TL;DR: Twelve criteria are worth scoring when you pick an IT staffing provider, and four separate providers more than the other eight combined: vetting depth, observed AI assessment, which legal entity employs the engineer, and time to first matched profile. Two answers should end a conversation rather than score low: refusal to name the employing entity, and refusal to share funnel drop rates. Weight the rest yourself, because importance depends on your situation rather than on an industry average.
Picking a provider matters more than most procurement decisions in this category, because the difference between a good one and a poor one shows up as a quarter of lost delivery rather than a line on an invoice. This page gives you the criteria, the diagnostic question for each, and a scoring method that does not borrow anyone else’s weightings.

Which criteria matter most?
Four do most of the work: vetting depth, observed AI assessment, the employing entity, and time to first matched profile.
Vetting depth. Ask them to walk through the funnel stage by stage, with the drop rate at each. A provider who answers with pool size is answering a different question, and a top-one-percent claim sitting next to a high acceptance rate means one of those numbers is wrong. Our guide to how vetting funnels work covers what a real one looks like.
Observed AI assessment. Not whether they ask about tools, but whether they watch someone use them. Ask for the written rubric.
Who employs the engineer. A named legal entity in a named country, or a broker engaging a freelancer. This single answer decides where classification risk sits.
Time to first matched profile. A real bench answers within a day, because the vetting happened before you called.

Why observed AI assessment earns its place
Because tool exposure no longer distinguishes anyone, so a provider screening on tool names is screening on nothing.
The 2025 Stack Overflow Developer Survey found 84 percent of developers use or plan to use AI tools, with 50.6 percent of professionals using them daily. What remains scarce is judgment about the output: 46 percent distrust its accuracy against 33 percent who trust it, and developers with ten or more years of experience are the most sceptical.
So the question to a provider is not “do your engineers use AI tools” but “show me the rubric you assess them against”. A provider claiming AI-native engineers without published criteria is making a claim nobody can check, including them.
Why the employing entity decides so much
Because control is what classification tests examine, and staff augmentation is control.
You assign the work, set the hours, provide the systems and review the output. The IRS common-law test weighs exactly those factors, and the HMRC CEST tool asks the same question in UK terms.
If the provider employs the engineer through a registered local entity, that exposure sits with them. If the provider is a broker introducing a freelancer, it sits with you regardless of what the sales conversation implied. Our guide to worker classification in cross-border IT staffing covers where the structure breaks.
Two answers should end the conversation rather than score low. A provider who cannot name the employing entity and country without checking, and one who will not share funnel drop rates. Neither is a scoring matter. Both tell you that something you will need later has not been thought about.

The other eight criteria
Each has one diagnostic question, and all eight fit in a single call.
Take them in that order too. Conversion and replacement terms are the ones a provider concedes most readily early in a conversation, and the ones that get expensive once they know you have chosen them.
- Conversion terms. What does it cost to make an engineer permanent, and does the fee expire after a period of service?
- Replacement guarantee. How many days to a replacement profile, does the trial restart, and what happens to the ramp you already paid for?
- Rate transparency. Send a sample invoice. Is the rate all-inclusive, and what sits outside it?
- Twelve-month retention. The figure a provider cannot control at the point of sale.
- Subcontracting disclosure. Name every legal entity between you and the engineer.
- Specialty coverage. Two engineers placed in your specialty in the last six months, and what happened afterwards.
- Security practice. How fast is access revoked when someone leaves? Ask for evidence from the last offboarding.
- Exit and handover. Notice period, whether handover time is billed, and what gets returned or destroyed.
Our list of 15 questions to ask before you sign extends these into the contractual detail, and the RFP template covers running a formal process.

How to score without borrowing someone else’s weights
Importance weightings published as industry averages promise more than they deliver. The right weighting depends on what your own engagement rests on, which no survey knows.
Pick your own top four. A regulated buyer weights the employing entity highest. A team racing a launch weights time to first profile. Those are different decisions and neither is wrong.
Score on evidence, not assertion. A claim scores one. A claim with a document behind it scores higher. Retention quoted from memory is not the same as retention reported.
Score every provider the same week. Spreading conversations across a month favours whoever you spoke to last, exactly as it does with candidates.
Keep the sheet, dated. It turns your next renewal into a comparison rather than a renegotiation from memory.

What good and weak answers sound like
The difference is rarely enthusiasm. It is whether a number arrives with the sentence.
Good answers name an entity and a country without checking, give drop rates per stage with the top failure modes, quote a retention figure with the window it covers, offer a written AI rubric, and itemise what sits outside the rate.
Weak answers offer pool size in place of drop rate, pair a top-one-percent claim with a high acceptance rate, need to check who employs engineers in a given market, describe engineers as AI-native with no rubric behind it, and say everything is included with no list to back it.

Weighting for your situation
The same twelve criteria, ordered differently depending on the engagement.
A regulated buyer puts the employing entity, subcontracting disclosure and security practice first, because being able to evidence the arrangement to a supervisor matters more than speed. A team racing a launch puts time to first profile and vetting depth first, since a fast provider with a weak funnel wastes the speed on candidates you reject.
A scarce specialty search puts market coverage and recent placements first, because generic quality means little if the provider cannot reach the pool. A buyer planning to convert puts conversion terms and retention first, since they are buying an option and should price the option before the rate.
Checking the provider’s own claims
Three claims recur in this category and each has a cheap verification.
Compliance coverage. A provider claiming to handle compliance in a given market should be able to name the entity, its registration and what it covers. Where the engagement touches personal data, GDPR Article 28 sets what the processing terms must contain, including sub-processor conditions, so ask to see that clause rather than a reassurance.
Security posture. Where any part of the service runs on the provider’s own infrastructure, ask for assurance evidence such as an AICPA SOC report rather than a policy PDF. The NIST Cybersecurity Framework gives you third-party vocabulary both sides will recognise.
Talent quality. The strongest available evidence is not a testimonial, it is the funnel data plus retention. Everything else a provider can say about quality is an assertion about people you have not met.
What to do after you choose
Evaluation does not end at signature, and the criteria above are worth re-running once a year.
Rates reset at renewal, benches change as a provider grows or loses people, and the retention figure that persuaded you is now a year old. A provider who was the right choice in January may not be the right choice for the seat you are filling next January, and finding that out through a bad placement is the expensive route.
Set a calendar reminder against the notice deadline rather than the renewal date. Notice runs backwards from renewal, and that is the date that costs money when missed. Our IT staffing checklist covers the ongoing cadence.
Keep the scoring sheet from the original evaluation. Re-scoring against your own earlier answers is faster than starting again, and it shows you whether the provider improved or you simply got used to them.
Provider evaluation FAQs
What does a good provider get wrong?
Worth asking directly, because the answer separates candour from a script. A provider who has been running for a few years has lost engineers, missed a date and had a placement fail. One who says none of that has happened is either new or not telling you, and both matter.
The useful follow-up is what changed afterwards. A specific process change in response to a specific failure is the strongest quality signal available in a sales conversation, and it is one nobody can fabricate convincingly.
How many providers should we evaluate?
Three is usually enough to calibrate. One gives you no comparison, and beyond four the marginal information drops while the scheduling cost does not.
Should we run a formal RFP?
For a single seat, no. For a programme, or where procurement policy requires it, yes. The criteria are the same either way; the RFP mostly adds documentation and time.
Is a lower rate a reason to switch providers?
Only alongside retention. A rate ten percent lower attached to materially worse retention costs more once you count the second search and the second ramp, and that cost lands in a quarter you did not plan for.
What if a provider refuses to share drop rates?
Treat that as the finding. Providers who measure their funnel share it, because it is their strongest argument. Providers who do not measure it have nothing to share.
Takeaways
- Four criteria carry most of the decision: vetting depth, AI rubric, employing entity, speed to first profile.
- Ask for drop rates, not pool size. Ask for the rubric, not the claim.
- Two refusals should end the conversation: the employing entity and the funnel data.
- Weight the criteria for your own situation rather than importing an industry average.
- Score every provider in the same week, on evidence, and keep the dated sheet.
Run the questions on us
Second Talent employs engineers through licensed local entities across Asia, matches within 24 hours, and reports 92 percent of placements still in seat a year later against a 4.9 average client rating.
Start the conversation, or read what IT staffing is if you are still choosing an engagement model.