本文へ移動
DocumentMS

Checklist

DMS RFP checklist: document management system requirements

A useful RFP asks what a system does, not whether it has a feature name. This checklist groups requirements by capture, control, search, security, records management, integration and support, and explains what an evasive answer to each one usually means.

Written to be used against every vendor, including us. Several questions below are ones we would rather not be asked, and they are here because they are the ones that distinguish products.

How to use this

Most document management RFPs ask whether a system has a feature. That produces a column of ticks from every vendor and tells you nothing, because almost everyone can answer yes to "does your system support version control".

The questions below ask what a system does instead, and each one comes with a note on what an evasive answer usually means. That second column is the useful part. A vendor who answers "yes, through our workflow engine" to a question about whether administrators can edit the audit trail has not answered it.

Weight these by what you are actually accountable for. An organisation with no statutory retention obligation should not be scoring vendors on disposition review, and one that is audited annually should not treat it as a nice-to-have.

Capture and intake

Where documents come from, and what happens on arrival.
Capture requirements and how to read the answers
AskWhy it mattersWhat an evasive answer means
Which intake routes are supported without a person filing manually?Email is where most documents arrive. Intake that requires leaving the mailbox does not happen."Users can drag and drop" is not an answer about automated intake.
Does OCR run automatically on arrival, and on which file types?A scanned archive without OCR is storage, not a searchable record.Vagueness about image-only PDFs usually means it handles them poorly.
Can mandatory metadata be enforced at the point of upload?Optional fields decay to blanks, and a metadata model of blanks cannot be reported from."Fields can be configured as required" — ask whether upload is actually blocked.
What happens when the same document arrives twice by different routes?Duplicates drive storage cost and cause superseded versions to circulate as current.Filename-based detection is not duplicate detection.

Control and versioning

The difference between storing documents and controlling them.
Version control requirements and how to read the answers
AskWhy it mattersWhat an evasive answer means
Is the current version marked unambiguously, and are superseded versions labelled?Work done to a superseded document is the most expensive documentation failure there is."Version numbers are shown" does not tell you which one is current.
Is version history ever trimmed, and can that be configured?A retained version limit silently deletes the evidence you will need.If there is a limit, ask what the default is — most people never change it.
Does a printed or downloaded copy carry its status?On a production floor or a construction site, the copy in use is paper.Watermarking is either supported or it is not; a long answer means it is not.
Can two people edit the same document at once, and what happens if they do?Concurrent editing and controlled versioning are different models. Pick deliberately."Both changes are saved" means you now have two documents.

Security and access

The questions a security review will ask anyway. Better to ask them first.
Security requirements and how to read the answers
AskWhy it mattersWhat an evasive answer means
Can an administrator edit or delete audit trail entries?A log privileged users can tidy cannot evidence privileged user behaviour.Anything other than a flat "no" is a "yes".
Are document views and downloads logged, or only modifications?A change log cannot tell you who read a record before it leaked."Full audit trail" often means changes only. Ask explicitly about reads.
Is there a permission level that allows reading without downloading?Contractors and auditors frequently need to read without retaining a copy."Permissions are granular" — ask to see the actual levels.
Which of these capabilities require a higher tier or an add-on?This is where comparison tables and quotes quietly diverge.Ask for it in writing, mapped to the tier you are being quoted.
How is administrative access to customer content controlled and logged?Vendor staff access is the risk customers forget to assess.The strong answer is that it is impossible without a logged, alerted break-glass grant.

Records management

Skip this section only if you have no retention obligation at all.
Records requirements and how to read the answers
AskWhy it mattersWhat an evasive answer means
Is retention attached to a record class or to a folder?Folder-scoped retention changes when a document is moved. That is a defect."Retention policies apply to libraries" means folder-scoped.
What event starts the retention clock, and can it be set after creation?Most real triggers — contract termination, end of employment, end of production — are not the creation date.If only creation date is supported, your schedule cannot be implemented correctly.
What happens when a retention period expires?Automatic deletion cannot evidence who authorised a disposal."Documents are deleted automatically" is a compliance problem, not a feature.
How does a legal hold interact with retention, and who can release it?Destroying records after litigation is anticipated is far worse than over-retaining.If holds are "achieved through permissions", they are not holds.

Integration, migration and exit

The section most RFPs leave until last, and the one that decides the cost of the next decision.
Integration and exit requirements and how to read the answers
AskWhy it mattersWhat an evasive answer means
Can we export everything — documents, metadata, version history, audit trail?A repository you cannot fully export is a future migration problem you have already bought.Partial export, or export "on request", is a lock-in mechanism.
What are the API rate limits and the deprecation window for breaking changes?A developer cannot design a reliable integration without both.If neither is published, the API is not a supported product surface.
Does single sign-on remove access when a user is disabled in our directory?This is how leavers actually lose access. Anything else depends on a manual step."SSO is supported" says nothing about deprovisioning.
Can documents be stored in our own cloud account and region?It converts a data residency commitment into something you can verify yourself.Ask specifically whether metadata and the search index follow the documents.
What happens to our data at termination, and how long is it retained?Should be in the contract, not the sales conversation.If it is not in the DPA, it is not a commitment.

Questions to ask about the vendor, not the product

These predict the next three years better than any feature comparison.
  • Can we see a SOC 2 report or ISO 27001 certificate under NDA, and what is its scope and date?
  • Will you sign our data processing addendum, or only your own paper?
  • Is customer data used to train AI models, and is that commitment contractual or marketing?
  • What is the published uptime commitment, how is it measured, and what is the remedy if missed?
  • Who implements this — you, a partner, or us — and what does that cost?
  • Can we speak to a customer of similar size in our sector, without you on the call?
  • What have you removed or deprecated in the last two years?
  • Which of our requirements does your product not meet? A vendor with no answer has not read them.

FAQ

Using this checklist

Can we use this in our own RFP document?

Yes, copy it. Attribution is welcome but not required. It is more useful to us as something buyers actually use than as a gated download — which is also why there is no form in front of it.

Is this weighted in DocumentMS’s favour?

Some of it, inevitably, because we built the product around the problems we think matter and the questions reflect that view. But several entries are questions we would rather not be asked — our API rate limits are unpublished, our certification position is not finalised, and we do not offer on-premise deployment. Those are in here anyway.

How many of these should be mandatory requirements?

Fewer than you think. An RFP with sixty mandatory requirements either eliminates every vendor or gets answered dishonestly. Pick the ten you are genuinely accountable for, make those mandatory, and score the rest.

What is the single best question on this page?

"Can an administrator edit or delete audit trail entries?" It takes ten seconds, the answer cannot be hedged usefully, and it separates systems designed for evidence from systems designed for storage more reliably than any other question here.

Send the checklist over with your weightings. Where the answer is "not yet" we will say so on the call rather than in a document three weeks later.