How do you check references, conflicts, and discretion?
By Joel Andren · Published by PressFriendly, a PR agency · Reviewed August 21, 2026 · Editorial standards · 4 of 4 in this section
Speak with people who managed comparable work, define conflicts in writing, and inspect how the provider controls sensitive information. Ask about routine delivery and difficult moments such as corrections, disagreement, staff changes, incidents, and exit. Respect former clients' confidentiality while requiring enough evidence to assess the proposed team.
References should verify how the work operated
Ask for references that collectively cover similar scope, executive access, and risk. Include a day-to-day manager when possible, and seek a relationship that experienced a material change or ended. Contact each person with the candidate's permission and ask:
- Which named people sold and performed the work?
- How much executive and internal time did the program require?
- What did the provider do well, and where did management intervene?
- How were facts, approvals, urgent requests, and corrections handled?
- Did the provider distinguish earned opportunities from paid access?
- Did reports separate activity, outputs, audience response, and outcomes?
- What happened when priorities, staff, or scope changed?
- How did the provider handle disagreement or confidential information?
- How were files, accounts, and access transferred at exit?
- Would you use the same team for the same work again?
Keep answers within the authorized selection group. Do not ask a reference to reveal strategy, private executive disclosures, personal data, credentials, or private contact information.
A new practice, confidential portfolio, or heavily subcontracted engagement may make a perfect reference unavailable. Use redacted process evidence, attributed public work, a paid trial, and specific contract protections to close the gap. An unexplained absence of verifiable evidence remains an open risk.
Define conflicts around the actual competition and access
Map competition for customers, capital, talent, policy influence, media attention, speaking slots, awards, and category ownership. Include the provider's current clients, active pitches, subcontractors, referral or financial interests, and relationships with paid opportunity vendors. Two companies may compete for the same executive position or scarce opportunity without selling the same product.
The PRSA Code of Ethics calls on members to disclose existing or potential conflicts promptly and safeguard client confidences. Apply those standards whether or not the provider belongs to PRSA.
The contract should define the restricted category, geography, subjects, named organizations, duration, disclosure deadline, consent owner, information barriers, team separation, and remedies. Price any exclusivity explicitly. Require notice before a new conflict is accepted, rather than relying on a general promise to manage it.
Discretion must appear in systems and behavior
Ask the provider to map where interview recordings, drafts, personal details, credentials, contact data, and approval records enter, move, and leave its systems. Confirm administrators, role-based access, approved tools, subprocessors, retention, backups, incident notification, and secure return or deletion at exit.
NIST says its Cybersecurity Framework 2.0 applies whether an organization operates assets itself or uses a service provider, and can support provider evaluation. Use it as a governance reference, then apply company-specific security, privacy, legal, and regulatory requirements.
Review whether the provider gets permission before using a client's name, logo, results, work, or executive quote in marketing. Ask for a redacted access register, incident process, or offboarding record when policy claims need operational evidence.
Do not reward a candidate for sharing another client's confidential information during a pitch. That behavior is evidence about how it may treat the executive's information later.
Each party should accept its part of the residual risk
The executive approves personal access, boundaries, and conflicts affecting their reputation. The payer accepts commercial protections, exceptions, and residual risk. The company approves access to its accounts, assets, and confidential information. The program manager must be able to operate the controls, maintain the diligence record, and escalate a concern.
Record findings, unresolved questions, approved exceptions, and decision owners in the selection file. Put material promises, conflict rules, security duties, and exit steps into the scope of work and contract.