Pass one: restate the outcome
Write one sentence that every bidder must answer:
The business needs these named users to complete this named workflow, using these systems and data, with these consequences if it fails.
Then list acceptance examples. “Client portal” is not an outcome. “Each client can retrieve only its approved reports, submit requested files, and recover access without staff intervention” is testable.
The UK government's Technology Code of Practice is written for public-sector technology, but its emphasis on user needs, accessibility, security, open standards, and lifecycle thinking supplies useful questions for any buyer. It does not certify a particular proposal.
Pass two: expose scope and exclusions
Give every quote the same rows:
| Area | Included | Excluded | Ambiguous | Acceptance evidence |
|---|---|---|---|---|
| Workflow discovery | ||||
| Interface and accessibility | ||||
| Identity and permissions | ||||
| Data migration | ||||
| Integrations | ||||
| Testing and security review | ||||
| Deployment and monitoring | ||||
| Backup and restore | ||||
| Documentation and training |
Do not fill an empty cell with a favorable assumption. Send it back as a question.
Pass three: normalize the price
Separate:
- one-time discovery and build;
- recurring platform and hosting;
- recurring operation and support;
- usage-based charges;
- included change capacity;
- rates for additional work;
- migration and training; and
- termination assistance.
Calculate one-year and three-year committed cost. Add internal staff hours with an explicit hourly assumption. Show uncertain incident and change work as a range instead of zero.
Pass four: assign responsibilities
For every recurring task, name the customer, vendor, platform, or third party that owns it. Include user access changes, billing, alerts, dependency updates, credential rotation, restore tests, support, and data retention.
“Hosted” does not answer who responds when the application is reachable but a critical workflow is broken. “Maintenance included” does not answer whether a new browser, dependency, integration, or business rule is a defect or a change request.
Pass five: price failure and exit
Ask what happens when:
- delivery is late;
- acceptance fails;
- a third-party integration changes;
- the application is unavailable;
- the vendor is unreachable;
- the relationship ends; or
- the business selects a replacement.
Record repository access, cloud-account control, data export, credentials, documentation, notice period, deletion timing, and handoff rates. This is not legal interpretation; unclear terms should be reviewed by qualified counsel.
Pass six: compare like with like
Do not average the rows into a decorative score. First reject any proposal that misses a required outcome or leaves a critical responsibility ownerless. Then compare the remaining options by normalized cost, evidence, risk retained by the buyer, and exit quality.
The cheapest proposal may still win. The worksheet simply prevents it from winning by omitting work that another bidder priced honestly.