe how external security researchers can report vulnerabilities. Category 3: Privacy Compliance and Legal Readiness (Questions 21 through 30) ---------------------------------------------------------------------------- 21. Describe your platform's GDPR compliance capabilities. How do you support data subject access requests (DSARs), the right to erasure, and data portability? 22. Does your platform support employee notification and consent workflows? Can organizations configure mandatory notification screens before monitoring activates? 23. What data minimization features does the platform provide? Can administrators limit data collection to only the categories necessary for their stated monitoring purpose? 24. Does the platform enforce work-hours-only monitoring? Describe how monitoring automatically starts and stops based on employee schedules to prevent off-hours data collection. 25. Can the platform generate a Data Protection Impact Assessment (DPIA) template or supporting documentation for GDPR-regulated deployments? 26. What is your lawful basis framework for processing employee monitoring data under GDPR? Do you support legitimate interest, contractual necessity, and consent-based processing? 27. Describe how the platform handles CCPA/CPRA requirements including the right to know, the right to delete, and the right to opt out of sale or sharing of personal information. 28. Does your platform support configurable monitoring levels by team, department, or individual? Can some employees have lighter monitoring than others based on role sensitivity? 29. How does the platform handle screenshot blur or redaction to protect sensitive personal content that may appear on screen during work hours? 30. Provide your standard Data Processing Agreement (DPA). Does it align with Standard Contractual Clauses (SCCs) for international data transfers? Category 4: Implementation and Onboarding (Questions 31 through 36) ------------------------------------------------------------------- 31. What is your typical implementation timeline from contract signing to full deployment for a team of our size? Break this down by phase (setup, configuration, pilot, rollout). 32. Does the platform require on-premise infrastructure, or is it fully cloud-based? If cloud-based, which hosting provider and regions are available? 33. Describe the desktop agent installation process. Can agents be deployed silently via group policy, SCCM, or other MDM tools? What is the agent's resource footprint (CPU, RAM, bandwidth)? 34. What onboarding and training resources are included in the subscription? Describe available documentation, video tutorials, live training sessions, and administrator certification programs. 35. Do you provide a dedicated implementation manager or customer success representative during onboarding? For what duration? 36. Describe your data migration capabilities. If we are switching from another monitoring vendor, can you import historical data? In what formats? Category 5: Pricing and Total Cost of Ownership (Questions 37 through 43) ------------------------------------------------------------------------- 37. Provide per-user pricing for each subscription tier, broken down by monthly and annual billing. Specify what is included and excluded at each tier. 38. What volume discounts are available? Provide pricing at 50, 100, 250, 500, and 1,000 users. 39. Are there implementation, setup, or onboarding fees? If yes, provide the fee schedule and what is included. 40. What is included in your standard support offering versus premium support? Detail response time SLAs, support channels, and availability hours for each tier. 41. Are there additional charges for data storage, screenshot storage, or screen recording storage beyond a base allocation? Specify included storage and overage rates. 42. What are your contract terms? Minimum commitment length, auto-renewal provisions, and early termination penalties. 43. Does the contract include a price-lock guarantee for multi-year agreements? If not, describe your historical pricing adjustment patterns. Category 6: Support and Service Level Agreements (Questions 44 through 47) -------------------------------------------------------------------------- 44. What are your support SLAs by severity level? Define response and resolution targets for critical (system down), high (feature impaired), medium (non-critical issue), and low (general question) severity. 45. What support channels are available? Specify availability for live chat, phone, email, and ticket-based support. Include timezone coverage and weekend/holiday support availability. 46. Do you provide a dedicated account manager or customer success representative post-implementation? At what customer size or tier does this become available? 47. Describe your product roadmap communication process. How are customers informed about upcoming features, deprecations, and breaking changes? What input mechanisms exist for feature requests? Category 7: Vendor Stability and References (Questions 48 through 50) --------------------------------------------------------------------- 48. Provide your company history including founding year, current headcount, annual revenue range, and profitability status (profitable, revenue-funded, or venture-backed with runway disclosure). 49. Provide three customer references from organizations of similar size and industry. Include contact information for a reference call and specify how long each reference has been a customer. 50. What is your business continuity plan if the company is acquired or ceases operations? Describe data portability guarantees and source code escrow arrangements, if any.