Pass one: restate the outcome

Write one sentence that every bidder must answer:

The business needs these named users to complete this named workflow, using these systems and data, with these consequences if it fails.

Then list acceptance examples. “Client portal” is not an outcome. “Each client can retrieve only its approved reports, submit requested files, and recover access without staff intervention” is testable.

The UK government's Technology Code of Practice is written for public-sector technology, but its emphasis on user needs, accessibility, security, open standards, and lifecycle thinking supplies useful questions for any buyer. It does not certify a particular proposal.

Pass two: expose scope and exclusions

Give every quote the same rows:

Area Included Excluded Ambiguous Acceptance evidence
Workflow discovery
Interface and accessibility
Identity and permissions
Data migration
Integrations
Testing and security review
Deployment and monitoring
Backup and restore
Documentation and training

Do not fill an empty cell with a favorable assumption. Send it back as a question.

Pass three: normalize the price

Separate:

  • one-time discovery and build;
  • recurring platform and hosting;
  • recurring operation and support;
  • usage-based charges;
  • included change capacity;
  • rates for additional work;
  • migration and training; and
  • termination assistance.

Calculate one-year and three-year committed cost. Add internal staff hours with an explicit hourly assumption. Show uncertain incident and change work as a range instead of zero.

Pass four: assign responsibilities

For every recurring task, name the customer, vendor, platform, or third party that owns it. Include user access changes, billing, alerts, dependency updates, credential rotation, restore tests, support, and data retention.

“Hosted” does not answer who responds when the application is reachable but a critical workflow is broken. “Maintenance included” does not answer whether a new browser, dependency, integration, or business rule is a defect or a change request.

Pass five: price failure and exit

Ask what happens when:

  • delivery is late;
  • acceptance fails;
  • a third-party integration changes;
  • the application is unavailable;
  • the vendor is unreachable;
  • the relationship ends; or
  • the business selects a replacement.

Record repository access, cloud-account control, data export, credentials, documentation, notice period, deletion timing, and handoff rates. This is not legal interpretation; unclear terms should be reviewed by qualified counsel.

Pass six: compare like with like

Do not average the rows into a decorative score. First reject any proposal that misses a required outcome or leaves a critical responsibility ownerless. Then compare the remaining options by normalized cost, evidence, risk retained by the buyer, and exit quality.

The cheapest proposal may still win. The worksheet simply prevents it from winning by omitting work that another bidder priced honestly.