Each note names the person or team who asked for this, and whether it is genuinely a must-have.
The reason to be strict is what the aggregate spend data shows happens afterwards. Vertice's Q1 2026 figures put 66% of SaaS licences either entirely untouched or surplus to requirements — 15% with zero activity at all, and a further 51% where the organisation uses fewer than half the licences it pays for. Those purchases were not made carelessly. They went through evaluations, with requirement lists, run by competent people.
Which means requirement lists are not doing the job they appear to do. A large share of what ends up unused was specified by somebody who would not have paid for it themselves — and unattributed requirements are how that happens. Nobody can tell whether a compliance certification is a legal necessity or something someone read about, so it sits in the must-have column and quietly eliminates two candidates.
Attach a name and the question becomes askable: do we actually need this, or would evidence of a programme in progress do?
A useful forcing test for the must/nice line: if the best option in every other respect failed this one, would we walk away? If not, it is a nice-to-have. And write down the requirements that are about the organisation rather than the software — who administers it, whose budget, what happens when the champion leaves — because those decide more evaluations than features do, and they are the ones that predict whether anyone still uses it in a year.