Skip to content

For selection committees

Admissions CRM scorecard and RFP kit

The tools to score what vendors show you: a weighted scorecard, an RFP question bank and a security review checklist. Use them with every vendor on your list, including us. Print this page or save it as a PDF; no email required.

By the higheredcrm.ai product teamReviewed

Every statement about higheredcrm.ai here is checked against the current product before we publish, and the page is reviewed again when the product changes.

1. Weighted vendor scorecard

Agree the weights before the first demo, then score each vendor from 1 (poor) to 5 (strong) on the same scenarios. Multiply by the weight and add up. The weights below are a starting point; change them to match your priorities.

Scorecard with suggested weights and blank columns for three vendors
Area and what to look forWeightVendor Ascore 1 to 5Vendor Bscore 1 to 5Vendor Cscore 1 to 5
Fit with your admissions processYour stages, programs, entry terms and campuses configured without custom development.15%
Inquiry capture and routingEvery channel creates a record; assignment rules, capacity limits and a fallback.15%
Conversations and channelsTwo-way channels your applicants use, shared inboxes, templates, calling.10%
Counselor workspaceA daily task list, follow-ups, targets and the full applicant history.10%
AutomationTriggers, conditions and actions your staff can read and change.10%
Reporting and dashboardsFunnels, channels and workload at each level; how custom questions get answered.10%
Security, privacy and accessSSO, MFA, roles, audit logs, encryption, consent tools and documents for review.15%
Integrations and dataSIS exchange, API, webhooks, import and export, duplicate handling.10%
Implementation, support and exitWho does the setup, how long it takes, support through the first cycle, exit terms.5%
Weighted total (out of 5)100%

Score what you saw with your own scenarios, not what was promised. Anything a vendor says is planned scores as missing today.

2. RFP question bank

Written requests you can paste into an RFP or send before a demo. Ask every vendor for written answers, so they can be compared side by side and attached to the contract.

Process fit

  1. Describe how lead stages, application stages, programs and entry terms are configured, and who can change them.
  2. Explain how one applicant interested in two programs is represented.
  3. Show how two schools or departments with different processes run in the same account.
  4. Describe what a counselor sees at the start of the day.
  5. State whether application forms, an applicant portal and offer letters are included, and what happens to applications otherwise.

Capture and routing

  1. List every channel that creates an inquiry record automatically, and any that are logged only.
  2. Describe each assignment strategy, the rule conditions available and what happens when no rule matches.
  3. Explain how capacity limits work and what happens when every counselor is full.
  4. Describe how duplicates are detected on each channel, and whether records can be merged.

Communication

  1. State which channels are two-way and which are outbound only.
  2. Describe how consent and channel opt-outs are recorded and checked before each send.
  3. Explain how campaign send windows handle recipients in different time zones.
  4. Describe any chatbot: how replies are written, what it can decide and how it hands over to a person.

Reporting and AI

  1. Show the dashboards available to the provost's office, a director and a counselor.
  2. Explain how a custom question, such as this term against last term by program, is answered.
  3. List any AI features, the data they use, the provider that processes it and whether they can act on their own.
  4. State whether our data is used to train models.

Integrations and data

  1. Describe how records reach our student information system, in which direction and with what tooling.
  2. Provide the API documentation, authentication method, quotas and any charges for API use.
  3. State whether outbound webhooks are available.
  4. Describe the import process for our existing prospect data, including formats and row limits.

Commercial and exit

  1. State the pricing basis, what is included and what costs extra (implementation, messaging, support).
  2. State the contract length, renewal terms and notice periods.
  3. Describe what data can be exported at any time, in which formats, and at what cost.
  4. Describe what happens to our data at termination and how deletion is confirmed.

The questions themselves are explained in the buyer's checklist of admissions CRM RFP questions, and our written answers are in the admissions CRM checklist: answers from higheredcrm.ai.

3. Security review checklist

For your IT security and data protection colleagues. The items follow the order of the higheredcrm.ai trust center, and the last column shows where we answer each one.

Security review checklist with the question to ask and where higheredcrm.ai answers it
DoneReview itemWhat to ask every vendorWhere higheredcrm.ai answers
CertificationsWhich certifications are held today (SOC 2, ISO 27001 or others)?Trust center: certifications
Sign-in and identityWhich SSO standards are supported? Is MFA available and can it be mandatory? Can users end sessions?Trust center: security controls
Access controlHow are roles defined? Can access be limited by page, action, record or field? Can contact details be masked?Trust center: security controls
Audit loggingWhich staff actions and record changes are logged, with what detail, and who can review the logs?Trust center: security controls
EncryptionWhat is encrypted, with which algorithm, in transit and at rest?Trust center: procurement pack
Hosting and data locationWhich hosting provider and regions are used? What options exist for data location?Trust center: procurement pack
DPA and sub-processorsProvide the data processing agreement and the current sub-processor list.Trust center: procurement pack
Privacy toolsHow are opt-outs, do-not-contact, data export and per-record history handled?Trust center: privacy tools
Incident responseHow are incidents contained and reported, and within what timeframe are we notified?Trust center: incidents
Responsible AIWhere is AI used, on what data, and can it change records or send messages on its own?Trust center: responsible AI
Vulnerability disclosureIs there a published disclosure policy and a security.txt file?Trust center: disclosure
API securityHow are API keys scoped, rotated and restricted by network? How are inbound webhooks verified?Developers and API
AccessibilityIs an accessibility conformance report (VPAT or ACR) available?Trust center: procurement pack
ExitCan all data be exported at any time? What happens to data at termination?Our checklist answers

Security questions for us go to security@higheredcrm.ai. We answer questionnaires in full.

Running the evaluation

A sequence that keeps a committee on the same page, whichever vendors you invite.

  1. 1

    Agree the problem, the outcomes and the scorecard weights before seeing any product.

  2. 2

    Send every vendor the same scenarios and the same questions from the bank above.

  3. 3

    Invite counselors to demos; they spot friction that managers miss.

  4. 4

    Bring IT and data protection in at the start with the security checklist.

  5. 5

    Score only what each vendor showed with your scenarios, and compare the written answers side by side.

Put higheredcrm.ai through the scorecard.

Send us your scenarios and we'll run them in a 30-minute walkthrough. Our written answers to the buyer's checklist are already published.