Built from your actual system, so the questions are about your problem rather than about trivia.
Questions grounded in your real codebase and a way to read the answers, including which answers should worry you.
Whether the experience described matches the answers given. Titles are cheap; reasoning is not.
What the proposal commits to, what it quietly excludes, and which line item is where the risk actually sits.
Whether the numbers are consistent with the work described, and which assumption would double them.
A structured technical interview you can run yourself, with what a good answer sounds like written next to each question.
How to check the specific technical claims a vendor is making, rather than taking the deck at face value.
Describe the situation in your own words and see the procedure — and its cost — before you spend anything.