Begin with real tasks
Choose software by walking through the obligations and work your organisation actually has. Make a short list of tasks that create risk when they fail: a time-sensitive report, a consent change, a staff approval or an audit request. Ask each vendor to demonstrate those tasks with realistic data and the roles that would perform them.
Map the data
Ask where information is stored, processed, backed up and accessed, including by support staff, analytics and AI services. The OAIC's APP 8 guidance explains why an overseas data flow needs assessment, while also distinguishing some overseas cloud uses from disclosures. A location statement on a sales page is not a complete data-flow map.
Check records and integrations
For records, ask what the system logs, who can alter an entry and how the organisation exports a history. For integrations, ask which systems exchange data, how errors are surfaced and how access is revoked. A CSV import may be appropriate for some workflows; an API is useful when the work needs a reliable ongoing exchange. Test the actual task instead of treating the integration label as proof.
Plan for change
Finally, ask how data can be exported at the end of a contract and what happens during an outage. Look at the vendor's support terms, change notices and release process. These questions give a more useful comparison than a long feature checklist, especially for a small team that will live with the system every day.