Practice Management System (PMS)
Integrate and automate various administrative, operational, client-related tasks, including billing, accounting, invoicing, time tracking and client contacts.
Instructions
This page helps you prepare "Solution Requirements" section in Vendor Management Portal and you will see the exact questions and flow.
🔴 Mandatory questions: Must answer "Yes" to continue
🟡 Preferred questions: Can answer either way and continue
Follow the question flow as indicated
Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility
Main Question: Does your solution allow for cloud-based, mobile-based, and/or web-based usage?
🔴 Answer: ○ Yes [Next: Q2] ○ No [⚠️ Cannot Proceed]
Q2 🔴 Mandatory - Customer Relationship Management
Main Question: Does your solution come with Customer Relationship Management functions to help the firm manage its interactions with current and potential customers, such as customer contact, opportunity management, and sales and marketing activities?
🔴 Answer: ○ Yes [Next: Q3] ○ No [⚠️ Cannot Proceed]
Q3 🔴 Mandatory - Financial Management and Accounting Functions
Main Question: Does your solution come with Financial Management and Accounting functions to help the firm manage its budget, billing and invoicing?
Additional Requirements: The solution automatically generate billing and invoices based on billable hours, and manage payments, overdue invoices and receivables.
🔴 Answer: ○ Yes [Next: Q4] ○ No [⚠️ Cannot Proceed]
Q4 🔴 Mandatory - ASR+ (Accounting)
Main Question: Is your accounting solution listed on IRAS Accounting Software Register Plus (ASR+)?
Requirements:
Your solution is required to be registered with IRAS under the ASR+ framework.
For more information, please refer to IRAS ASR+ website for more details
Submission Requirements: Please provide screenshots of IRAS listing and name the file as "IRAS ASR Supporting.pdf". Submit this document in your submission.
🔴 Answer: ○ Yes [Next: Q5] ○ No [⚠️ Cannot Proceed]
Date of Issue Required: [Date Field] Upload Supporting Document Required: [File Upload] Text Elaboration Required: [Text Box for Description/Details]
Q5 🔴 Mandatory - Case Management and Task Tracking
Main Question: Does your solution come with Project Management functions to help the firm estimate project costs, monitor work in progress, and monitor staff performance?
🔴 Answer: ○ Yes [Next: Q6] ○ No [⚠️ Cannot Proceed]
Q6 🟡 Preferred - Calendar Management
Main Question: Does your solution include calendar functions with scheduling, reminders, and notifications pertaining to case management?
🟡 Answer: ○ Yes [Next: Q7] ○ No [Next: Q7]
Q7 🔴 Mandatory - Conflict of Interest and Compliance Checking
Main Question: Does your solution check for conflicts of interest and compliance with local statutory requirements?
🔴 Answer: ○ Yes [Next: Q8] ○ No [⚠️ Cannot Proceed]
Q8 🟡 Preferred - Time and Expenses Tracking
Main Question: Does your solution track the time and expenses spent to enable itemised billing for each case?
🟡 Answer: ○ Yes [Next: Q9] ○ No [Next: Q9]
Q9 🔴 Mandatory - Dashboards and Reports (PMS)
Main Question: Does your solution provide customised dashboards and reporting capabilities to track the firm's operations, staff projects and client status?
Technical Requirements: Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.
Dashboard Requirements: The dashboard must include at least one of the following interactive features:
Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard
🔴 Answer: ○ Yes [Next: Q10] ○ No [⚠️ Cannot Proceed]
Q10 🔴 Mandatory - Module Integration
Main Question: Are the modules above tightly integrated such that information can be pulled from all modules to the dashboard?
🔴 Answer: ○ Yes [Next: Q11] ○ No [⚠️ Cannot Proceed]
Q11 🟡 Preferred - System Integration
Main Question: Does your solution support integration with systems and software such as email, Know Your Customer (KYC) / Anti-Money Laundering (AML) functions, audit tools, document management systems, accounting software, and HR software?
🟡 Answer: ○ Yes [Next: Q12] ○ No [Next: Q12]
--
Q12 🔴 Mandatory Follow-up - System Integration - Elaboration
This question appears only if you answered "Yes" to Q11
Main Question: List the systems and software that your solution can be integrated with.
🔴 Answer: ○ Yes [Next: Q13] ○ No [⚠️ Cannot Proceed]
Text Elaboration Required: [Text Box for Description/Details]
Q13 🟡 Preferred - AI Features
Main Question: Does your solution incorporate AI in your core features and functions?
🟡 Answer: ○ Yes [Next: Q14] ○ No [Next: Q15]
--
Q14 🔴 Mandatory Follow-up - AI Features - Elaboration
This question appears only if you answered "Yes" to Q13
Main Question: Describe your AI feature and its benefits. Examples are:
a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify
🔴 Answer: ○ Yes [Next: Q15] ○ No [⚠️ Cannot Proceed]
Text Elaboration Required: [Text Box for Description/Details]
Q15 🔴 Mandatory - Business Data Extraction
Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?
🔴 Answer: ○ Yes [Next: Q16] ○ No [⚠️ Cannot Proceed]
Q16 🔴 Mandatory - Personal Data Protection
Main Question: Can your solution demonstrate compliance with the following Personal Data Protection requirements?
Requirements: Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).
Compliance Requirement: To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at https://go.gov.sg/pdp.
🔴 Answer: ○ Yes [Next: Q17] ○ No [⚠️ Cannot Proceed]
Q17 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)
Main Question: Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.
Submission Requirements: Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.
Additional Information: If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.
Qualified Third-Party Definition: Qualified third-party refers to: CREST-certified companies [ https://www.crest-approved.org/members/] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.
🔴 Answer: ○ Yes [Next: Q18] ○ No [⚠️ Cannot Proceed]
Date of Issue Required: [Date Field] Upload Supporting Document Required: [File Upload] Text Elaboration Required: [Text Box for Description/Details]
Q18 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)
Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?
🟡 Answer: ○ Yes [Next: Q19] ○ No [Next: Q21]
Q19 🟡 Preferred - CEM for Product Principal
Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?
Requirements: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.
Additional Information: For more information on Cyber Essentials mark, please refer to https://www.csa.gov.sg/cyber-essentials/
🟡 Answer: ○ Yes [Next: Q20] ○ No [Assessment Finished]
--
Q20 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration
This question appears only if you answered "Yes" to Q19
Main Question: Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification
Submission Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.
🔴 Answer: ○ Yes [Assessment Finished] ○ No [⚠️ Cannot Proceed]
Date of Issue Required: [Date Field] Upload Supporting Document Required: [File Upload] Text Elaboration Required: [Text Box for Description/Details]
Q21 🟡 Preferred - CEM for Resellers
Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?
Requirements: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.
Additional Information: For more information on Cyber Essentials mark, please refer to https://www.csa.gov.sg/cyber-essentials/
🟡 Answer: ○ Yes [Next: Q22] ○ No [Assessment Finished]
--
Q22 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration
This question appears only if you answered "Yes" to Q21
Main Question: Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification
Submission Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.
🔴 Answer: ○ Yes [Assessment Finished] ○ No [⚠️ Cannot Proceed]
Date of Issue Required: [Date Field] Upload Supporting Document Required: [File Upload] Text Elaboration Required: [Text Box for Description/Details]
Preparing for submission?
Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. Contact us if you need help.
Last updated