How to use this checklist
Most awareness platform RFPs are built from feature lists, and feature lists are where vendors all look identical. Every vendor will answer yes to does your platform send phishing simulations and do you offer training modules. Those questions cost you evaluation time without producing a decision.
The questions below are chosen because they discriminate. Each one has answers that meaningfully differ between vendors, and several will remove candidates outright if your organisation is regulated in Indonesia. Use them as requirements to score, not as a questionnaire to file.
This is written vendor-neutral and Claro is one of the products it would be used to evaluate. Where we have a position we say so explicitly rather than hiding it inside a requirement. You should assume any vendor-authored checklist is shaped by what that vendor does well, including this one, and cross-check against a second source.
Data residency and deployment
This is the first section for a reason: for many Indonesian banks and government bodies it is disqualifying, and asking it late wastes an entire evaluation cycle. Ask where employee data is stored and processed, naming the country and region, not the vendor's headquarters. Ask whether an on-premise or in-country deployment exists today with named reference customers, rather than being on a roadmap.
Then ask what leaves the environment. Some platforms deploy locally but still send telemetry, licence checks or AI inference requests offshore. Ask specifically which outbound connections are required for the product to function, and whether it operates in a fully air-gapped configuration.
Finally ask about the data itself: what personal data of employees is collected, how long it is retained, whether retention is configurable, and how deletion works. Under UU PDP you are the data controller for this processing, so the vendor's answer becomes your compliance position.
Bahasa Indonesia as a first-class language
Ask to see three actual phishing templates and one full training module in Bahasa Indonesia, rendered as an employee would see them, before signing anything. Machine-translated content is immediately obvious to Indonesian staff and undermines the credibility of the whole programme.
Then probe whether localisation goes beyond language. Do the templates reference Indonesian institutions, payment rails and scam patterns that staff would actually encounter, such as QRIS, e-wallets, BPJS, DJP and the WhatsApp APK campaigns? Or are they English scenarios with the words swapped?
Ask who authored the Indonesian content and whether new content ships in both languages simultaneously or lags. A platform where Indonesian content arrives two quarters behind English is an English platform with a translation pipeline.
Compliance evidence, not compliance claims
Ask which frameworks the platform reports against by name. Many vendors cover ISO 27001 and SOC 2 while offering nothing for OJK, BSSN, UU PDP, PP 71/2019, SPBE or Bank Indonesia expectations. If your supervisor is OJK, ISO-only reporting means you build the mapping yourself.
Ask for a sample export, not a screenshot of a dashboard. The test is whether you can hand the output to an internal auditor or a supervisor without reformatting it. Ask specifically whether evidence is per-user and time-series, because completion percentages alone are weak evidence that behaviour changed.
Ask what happens at audit time if the vendor relationship has ended. Can you export historical evidence in an open format and retain it, or does your audit trail live inside a subscription you must keep paying for?
Measurement that reflects behaviour
Ask how the platform defines and calculates phish-prone rate, and whether the definition is documented. Vendors differ on whether an open counts, whether repeat offenders are weighted, and whether reported emails offset clicks. Two platforms can report very different numbers for identical behaviour.
Ask whether risk is scored per user and how the score is derived, whether it decays over time, and whether it accounts for role. A finance employee with payment authority carries different exposure from a warehouse employee, and a single organisation-wide percentage hides that.
Ask what happens automatically when someone fails. Assignment of targeted remediation without an administrator intervening is the difference between a measurement tool and a behaviour-change programme.
Channels beyond email
In Indonesia, WhatsApp is a primary business channel and a primary attack channel, so email-only simulation leaves the most active route unmeasured. Ask which channels are supported natively: email, WhatsApp, SMS, voice, and QR codes.
Ask how non-email channels are delivered and priced, since some vendors resell a third-party gateway and pass through per-message costs that are easy to miss in a first-year quote. Ask who holds the telecom relationship and whose credentials are used.
Ask for the consent and disclosure model on voice and messaging simulations. Calling employees carries legal and cultural sensitivities, and a vendor without a considered position on disclosure has not deployed it seriously in this market.
Integration, operations and commercials
On integration, ask about SSO via SAML, user provisioning via SCIM or directory sync, whether provisioning is bidirectional, SIEM output format, and whether a documented public API exists with rate limits published. Ask whether phishing reporting integrates with Outlook and Gmail as a button employees actually have.
On operations, ask who runs campaigns day to day, how long a first campaign takes from a standing start, and what support hours apply in Indonesian time. A platform supported only in US business hours is a platform your team supports.
On commercials, ask what the licence covers per user, what is excluded, how mid-term seat changes are handled, and what the second and third year cost. Ask what happens to your data and evidence at termination. Get the multi-channel message costs stated separately rather than bundled.
Scoring and shortlisting
Score the disqualifiers first. Data residency, genuine Bahasa Indonesia content and named-framework reporting will typically reduce a long list faster than any feature comparison, and doing them first saves weeks.
For the remainder, weight measurement quality and automated remediation above feature count. The platforms that change behaviour are the ones that act on a failure without an administrator remembering to, and that difference does not show up in a feature matrix.
Then require a live pilot on your own staff, in Bahasa Indonesia, with the evidence export produced at the end. Every vendor demonstrates well on their own data. Very few produce an audit-ready export from a two-week pilot on yours, and that is the test worth running.
Key takeaways
- Ask data residency first; for regulated Indonesian organisations it disqualifies candidates faster than any feature question.
- Require sight of real Bahasa Indonesia templates and a full module before signing, since machine translation is obvious to staff and damages credibility.
- Ask for a sample evidence export rather than a dashboard screenshot, and check it names OJK, BSSN and UU PDP, not only ISO 27001 and SOC 2.
- Make the vendor state how phish-prone rate is calculated; differing definitions make cross-vendor numbers non-comparable.
- Email-only simulation leaves WhatsApp unmeasured, which in Indonesia is the most active attack channel.
- Finish with a paid pilot on your own staff that must produce an audit-ready export, because that is what separates demos from delivery.