Every business I work with in Alberta has the same shelf of software nobody quite remembers signing up for. A project tool from a hire who left eighteen months ago. Two overlapping e-signature platforms because nobody checked before buying the second one. A "starter" plan that quietly became the "growth" plan at three times the price, and the renewal email went to an inbox nobody reads.
None of this is negligence. It's what happens when contract review isn't anyone's actual job. The fix isn't more software — it's a short list of questions, asked before you sign or renew, not after the invoice arrives.
This is the checklist I use in technology reviews. Steal it.
Before You Sign Anything New
1. What does this replace, exactly? If the honest answer is "nothing, it's additive," get a second opinion before buying it. Most tools sold as new capability are actually replacing three spreadsheets and a Slack channel — worth knowing which, so you're not paying twice.
2. Who else in the business already touches this problem? The most common SaaS-sprawl story isn't a bad purchase — it's two departments buying the same category of tool six months apart because neither knew the other was shopping.
3. Where does this data actually live? Ask for the specific country or region, not "the cloud." For anything touching customer or employee personal information, this isn't a technicality — Alberta's Personal Information Protection Act and the federal PIPEDA both hold your business accountable for what a vendor does with that data, regardless of where the vendor is incorporated.
4. What happens to our data if we leave? Get this in writing before you sign, not when you're trying to cancel. Ask specifically: export format, how long they retain a copy after cancellation, and whether export is free or a paid "offboarding" service.
5. What's the real total cost at the seat count we'll actually reach? Per-seat pricing that looks reasonable at 5 users can double at 25. Ask for the price at your 18-month headcount projection, not today's.
6. Does the free trial's admin actually match the paid tier? Security controls, SSO, and audit logs are routinely gated to the top pricing tier. Confirm the tier you're buying includes what you evaluated in the trial.
Before You Renew Anything Existing
7. Is anyone still using this? Pull actual login or usage data, not a guess. Zylo's 2026 SaaS Management Index — which tracks software portfolios across hundreds of companies — found license utilization sitting around 46% even after a year of improvement industry-wide, meaning close to half of paid seats go untouched in a typical month. Nobody's portfolio is immune to this by default.
8. When is the cancellation notice window, and is it in the calendar? Most contracts require 30, 60, or 90 days' written notice before the renewal date to avoid auto-renewing into another full term. Put the actual deadline — not the renewal date — on someone's calendar.
9. Has the price changed since we signed, and why? Annual escalators buried in contract fine print (5–15% is common) compound quietly. If nobody's checked in two renewal cycles, ask the vendor to itemize what changed.
10. Are we still on the right tier? Usage grows in one direction (more seats, more storage) and shrinks in another (fewer active features) at the same time. Both deserve a look at renewal, not just the first one.
11. What would it cost, in hours and dollars, to actually migrate off this? If the honest answer is "too much to ever leave," that's not a compliment to the vendor — it's a lock-in risk worth pricing into your renewal negotiation.
12. Does this vendor appear in our last security incident or outage report? Reliability history is a legitimate renewal factor, not just price and features.
Questions About the Contract Itself
13. Can the vendor change terms or pricing unilaterally, with less notice than we owe them? A lopsided termination clause — them: 30 days, you: locked for a year — is the single most common one-sided term I find. It's usually negotiable if you ask before signing.
14. Is there a price-lock or renewal-cap clause available? Multi-year commitments often unlock a capped annual increase (e.g., "no more than 3% per year"). Worth asking for even on a one-year term.
15. Who signs on our side, and do they have the authority to? Contracts signed by whoever was in the room at the sales call, rather than someone accountable for the budget, are how six-figure commitments happen without anyone above them knowing.
16. Is there a Data Processing Addendum (DPA), and have we actually read it? If the vendor touches any personal information, the DPA — not the marketing page — is where your actual obligations and their actual obligations are defined.
17. What's the support SLA, in writing, not in the sales deck? "Enterprise-grade support" means nothing without a response-time number attached to a severity level.
18. If this vendor disappeared tomorrow, what's the plan? Not every tool needs a contingency plan. The ones holding your customer data, your billing, or your production infrastructure do.
The One-Sentence Version
If nobody specific owns the renewal calendar, the contract owns you. That's the whole problem this checklist solves.
Why This Is Usually a 90-Minute Problem, Not a Project
Most businesses I meet assume a real vendor review means weeks of work. In practice, running this list against your top ten contracts by spend — the ones actually worth the time — is usually an afternoon. The value isn't in reviewing everything; it's in reviewing the handful of contracts nobody's looked at since the day they were signed.
If that afternoon doesn't exist on anyone's calendar, that's the actual finding: not a bad vendor, a missing owner. That's exactly the gap a technology review is built to close — an outside, non-commissioned look at what you're actually paying for, with a straight answer on what to renegotiate, renew, or cut.
Book a Free Technology Review Call →
Frequently Asked Questions
How often should a small business review its software vendor contracts?
Once a year at minimum, and always 60–90 days before an auto-renewal date — not the week it lands. Renewal clauses typically require notice inside a specific window, and missing it locks you into another full term even if the tool is a bad fit.
What does "data residency" mean and why does it matter for a Canadian business?
It means which country the vendor's servers physically live in. A US-hosted vendor can be compelled to produce your data under US law regardless of where your business operates. For anything touching customer, employee, or health information, ask directly where it's stored and whether a Canadian or contractual data-processing addendum is available.
Can I negotiate SaaS contract terms as a small business, or is pricing fixed?
Almost everything below the enterprise tier is negotiable if you ask before renewal, not after. Multi-year discounts, price-lock clauses, and reduced auto-escalation are the easiest wins — vendors would rather concede 10% than lose a renewal to a competitor.
What's the biggest red flag in a vendor contract?
A one-sided termination clause — the vendor can cancel or change terms with 30 days' notice, but you're locked into an annual term with no exit. Read the termination section before the pricing section; pricing is negotiable, termination terms rarely are once signed.
Who should own vendor contract review if we don't have an IT department?
Someone specific, even if it's a part-time role. The most common failure isn't a bad decision — it's no decision, because the contract auto-renews before anyone with authority looks at it. A fractional CTO or technology reviewer can own this calendar for you if nobody internally has the bandwidth.
About Code to Cloud
We're based in Alberta and work with startups, small businesses, and growing companies across Western Canada — reviewing what you're already paying for before we ever pitch you something new. Disclaimer: This article provides general information only and does not constitute legal, financial, or professional advice. Every business situation is different. Consult with qualified professionals for advice specific to your circumstances. Code to Cloud is not liable for any actions taken based on this content.



