Raffles Consulting Services
PSG IT solutions need a business, data and security review before a company accepts the vendor quote and submits its grant application.
Enterprise Singapore may pre-approve PSG IT solutions for grant support, but that does not mean every package is secure or suitable for every company. Before accepting a quotation, the buyer should check the business process, data handled, user access, hosting, incident support and exit terms. The grant decision and the technology decision are related, but they are not the same decision.
This review is especially important for payroll, customer management, accounting, e-commerce and document systems. Weak access controls, difficult data extraction or unclear incident terms can outweigh a low implementation cost.
Match the quotation to the approved package
The current Productivity Solutions Grant page requires an IT quotation from a pre-approved vendor. The items and costs should match Annex 3 for the selected package. The grant normally supports only the actual purchase, lease or subscription in that package. The live terms normally exclude delivery, installation and other administrative charges.
Compare the vendor’s legal name, solution name, version, appointment period, user quantity, subscription period and cost items with the current listing. If the vendor proposes extra modules or services, show them separately and ask whether they are outside the grant. A quotation should not blur a supportable package with optional consulting, migration or hardware.
Define the business and data before viewing a demo
Write down the process the system must improve, the people who will use it and the evidence that will show a productivity gain. Then list the information that will enter the system. Include customer records, employee details, financial data, identity documents, payment information, contracts and confidential business material.
For each data type, identify who may create, view, change, download and delete it. Record whether the vendor will host it in Singapore or overseas and whether subcontractors can access it. This gives the vendor a clear question to answer and prevents a generic demonstration from replacing the company’s own risk review.
| Check | Evidence to request | Decision to make |
|---|---|---|
| Approved scope | Current Annex 3 and itemised quotation | Which items does the grant support, and which are extra? |
| Data location | Hosting regions and subprocessors | Where will the vendor store company and personal data? |
| User access | Role matrix, multi-factor authentication and audit log | Can managers align and review access against job duties? |
| Security service | Patching, backup, monitoring and incident terms | Who acts, how quickly and with what notice? |
| Recovery | Restore test, recovery objectives and support route | How long can the business operate without the system? |
| Exit | Export format, deletion confirmation and transition fees | Can the company retrieve usable data and leave? |
Test the shared security responsibilities
The Cyber Security Agency of Singapore aligns pre-approved cybersecurity solutions with measures in the Cyber Essentials mark. Its current materials cover classical cybersecurity, cloud, artificial intelligence and operational technology risks. Buyers should still ask which controls belong to the vendor and which remain with the customer.
For example, a vendor may secure the cloud infrastructure while the customer remains responsible for user accounts, permissions, exported files and compromised staff devices. Ask about multi-factor authentication, password rules, administrator access, encryption, audit logs, vulnerability handling, security patches, backups and restoration tests. Record who configures each control before launch.
If the product connects to email, banking, payroll or another system, map the connection and the credentials it uses. Remove unnecessary broad access. A test account should not remain a permanent administrator, and a departing employee’s access should not depend on the vendor noticing the resignation.
Put personal-data duties into the contract
The PDPC guide to managing data intermediaries covers governance, risk assessment, service management and exit management when another organisation processes personal data. The buyer remains responsible for understanding the arrangement and cannot treat a grant approval as a data-protection approval.
The written agreement should define the processing purpose, permitted data, security measures, approved subprocessors, overseas transfers, retention, return or deletion, incident notification, audit information and assistance with access or correction requests. Check that the sales quotation, service terms and privacy documents do not contradict each other.
If the vendor uses customer data to train or improve an artificial-intelligence feature, ask which data the feature uses, whether administrators can disable it and who reviews the output. Do not assume that a feature described as automated or intelligent is necessary for the approved productivity outcome.
Run a short acceptance test before full deployment
Create sample users for an ordinary employee, manager and administrator. Confirm that each sees only the records required for the role. Test a password reset, user removal, data export, backup restoration and an attempted unauthorised action. Keep screenshots or system logs with the acceptance record.
Suppose a 20-person company adopts a cloud payroll package. The finance manager should not rely only on the vendor’s demonstration. The company can load sample data, check that supervisors cannot see unrelated salaries, confirm multi-factor authentication for administrators, test the employee export and document the vendor’s incident contact. The company should resolve any defect before migrating live personal data.
Keep the PSG timing clean
The PSG questions and answers say the grant does not support a retrospective application. Do not make a payment or deposit before submitting the application. Confirm the approved solution and quotation first, complete the internal security review, then submit through the Business Grants Portal before committing.
After approval, retain the Letter of Offer, quotation, contract, invoice, payment evidence, deployment record, licence details and usage evidence. The applicant entity must use the system and must not shift it to a related party. Our PSG claim-document guide explains the later claim file.
The Singapore business support guide is the pillar cornerstone, and the Enterprise Support and Grants hub covers other support routes. For a PSG technology purchase, the useful approval record states both why the package qualifies and which controls let the company operate it safely.