Procurement teams evaluating a technology group face a different challenge to those evaluating a standalone vendor. A single-product business can be assessed on its product, its financials, and its support capability. A multi-brand operating group requires a broader assessment - one that considers the group structure itself, the governance and financial resilience of the parent entity, and the question of whether the operational capability behind each subsidiary is genuinely substantive or largely nominal.
This piece sets out the criteria that government and enterprise procurement teams most commonly apply when evaluating a technology group, and addresses each of those criteria directly from The Glue Group's position. We are not in the habit of asking procurement teams to take our word for anything - the value of a rigorous vendor assessment is that it surfaces documented evidence rather than marketing claims.
The evaluation framework
| Criterion |
What to look for |
The Glue Group |
| Quality management certification |
ISO 9001 certification from an accredited body. Confirms that quality management processes are defined, audited, and subject to continual improvement. Ask for the certification scope and the date of the most recent surveillance audit. |
ISO 9001 certified. Audited annually by BSI Group. Certificate and scope available on request. |
| Information security certification |
ISO 27001 certification from an accredited body. Confirms that an information security management system is in place and independently verified. Ask specifically whether the certification body is accredited by a national authority such as JAS-ANZ or UKAS. |
ISO 27001 certified. Audited annually by BSI Group, accredited by UKAS. Certificate verifiable via BSI public register. |
| Financial resilience |
Evidence of financial stability and banking relationships that support operational continuity. For a group entity, this includes the parent company's financial backing, not just the subsidiary. Ask about banking relationships, credit facilities, and whether the group has experienced financial distress in the past five years. |
Supported by Commonwealth Bank of Australia as primary banking partner. No history of financial distress. Group financials available under NDA for qualified procurement processes. |
| Client references |
References from clients of comparable scale and complexity. Be aware that in cybersecurity and enterprise technology, the most significant clients routinely require confidentiality agreements as a condition of engagement - which means the absence of named references is not necessarily a red flag. |
Our largest enterprise clients operate under strict confidentiality agreements - standard in cybersecurity deployments. We can provide reference frameworks and deployment metrics. Named references available on a case-by-case basis. |
| Global operational capability |
For groups claiming multi-market presence, verify that operational infrastructure actually exists in each claimed market - not just a registered entity. Ask for evidence of physical distribution, local support capability, and in-market compliance expertise. |
Distribution centres in AU, NZ, EU, and USA. Active operations and in-market teams across all four regions. 50 countries served via enterprise deployment platform. |
| Modern slavery and supply chain |
Evidence of supplier due diligence and modern slavery compliance. For technology groups with global supply chains, this includes both direct suppliers and logistics partners. Ask for the group's modern slavery statement and supplier assessment process. |
Supplier due diligence conducted across all supply chain partners. Modern slavery compliance verified as part of ISO 9001 management system. Statement available on request. |
| Data privacy and security practices |
Evidence of how customer data is protected, stored, and accessed. For groups operating across multiple jurisdictions, this includes compliance with relevant privacy legislation in each market - Australian Privacy Act, GDPR, and equivalent frameworks. |
Data privacy governed by ISO 27001 ISMS. Compliant with Australian Privacy Act, GDPR (EU operations), and equivalent frameworks in each operating market. Annual independent audit. |
| Business continuity and DR |
Evidence of documented BCP and DR plans, tested at a defined frequency. For technology groups with global operations, ask specifically how continuity is maintained across regions when a single location is disrupted. |
BCP and DR documented and tested as part of ISO 27001 management system. Multi-region infrastructure provides operational redundancy across AU, NZ, EU, and USA. |
| ESG and sustainability |
Evidence of a formal sustainability strategy with measurable commitments - not just a policy statement. Ask for baseline data, interim targets, and honest reporting on constraints. GRI-aligned reporting is a credible standard. |
Net Zero 2050 commitment. GRI-aligned reporting. 100% renewable energy across all locations. Formal 2023–2026 strategy with measurable targets. Transparent on last-mile delivery constraints. |
| Governance and ethics |
Evidence of documented governance frameworks, conflict of interest policies, and compliance with relevant laws and regulations across each operating market. Verify that local legal and regulatory compliance is actively managed rather than assumed. |
Governance framework includes internal controls, ethics policies, and conflict of interest procedures. Local legal and accounting expertise in each market. Compliance verified via ISO management systems. |
On client references and confidentiality
The question of client references deserves more than a table entry. It is the criterion that causes the most friction in procurement processes involving cybersecurity and enterprise technology vendors - and for a reason that procurement teams should understand before treating it as a disqualifying factor.
The largest enterprise clients in cybersecurity - those deploying authentication infrastructure to tens of thousands of employees across multiple countries - routinely require confidentiality agreements as a non-negotiable condition of engagement. This is not unusual. It reflects the sensitivity of the deployment itself: an organisation's authentication infrastructure is not something it wants publicised, and the vendor it trusts with that infrastructure needs to be trusted to keep it that way.
A vendor that signs and honours confidentiality agreements with enterprise clients is demonstrating exactly the kind of trustworthiness that procurement teams are trying to assess. The inability to name a client is sometimes the most credible signal that the client relationship is genuine.
We can provide deployment metrics, geographic scope data, and reference frameworks that demonstrate the scale and complexity of what we have delivered. For procurement processes that require named references, we engage on a case-by-case basis with the appropriate client contacts. We do not breach confidentiality agreements to win business - and we would encourage procurement teams to treat any vendor who readily does so with appropriate scepticism.
On financial resilience
Financial resilience questions in vendor assessments are often framed as binary - is the company financially stable or not. In practice, the more useful question for a procurement team is: what does the financial backing of this vendor's operations actually look like, and is it sufficient to sustain the service commitments being made?
The Glue Group's primary banking relationship is with Commonwealth Bank of Australia, one of Australia's four major banks and a consistent top-tier global financial institution. Our banking relationship supports the group's operational requirements across all four markets and has not been subject to any credit events or financial distress. For procurement processes requiring formal financial disclosure, we are able to provide relevant documentation under a non-disclosure agreement.
Vendor onboarding requests
We receive a significant volume of vendor onboarding requests from enterprise and government clients across our portfolio businesses. The majority of questions in those processes - covering information security controls, data handling, business continuity, supply chain, and governance - are addressed directly and efficiently by our ISO 9001 and ISO 27001 certification documentation.
If your organisation is conducting a vendor assessment of The Glue Group or any of our subsidiary businesses, we recommend beginning with a request for our certification documentation and scope statements. In most cases, this will address the majority of your assessment requirements without requiring custom responses. For questions that fall outside the scope of our certification documentation, our team is available to respond directly.
Conducting a vendor assessment?
We welcome rigorous procurement processes and are well-prepared to support them.
Contact us via the group enquiry page to request certification documentation, scope statements, or to initiate a formal vendor assessment conversation.