Risk checks

Treat privacy and security as purchase criteria.

An LMS handles learner records, performance data, and operational access. Review how the system protects data, limits access, and handles retention before you sign.

iLearn LMS Guide
iLearn LMS Guide is an independent educational resource. It is not an LMS vendor, school, government portal, login service, or support desk. It is not affiliated with Queensland Government iLearn, India's ilearn.gov.in, iLearnNYC, or any other similarly named platform.
Step 1Define requirements
Step 2Test real workflows
Step 3Plan ownership
01

Identity and access

Confirm how users authenticate, reset access, and recover accounts.

Check whether role-based access controls are granular enough for your org structure.

Ask how the system logs privileged actions and access changes.

02

Data handling

Review what data is stored, where it is stored, and how long it is retained.

Check whether you can export records in usable formats without vendor help.

Ask how backups, deletion requests, and legal holds are handled.

03

Vendor controls

Request a plain explanation of incident response, vulnerability management, and patching practices.

Check whether sub-processors or third-party services are involved in hosting, analytics, or support.

Confirm whether security reports or audit summaries are available on request.

04

Next steps

Map the data you will collect and who can access it.

Review the retention and deletion policy before launch.

Decide how you will exit the platform if needed later.

  • Confirm authentication and role controls.
  • Verify retention, deletion, and export options.
  • Review incident response and third-party dependencies.

Review the risk checklist

Use the glossary next if you want the terms behind the evaluation criteria in plain English.

Start the checklist