The accessibility procurement checklist for EdTech buyers
An accessibility procurement checklist for edtech should test four things: whether the product is genuinely accessible and tested by people, whether the vendor can document it with an ACR (Accessibility Conformance Report), how they handle your institution's data, and whether they can evidence impact and support after signing. The twelve categories below turn that into vendor questions, with good answers and red flags for each.
Compliance and testing
Ideal practices
-
Has WCAG compliant features and a remediation plan
-
Manual testing takes place before new feature releases
-
This topic is approached with transparency and honesty
Poor practices
-
Relies on automated testing
-
Does not address how they test new features during product development to look for accessibility bugs
ACR (VPAT) documentation
Ideal practices
-
Documentation is readily available
-
Evaluation should include manual testing
-
Evaluation completed by a trusted third-party
Poor practices
-
ACR (VPAT) is not provided or difficult to access
-
Evaluation only uses automated testing
-
Evaluation not performed by a third-party expert
Accessibility overlays/widgets
Ideal practices
-
Software does not use an accessibility overlay or widget, and focuses on creating an accessible codebase
Poor practices
-
Utilizes an accessibility overlay to mask inaccessible code
Data ownership
Ideal practices
-
Ownership and intellectual property rights never transfer to the vendor
Poor practices
-
Data ownership is not addressed in terms and conditions
-
Lack of clarity on this issue
Privacy and security
Ideal practices
-
Evidence that policies align with global standards
-
Security validated by a SOC 2 Type II report, dated within the past 12 months
-
Privacy and security commitments included in T&Cs
Poor practices
-
Poor or lacking privacy notice
-
Not SOC 2 compliant or the report is out of date
Access controls
Ideal practices
-
Authorized persons only, based on business need
-
Access granted for a limited time on a case by case basis
-
Full access logs available
Poor practices
-
Lack of a clear position
-
No clear processes
-
No access logs
Third-party transparency
Ideal practices
-
Readily-accessible list of third-parties, their processing location, and reason for processing the data
Poor practices
-
Unable to produce a list of third-parties
-
Unclear about the reason for working with each third-party
Third-party vetting
Ideal practices
-
Clarity on security of third-parties
-
Data Processing Agreement (DPA) in place
Poor practices
-
Not able to provide details on their third parties and the controls in place, and lacks clarity around this issue
AI model training
Ideal practices
-
Clear statement that third-parties cannot train AI models using user data
Poor practices
-
Unsure, ambiguous or acknowledges that third-parties can train AI models with their user’s data
Evidence and research
Ideal practices
-
Empirical research and evidence to demonstrate impact
-
Case studies from both student and admin users
Poor practices
-
Unable to evidence impact at scale or over time
-
Sweeping statements about impact without facts
Industry expertise
Ideal practices
-
Focus on using learning research and best practices to drive learner outcomes. Features promote active learning
-
Expertise and experience working with different departments within the higher education system
Poor practices
-
May be vague, focus on general productivity, or lean heavily on automated processes rather than active learning
-
Lacks knowledge or awareness of the different departments involved in the higher education system
Customer experience and support
Ideal practices
-
Clarity on post-purchase support, regular touchpoints with a Customer Success Manager, and good response times
Poor practices
-
Unsure or unclear on what support is offered to customers and their students after licenses have been purchased
Genio supports learners at over 1,000 institutions globally