A lead-data vendor can show millions of records in a demo and still be a poor fit for your sales motion. The questions that matter are less glamorous: Where did this field come from? When was it observed? What does “verified” mean? Can we use it in our intended channel and geography? What happens when someone opts out?

Those questions determine whether purchased or researched data becomes productive pipeline, seller repair work, deliverability risk or a compliance problem.

Use this checklist with database providers, outsourced researchers, enrichment vendors, signal platforms and managed prospecting teams.

1. What is the provenance of each critical field?

Do not accept “proprietary data” as a complete answer.

Ask how the vendor obtains:

  • company identity;
  • industry;
  • employee count;
  • revenue estimates;
  • person name;
  • current role;
  • work email;
  • phone;
  • technology information;
  • intent or event signals.

The vendor may combine public sources, licensed data, customer-contributed data, inference and direct verification. You do not need every algorithm. You do need enough provenance to assess whether the data fits your risk and use case.

Require observed and inferred fields to be distinguishable where possible.

2. What does “verified” mean?

Verification is one of the most abused words in sales data.

For email, “verified” might mean:

  • syntax checked;
  • domain has mail records;
  • mailbox accepted a technical probe;
  • address observed publicly;
  • address recently used successfully;
  • human confirmed the person.

Those are not equivalent.

For phone, it might mean only that the number is valid, not that it belongs to the current person or can be used for the intended marketing purpose.

Ask the vendor to define the method, timestamp and confidence.

3. How recent is role data?

A perfect email attached to the wrong former employee is not a useful contact.

Request:

  • last-observed date;
  • source of role change;
  • update cadence;
  • treatment of conflicting sources;
  • whether departed employees are suppressed;
  • whether “current” is inferred from absence of contrary evidence.

Then test a sample against company sites and recent public evidence.

4. How strong is coverage in our actual segment?

Overall database size is irrelevant.

Give the vendor a segment that matters to you and run a benchmark:

  • 100 known target companies;
  • 20 known target roles;
  • several difficult geographies;
  • a mix of small and large firms.

Measure company coverage, current-role coverage, usable-contact coverage and false positives.

A provider can be excellent for U.S. SaaS and weak for independent Canadian contractors. Buy the coverage you need, not the headline number.

5. How are company duplicates and aliases resolved?

One business may appear under legal name, trade name, local branch and parent company.

Ask about:

  • domain matching;
  • address normalization;
  • parent-child hierarchy;
  • mergers/acquisitions;
  • franchise locations;
  • subsidiaries;
  • duplicate contacts across sources.

If account identity is unstable, enrichment can create duplicate outreach and inaccurate attribution.

6. What evidence comes with a researched account?

For manual or managed research, require a minimum evidence packet.

For example:

  • company website;
  • why it fits the ICP;
  • relevant page proving product/service fit;
  • location evidence;
  • current role source;
  • contact route source or verification;
  • research date;
  • uncertainty notes.

This makes the work auditable and lets sales reject the rule rather than blaming the researcher.

7. How are data rights and permitted uses described?

Ask what your contract actually allows:

  • CRM storage;
  • export;
  • enrichment;
  • outreach;
  • advertising audiences;
  • resale or redistribution;
  • sharing with contractors;
  • retention after subscription ends.

Do not assume that because a UI displays a field you may use it everywhere.

Legal and platform requirements also vary by geography and channel, so involve qualified counsel or privacy professionals where the risk warrants it.

8. How does the vendor support suppression and opt-out handling?

This is an operational requirement, not a footer feature.

Ask whether your suppression list can be applied before export/enrichment and whether new data can be screened against it.

FTC CAN-SPAM guidance governs U.S. commercial email and includes requirements around opt-outs and sender information. ICO guidance for UK B2B marketing notes that individuals have rights to object to direct marketing when personal data is processed.

A good sourcing workflow should make “do not contact” durable across sources. Deleting a record without maintaining suppression can cause the same person to be re-imported next week.

9. What jurisdictions does the vendor claim to support?

Be suspicious of the answer “global compliance.”

Ask country by country:

  • what data is supplied;
  • what collection/use basis the vendor relies on;
  • what documentation is available;
  • what customer obligations remain;
  • whether certain fields or channels are restricted.

The vendor’s legal position does not automatically become yours. Your role, purpose and outreach behavior matter.

10. Does the workflow rely on platform scraping or prohibited automation?

Ask explicitly.

LinkedIn states that it does not allow third-party software or browser extensions that scrape or automate activity on the site. Other platforms also have their own terms and technical controls.

If the vendor’s core promise depends on hidden automation against a platform, account restriction and continuity become procurement risks even before legal analysis.

Request a written description of collection methods that materially affect your usage.

11. What happens to data when we cancel?

Ask:

  • which exported data may be retained;
  • which fields must be deleted;
  • API access after termination;
  • suppression data retention;
  • derived CRM fields;
  • cached data;
  • audit logs.

Your sales process should not collapse because a subscription ends, but you also should not retain data contrary to contract or law.

12. How does the vendor handle correction and deletion requests?

If a person says the data is wrong or asks to exercise applicable rights, can the vendor receive and propagate that correction?

Ask for:

  • request intake;
  • identity verification;
  • response time;
  • downstream correction;
  • customer notification;
  • reappearance prevention.

This matters operationally even when the legal obligations differ across jurisdictions.

13. What are the API and export limits?

Sales operations needs the boring details:

  • credits;
  • rate limits;
  • pagination;
  • bulk export size;
  • webhook availability;
  • error handling;
  • retry rules;
  • field history;
  • unique IDs;
  • version changes.

A sourcing process built around manual CSV export can become fragile as volume grows.

14. Can we see field-level confidence and timestamp?

A single account-level “92% quality score” is difficult to act on.

It is more useful to know:

  • industry: observed 10 months ago;
  • role: observed 12 days ago;
  • email: verified 3 days ago;
  • phone: inferred from business directory;
  • expansion signal: event dated yesterday.

Then sales can decide which fields need another check.

15. How will you prevent overproduction?

This is a vendor-management question almost nobody asks.

If the service can produce 20,000 leads but your team consumes 2,000, you are paying to create decaying inventory.

Ask whether delivery can be paced, paused or prioritized dynamically. Freshness should be aligned with sales capacity.

16. How is quality measured after delivery?

Do not accept only provider-defined accuracy.

Create shared metrics:

  • ICP acceptance;
  • current-role rate;
  • usable route rate;
  • duplicate/suppression rate;
  • seller repair minutes;
  • positive/negative reply quality;
  • meetings;
  • opportunities;
  • sourced gross profit.

Segment by vendor, researcher and data cohort.

The sourcing provider should be willing to learn from downstream rejection reasons.

17. How does the vendor affect email deliverability operations?

A data vendor cannot guarantee inbox placement, but data quality affects sending risk.

Gmail’s current guidance for senders includes authentication and spam-rate expectations, and its bulk-sender guidance includes one-click unsubscribe requirements for marketing/promotional messages. Poor targeting and hygiene can increase complaints and bounces, harming a shared sending asset.

Ask whether the vendor provides:

  • recent verification timestamps;
  • catch-all handling;
  • invalid-address replacement;
  • role-account labeling;
  • source segmentation;
  • complaint/opt-out feedback fields.

Do not solve poor data by cycling domains.

18. What does a paid pilot look like?

Before an annual commitment, define a pilot with an acceptance test.

Example:

  • 500 accounts in one target segment;
  • fixed ICP rubric;
  • required evidence;
  • maximum duplicate rate;
  • current-role target;
  • usable-route target;
  • sales acceptance target;
  • two-week feedback cycle.

Do not make the pilot depend on closed revenue if the sales cycle is six months. Use leading metrics first, then keep tracking the cohort.

A case review: why a cheap list became expensive

Imagine a team buys 10,000 inexpensive records. Only half fit the ICP. One third of contacts are stale. Salespeople spend several minutes checking each record. The email team must re-verify addresses. Suppression is not synced, so old opt-outs reappear.

The vendor cost looks low while total labor and reputation cost climbs.

The correction is not necessarily to buy a premium database. It may be to buy fewer candidates, verify close to outreach time, require evidence for ambiguous fields, and cap monthly volume to seller capacity.

The transferable rule is simple: pay for usable decisions, not record count.

A good lead-sourcing vendor should make provenance, freshness, uncertainty and allowed use easier to see. If procurement cannot explain those four things after the demo, the dataset is not ready to become part of the sales system.

19. Can the vendor reconstruct one record end to end?

Pick one delivered account and ask for a record-level walkthrough.

The provider should be able to explain, at an appropriate level:

  • how the company was discovered;
  • why it matched the requested segment;
  • how the current contact role was determined;
  • when the route was verified;
  • which fields are inferred;
  • which source or system supplied each important field;
  • what quality checks occurred before delivery.

You are not asking for proprietary algorithms. You are checking whether “data quality” is an operational process or a marketing phrase.

If the vendor cannot reconstruct one record, it will be difficult to investigate systematic errors across ten thousand.

20. What happens when two sources disagree?

Conflicting data is normal. One source says 80 employees, another says 220; one lists a person as VP Sales, another as former employee.

Ask the vendor which source wins, whether conflicts are stored, and whether recent evidence has greater weight. For high-value fields, a conflict flag can be more useful than a forced answer.

A trustworthy vendor should expose uncertainty rather than converting disagreement into fake precision. Sales operations can then decide which conflicts require human review before activation.

Sources

Related Reading