Monday morning, no signature
The tester is ready at nine on Monday. The scope is agreed, the tools are set up, the client's VPN credentials arrived on Friday. Then the tester checks the engagement folder for the signed authorisation form. It is not there. The client's IT manager says their director signed it, but it is sitting in the director's inbox and the director is at a conference.
When the form does arrive, at lunchtime, the IP ranges on it do not match the scope in the statement of work: the client added a new range last week and emailed it separately. And one of the web applications turns out to be hosted with a provider whose terms need notice before testing. Nobody asked.
The tester spends the day on internal work. Day one of a five-day test is gone, and the client still expects five days of testing.
Your operations manager has been here before. Every firm has its own checklist of what must be in place before testing, but the checklist is a document, and whether each item is actually done is tracked in email.
Why paperwork is still missing on day one
- The authorisation form is sent with the proposal and forgotten until the week of the test.
- The person who signs is often not the person you deal with day to day.
- Scope changes after signing (new ranges, new URLs) are sent by email and not added to the signed documents.
- Third-party hosting and cloud providers each have their own rules on notice and permission, and clients do not know them.
- Emergency contacts and test windows are assumed rather than confirmed.
What your firm requires before testing, and what the law and your insurers expect, are for you and your advisers to decide. The problem we deal with is making sure your own requirements are met, every time, before the tester starts.
What a late signature costs
| Missing item | Consequence |
|---|---|
| Signed authorisation | Testing cannot start, tester day lost |
| Scope on form differs from agreed scope | Rework, or testing held until corrected |
| Hosting provider not notified | Part of the test postponed |
| No emergency contact | Nobody to call if something unexpected happens |
| Test window unclear | Testing at a time the client did not expect |
There is a further cost that does not show on a timesheet. A firm that is seen to start testing without proper authorisation, even once, has a reputational problem far bigger than a lost day.
The pre-test pack we build
- When an engagement is booked, a pre-test pack is created from your own checklist: authorisation, scope confirmation, test windows, emergency contacts, credentials and access, and third-party permissions.
- The client gets a single link with each item explained. Authorisation is signed electronically by the named signatory, through a tool such as DocuSign or Adobe Sign, and the signatory's role is recorded.
- The scope on the authorisation is generated from the agreed scope in the statement of work, so the two cannot drift apart. Any later scope change creates a new version for signature.
- Hosting and cloud providers are listed from the scoping answers, and the client is asked to confirm each provider's permission or notice has been dealt with under that provider's terms.
- Each item has a due date set back from the test start. Items still missing at that point alert the account manager, and at a final cut-off the booking is flagged not ready.
- On the morning of the test, the tester sees a single status: ready, with every document attached, or not ready, with what is missing.
Your checklist and cut-off points are settings, not code, so they can change when your procedures or your insurers' requirements change.
How the start of a test feels afterwards
The chasing happens in the fortnight before the test, automatically, not on the morning. The account manager sees at a glance which upcoming tests are at risk and why. When something is missing at the cut-off, the conversation with the client is about moving the date, with notice, rather than wasting a tester's day.
And the engagement record holds every signed version, every scope change and every permission confirmation, which is exactly what you want to have in one place if a question is ever raised about a test.
Is this happening to your testers?
- Tests start late because authorisation is not signed.
- The scope on the signed form differs from the statement of work.
- Hosting provider permissions are dealt with at the last minute.
- Emergency contacts are missing or out of date.
- Your pre-test checklist is a document, not a tracked process.