
A CRM decision is easier when you describe the work before a supplier shows you its features. Follow an enquiry through sales, delivery and service; define what each role needs and how you will test it.
The quick answer
Write five real customer journeys, make the requirements testable and give each one an owner. Set pass-or-fail gates for privacy, access and data export. Then score shortlisted systems against the same demo, evidence and three-year cost.
Start with the outcome, not a product list
Ask people who receive enquiries, sell, deliver and invoice to walk through a recent case. Note where information arrived, who decided, which system changed and what happened when something went wrong.
For a small consultancy, one outcome might be: Every valid enquiry has one owner, a recorded source and a dated next action within one working day. Adapt the measure to your business.
Write each requirement so a supplier can demonstrate it: As a [role], when [event], I need [action and information], so that [outcome]. “Easy reporting” is vague; showing open opportunities by owner and expected decision month without a spreadsheet is testable.
The five journeys to map
- Enquiry to owner: Capture source and preferences, check for an existing contact, assign responsibility and set the next action.
- Opportunity to decision: Record qualification, proposal, approval, decision date and outcome.
- Won deal to delivery: Hand over scope, dates, documents and an accountable owner.
- Delivery to finance: Pass approved billing details without unnecessary retyping or exposure.
- Service to improvement: Route and resolve a request; report what management needs to see.
If service sits outside the CRM, define the boundary and handover.
A pre-purchase CRM requirements checklist
Mark each area must have, should have, later or not needed. Name a tester for each must-have.
| Area | Questions to answer before a demo |
|---|---|
| People and roles | Who creates, edits, approves and reads each record? What can a temporary worker or external partner see? |
| Enquiry capture | Which forms, inboxes and phone processes create leads? How will duplicates and incomplete records be handled? |
| Pipeline | What are the real stages and exit conditions? Which approvals need a named decision? |
| Client handover | Which fields and documents must reach delivery or finance? What happens when they are missing? |
| Communication | What email, meeting and call history is needed? How are preferences, objections and opt-outs recorded? |
| Reporting | Which five management questions must be answered? What fields make those answers trustworthy? |
| Integration | Which systems exchange information, in which direction and with which system as the source of truth? |
| Adoption | Can ordinary users complete a typical task on their usual device? What training and administrator capacity exist? |
| Ownership and exit | Who owns configuration, changes and support? Can usable records and relationships be exported if you leave? |
This is for selection. After choosing a platform, use Futuro's Zoho CRM implementation checklist or CRM migration guide for those separate tasks.
Make privacy and security pass-or-fail gates
A CRM holds information about people, even when customers are companies. The ICO's data protection by design guidance says privacy should be considered from design through the system's life. It links defaults to using and exposing only the personal information needed for each purpose.
Ask suppliers to show:
- role-based access to a sensitive note, an ordinary account and a manager's report;
- multi-factor authentication and removal of a departing user's access;
- the audit trail for a changed owner, stage or key field;
- how records, attachments and relationships can be exported in a usable format;
- where data and backups are held, who processes them and how they are returned or deleted; and
- how retention, objections and communication preferences can be applied to records and exports.
The NCSC says: “Large and small organisations should determine if a cloud provider is 'secure enough' for their requirements.” Its provider guidance and SaaS guidance frame the evidence to request for authentication, access, monitoring and recovery.
A gate is binary. If essential access or export cannot be demonstrated, a low subscription price cannot compensate. Seek specialist advice for unusually sensitive uses.
Compare vendors with a weighted decision worksheet
Agree weights before the demos. This example suits a service business handling enquiries, projects and customer information; adjust it to your priorities.
| Requirement group | Example weight | Score, 0–5 | Evidence and unresolved questions |
|---|---|---|---|
| Customer journey and pipeline fit | 20 | ||
| Records and reporting | 15 | ||
| Everyday usability and adoption | 15 | ||
| Integrations and handovers | 15 | ||
| Privacy, access and security | 15 | ||
| Administrator control and support | 10 | ||
| Three-year cost and exit | 10 | ||
| Total | 100 |
Score 0 for not demonstrated, 1 for a major gap, 3 for workable with compromise and 5 for convincing evidence. Calculate weight × score ÷ 5 for each row and add the results out of 100. Missing evidence scores zero.
Keep pass/fail gates for essentials. A system scoring 82 might fail an access requirement while a simpler option scoring 74 passes. The number makes trade-offs visible; it does not decide for you.
Give every supplier the same demonstration
Send the same script and fictional or sanitised records to each supplier. Ask a user, manager and administrator to judge the relevant parts.
For example: an enquiry arrives for a service already discussed with the same company. Can the user find the existing contact, avoid a duplicate, assign an owner, record the source and send a suitable acknowledgement? The prospect then requests a proposal with a non-standard term. Can the manager see the approval, and can delivery find the agreed version after the deal is won? Finally, can finance and management retrieve the information they need without seeing unrelated confidential notes?
Show awkward cases too: a missing email, unavailable owner or failed integration. Record what works today, what needs another licence and what needs custom development.
Price the decision across its life
Request a written three-year estimate with assumptions. Separate user licences, add-ons, implementation, data preparation, integration charges, training, administrator effort, support, future changes and exit work. Confirm whether prices include VAT and whether contract terms change with user numbers. If the supplier quotes an introductory rate, record what happens afterwards.
Include internal time. Someone must resolve data ownership, attend workshops, test real scenarios and maintain the system. The Zoho CRM implementation cost guide explains why software and implementation costs are different, even when the initial user count is small.
Before agreeing a contract, ask for a sample export and the supplier's exit process. Who can extract the data, how are relationships represented and what happens to integrations and backups? A low entry price is less attractive if future change is difficult to control.
CRM requirements checklist FAQs
How many requirements do we need?
Enough to test your key journeys and deal-breakers. Start with a short list of outcomes, roles, must-have controls and integrations. Add detail where a supplier's answer could change the decision. Avoid a hundred-line feature list that nobody can validate.
Should we choose a CRM before mapping our process?
Map at least the principal enquiry, sales and handover journeys first. You do not need to design every future workflow, but you should know what the first release must support and what information each team needs.
Should our current CRM be in the shortlist?
Yes, if it is viable. Score a realistic improvement of the current system against the same requirements as a replacement. Configuration, training or a cleaner process may resolve the problem at lower disruption; the demonstration should show whether that is true.
Is the cheapest CRM the best choice for a small business?
Sometimes, but compare the full cost of licences, add-ons, implementation, support and staff effort. A cheap licence can be expensive if it requires repeated manual work or a fragile integration.
Do we need a UK-hosted CRM?
Location is one question within a wider assessment of data flows, supplier terms, access, transfers, security and the types of personal information you process. Document the requirement and obtain appropriate advice rather than assuming a UK address alone proves suitability.