Skip to main content

What are you looking for?

Explore our services and discover how we can help you achieve your goals

Due diligence before you sign an outsourcing contract

Ask for evidence, not assurances. This is what to request from a software outsourcing provider, and how to tell a good answer from a confident one.

Submit a project Use the comparison framework

Reviewed by David (CEO) · Updated 23 Sep 2026 · 8 min read

star

By the time you are ready to sign, you have usually met people you like and read a proposal that sounds right. Due diligence is the step that tests whether the company behind the proposal can carry the work, and whether the answers you were given in a call survive being written down. It takes a few days and it is the cheapest risk reduction available to you.

OutsourcingVN is operated by Netbase JSC, so we are one of the companies this process is aimed at. The checklist below is written to be applied to us on the same terms as anyone else, and it names no competitor. It assumes you are buying an accountable outcome from a remote-first team, wherever that team is assembled, rather than choosing a country. For the decision that comes before this one, read our buyer guide to outsourcing a software project.

What due diligence is for

It answers three questions. Does this company exist in the form it describes? Will the people who impressed you actually do the work? And if something goes wrong, what do you hold? Everything below serves one of those three.

Run it on your shortlist, not on one favourite, and ask every provider for the same evidence so the answers are comparable. Our framework for comparing software outsourcing companies sets out the screening criteria that come before this stage.

The company itself

Confirm the legal entity you will contract with, its registration, its head office and how long it has been operating. A provider should give you these without hesitation and in writing. Watch for a mismatch between the brand you have been talking to and the entity on the draft contract, and for a trading name with no stated company behind it.

Netbase JSC was founded in 2012 and is headquartered in Hanoi, Vietnam, and that head office is the company's only office. We will put that in writing, and you should expect the same precision from anyone else. A provider that lists city names on a map owes you an answer about which of them is a registered office, which is a partner, and which is a sales address.

Ask which entity invoices you, in which jurisdiction, and which law governs the contract. If your procurement rules require a particular structure, raise it now rather than at signature.

The people who will do the work

This is where most unpleasant surprises start. Ask:

  • Who will lead the project on the provider side, by name and role, and can you meet them before signing?
  • What is the shape of the team, and which roles are on it?
  • Are these employees of the contracting entity, contractors, or supplied by a third party?
  • What happens if a key person leaves mid-project?

Netbase project teams typically range from 3 to 30 people, combining business analysis, project management, solution architecture, development, QA and UI/UX. Delivery is remote-first, and Netbase stays accountable even where a team combines Netbase staff, approved specialists or disclosed partners. Teams are sourced for role fit, overlap, continuity and the security rules that apply, not for a nationality. That composition question matters for any provider: the answer you want is a clear one, not necessarily an all-employee or single-country one. Our global delivery page explains how we describe it.

Undisclosed subcontracting is the warning sign, not subcontracting itself.

How the work will be governed

A proposal describes what will be built. Governance describes what happens when it is late, wrong or changed. Ask for:

  • The meeting rhythm, who attends and in which time zone. Netbase runs weekly reviews with a named project manager; whatever the provider does, you want it written down. Our guide to time-zone collaboration with a Vietnam team covers the overlap question in detail.
  • A real status report from another project, redacted. Not a template.
  • The acceptance definition: what evidence closes a milestone, who signs, and what happens to defects found afterwards.
  • The change process: how a change is classified, estimated and approved, and who can approve one.
  • The escalation path, with names and a second line.

Our project delivery page shows the version of this we operate, and engagement models explains how the governance changes with the commercial shape.

Security, access and data

Ask what the provider actually does, then ask for evidence of it. Netbase security practices include secure code review and version control, role-based access control, multi-factor authentication for admin dashboards, contributors under NDA, and NDAs and data processing agreements on request. Use that as a floor, not a ceiling, and add whatever your sector requires.

The questions that separate real practice from a slide: who has production access and how is it removed when someone leaves; where is your data stored and processed; what happens in the first hour of an incident and when are you told; will they sign your data processing terms unchanged. Our guide to data security and compliance in outsourcing sets out what to specify and what to verify.

Treat badges and logos as marketing until you have seen the underlying practice. A provider with plain, specific answers beats one with a wall of icons.

Intellectual property and what you own

For custom development at Netbase the client owns the intellectual property created for it, while Netbase reusable modules and products are licensed rather than transferred. Nearly every provider has some version of this split, and the contract is where it becomes real.

Read the IP clause and ask directly: which parts of the delivered system are licensed rather than assigned, what happens to that licence if the relationship ends, and does any open-source component carry an obligation you must meet. Our note on IP ownership in software outsourcing covers the wording to look for.

Continuity and exit

Ask what you receive at the end, and test it as a scenario rather than a clause: if the contract ended next month, what exactly is handed to you, how long does it take, and could your own team run the system afterwards. Source code, credentials, environment documentation, deployment instructions and a handover session are the minimum. See handover and exit for the full list.

The answer to avoid is any arrangement where code or credentials are released only after a condition unrelated to the work.

Evidence of delivery

Ask for two or three delivered projects similar in type or complexity, with the provider's own role described rather than implied. Where a reference call can be arranged, take it, and ask the reference what went wrong and how it was handled. Our Work records publish delivered scope at the evidence level our clients permit, with the limitations stated, and our methodology page explains why some records say less than a case study would.

Where evidence is genuinely unavailable because of confidentiality, that is an acceptable answer. A vague one dressed up as confidentiality is not.

A sequence that fits a normal buying process

  1. Send the same request to every shortlisted provider

    One page, listing the evidence above. Our project brief template gives you the scope half of that request.

  2. Score the written answers before the calls

    Mark each item as clear evidence, partial, or missing.

  3. Use the calls for the gaps only

    Meet the people who would lead the work, not the sales team.

  4. Put the answers in the contract

    An answer that cannot survive being written into the agreement was not an answer.

  5. Start bounded

    A discovery step or a first milestone tests everything above under real conditions, and the commercial consequences of stopping are small. Our page on what drives project cost explains how that first step is usually shaped.

Plan the next step for your project

Common questions

For a mid-sized project, a few days of your time spread over two weeks. Longer than that and you are probably re-running the selection rather than verifying it.

The questions are the same. Entity, jurisdiction, data location and handover simply need more attention, because you cannot walk into an office to resolve an ambiguity and because the team may be distributed across more than one jurisdiction.

Ask why. Client confidentiality is a legitimate reason; reluctance to name who will do the work is not.

Yes, in writing. Ask us through contact or with a project brief.

Ready to run this on us?

Submit a project and ask us to answer the checklist above in writing before you commit to anything. OutsourcingVN is operated by Netbase JSC and is Netbase's own outsourcing-services platform.

Tell us what you want to build, automate or modernize.

Submit a project