Define the data-quality job before selecting a vendor
Enterprise B2B marketing data can fail in many ways: duplicate accounts, missing source values, stale firmographics, inconsistent lifecycle stages, broken consent fields, unowned enrichment, or a report that cannot be reconciled to pipeline. A vendor may be able to repair one of these problems without being qualified to govern all of them.
Evaluate the provider against a specific decision and data boundary. The buyer should know which records, fields, systems, jurisdictions, transformations and outcomes are in scope. The vendor should show how it will measure quality, preserve the original evidence, handle unknowns, protect access and return the work to an accountable internal owner.
The NIST Information Quality Standards describe quality through usefulness, objectivity and integrity, with review appropriate to purpose and risk. They are a useful vocabulary, not a certification of a marketing data vendor. Use the vocabulary to make the evaluation testable.
Freeze the scope and decision contract
Write a one-page contract before comparing proposals. Include the business decision affected, data domains, source systems, record volume, quality dimensions, permitted actions, internal owner, vendor role, timebox and budget boundary.
Name what the vendor is not allowed to do without separate approval:
- merge accounts or contacts irreversibly;
- overwrite raw source values;
- infer consent, buying authority or employment characteristics;
- upload personal data to an unapproved enrichment source;
- change production routing or lifecycle stages;
- claim a pipeline or revenue result before the cohort matures.
Define the quality dimensions in observable language:
- Completeness: required fields present or explicitly unknown.
- Validity: values follow the agreed format and domain rule.
- Consistency: the same concept means the same thing across systems.
- Timeliness: freshness matches the decision’s time window.
- Uniqueness: duplicate logic and exceptions are visible.
- Lineage: source, transformation, timestamp and owner are traceable.
Do not let a vendor substitute a platform health score for the company’s decision contract.
Request evidence, not a scorecard alone
Ask for a redacted sample of the provider’s working artifacts: data dictionary, profiling output, exception queue, match rules, correction log, lineage map, access register, handoff guide and pilot report. The buyer should see what the team actually produces, not only the labels used in a slide deck.
For each case reference, request:
- the data problem and starting definition;
- systems and fields touched;
- vendor role and internal owner;
- sample size, denominator and quality rule;
- changes made and original-value handling;
- privacy/security boundary and subcontractors;
- recheck method and remaining unknowns;
- permission to verify the evidence.
The FTC Advertising and Marketing guidance provides a general substantiation lens for material performance statements. It does not approve a data-quality vendor. Treat “cleaned,” “accurate,” “compliant” or “pipeline-ready” as claims that require scope, evidence and a reviewer.
Test the vendor on a controlled sample
Give each finalist the same synthetic or permissioned sample containing duplicates, missing values, conflicting account identifiers, stale timestamps, invalid source values and an explicit unknown state. Ask the provider to profile it without changing the source.
Observe whether the team:
- confirms the rule before calculating a pass rate;
- separates observation from correction;
- preserves raw and normalized values;
- identifies records that need a human decision;
- documents confidence, exception and rollback;
- limits access and explains retention;
- returns an artifact the internal owner can maintain.
A vendor that produces a clean-looking percentage without showing the denominator, rule version or unresolved queue has not passed the evaluation. A careful provider may identify that the sample is insufficient; that is evidence of judgment, not failure.
Evaluate architecture, privacy and access
Map every system touched: CRM, marketing automation, enrichment, analytics, advertising, warehouse, support and sales tools. Record credentials, roles, API scopes, export paths, subcontractors, retention, deletion and offboarding. Use the least sensitive sample that can answer the pilot question.
The NIST Privacy Framework is a voluntary tool for identifying and managing privacy risk through enterprise risk management. It does not decide which data the provider may process or replace legal review. Ask the vendor how purpose, access, correction, retention, incident response and data-subject requests are handled.
For security and recovery questions, the NIST Cybersecurity Framework can organize discussion of identification, protection, detection, response and recovery. It is not a vendor attestation. Require evidence of the provider’s actual controls and a clear boundary for what remains the buyer’s responsibility.
Use interview questions that expose ownership
Ask questions that require an operating answer:
- Who decides whether two accounts are the same?
- What happens when the source systems disagree?
- Where is an unknown value stored and who resolves it?
- Which repair classes can run automatically, and which must wait for a named approver?
- How is a field definition versioned and communicated?
- How will a late or duplicate event appear in the report?
- What does the vendor return at the end of the engagement?
- Who can pause a transformation or restore the previous mapping?
- How are errors, access changes and subcontractors disclosed?
- Which claimed result would the provider refuse to guarantee?
The answers should map to artifacts, owners and rechecks. “Our platform handles it” is not an answer unless the provider demonstrates the rule, output and exception path.
Compare maintenance and handoff, not only the pilot
A convincing pilot can still leave the buyer with an unmaintainable process. Ask each finalist to explain the first 30 days after handoff: who receives new source fields, who reviews a changed match rule, how a failed job is noticed, and how an internal analyst can reproduce a quality measure without the vendor’s private tooling. Request a sample runbook, release note, change ticket and escalation path.
Test a small maintenance event during the pilot. Add one new value, retire one old value, introduce a duplicate, and delay one source feed. The vendor should show the resulting exception, version change, notification, owner decision and safe reprocessing step. Price the ongoing work separately from the initial cleanup: monitoring, rule review, access recertification, data-return requests and periodic sample audits. If the buyer cannot budget or staff those controls, the proposed solution is not yet operationally complete.
Classify red flags and acceptance gates
Use defect severity separate from proposal scoring:
- Blocker: unapproved personal-data use, irreversible overwrite, missing access boundary, fabricated proof, no owner or no restoration path.
- Major: unclear match rule, hidden exceptions, no lineage, unsupported quality percentage, weak handoff or missing incident process.
- Minor: naming, formatting or documentation gap with an assigned fix.
- Observation: useful improvement with no current gate impact.
The pilot gate requires a defined sample, source preservation, quality rules, exception handling, access review, owner handoff, evidence packet and rollback test. Acceptance can be pass, pass with repair, extend research or stop and restore. A weighted score cannot cancel a blocker.
Use the Marketing Data-Quality Vendor Framework
Complete one evaluation record per provider:
- Decision and scope: what data-quality decision is being supported?
- Domains and systems: records, fields, sources, destinations and jurisdictions.
- Quality contract: dimensions, rules, denominator, unknowns and maturity.
- Evidence request: artifacts, sample, references, permissions and limits.
- Pilot test: synthetic/permissioned input, expected output and controls.
- Interview record: answer, evidence, owner and open question.
- Red flags: blocker, major, minor or observation.
- Ownership: buyer, vendor, shared, successor and escalation route.
- Release gate: not ready, pilot-ready, accepted, repaired or stopped.
- Offboarding: access removal, data return/deletion, asset transfer and report version.
- Rollback: prior mapping, rule, feed and communication owner.
The framework is complete when the provider’s work can be tested on a bounded sample, the internal team retains the decision rights, and a correction can be made without losing source evidence. Keep indexable: false until editorial, overlap, privacy, security, claims and canonical reviews are complete.
How did this article land?
Choose one reaction. You can change it anytime.