IT and security checklist for choosing a fleet supplier
The questions your IT and security team will ask of any fleet software vendor, aligned with Australian government expectations, in one checklist.
How to use it: Send it to every shortlisted vendor and insist on documents, not adjectives, in response. The wording is aligned with what Australian government buyers already require of telematics suppliers, so answers slot straight into a procurement evaluation.
Data ownership and residency
- Who owns the fleet data under the contract? (The answer must be: you do.)
- Where is data hosted, processed and backed up? Name the country and region.
- What hosting certifications does the infrastructure provider hold (for example, Australian Government Hosting Certification Framework status)?
- Can all data be exported in open formats, at any time, at no extra cost?
- What happens to data at contract end, and how is deletion evidenced?
- Can data be remotely deleted from lost, stolen or decommissioned devices?
Identity and access
- Does the platform support single sign-on with our identity provider?
- Is multi-factor authentication enforced for all access paths?
- Can our directory drive provisioning and deprovisioning automatically (for example SCIM), so leavers lose access the day they leave?
- Is access role-based and scoped (by depot, function or module), defaulting to least privilege?
- Is there a complete audit trail of who did what and when, including the vendor's own support access?
Security posture
- Which recognised frameworks are the vendor's controls aligned with (ISO 27001, ASD Essential Eight), and what evidence exists: certificates, assessment reports, or a documented control mapping?
- Is data encrypted in transit and at rest, including backups?
- When was the last independent penetration test, and can the summary be shared?
- Is there a published or contractual vulnerability disclosure process?
- For tracking hardware: are default credentials unique per device, are firmware updates signed and supported for a stated period?
Incidents and breach notification
- What breach notification window does the vendor commit to in writing, in hours? (Government contracts commonly require 24 to 72 hours; your own Notifiable Data Breaches obligations depend on being told fast.)
- Who is the named security contact?
- Will the vendor assist with your regulator notifications if their systems are involved?
- Is there a tested incident response and disaster recovery plan, with recovery objectives stated?
Privacy and surveillance compliance
- How does the product support workplace surveillance notice requirements (written notice periods, in-vehicle notices)?
- Is driver location collection proportionate (for example, app tracking limited to active work trips)?
- Does the vendor act as anything other than a processor of your data? Any secondary use must be stated and justified.
Continuity and support
- Where is support located, and what are the response targets by severity?
- What uptime is committed, and how is it reported?
- What is the vendor's ownership and financial standing? Australian-owned, or subject to overseas jurisdictions?
A vendor that answers all of this in documents inside two weeks is telling you something. So is one that cannot.
Last updated 10 July 2026. General information, not tax or legal advice.