Bitnet Solutions
Checklist

Things Schools
Should Consider

What to require from a technology provider

A procurement checklist for schools, trusts and specialist settings. Twelve areas, the questions worth asking, and the answers that should give you pause.

Bitnet Solutions · September 2026
It names no products, including ours.
bitnets.co.uk
How to use this

Written to be taken into a meeting

This checklist is written to be taken into a meeting. Twelve areas, each with the questions worth asking, the evidence worth requesting, and the answers that should give you pause.

It names no products, including ours. A checklist that only one supplier can pass is a sales document, and school leaders can spot one at fifty paces. Every requirement here is one you should be able to put to any provider, and several good ones will answer well.

Three suggestions on using it well
Ask for evidence, not assurance

"Yes, we're compliant" and "here is the certificate, dated" are different answers. The distinction matters most in the areas you are least equipped to verify yourself.

Weight it for your setting

A mainstream primary and a hospital school running five sites across fifty weeks have genuinely different priorities. Sections 6 to 9 matter disproportionately to specialist settings. Score what matters to you.

Ask the exit questions early

Section 10 covers data portability and exit terms. Suppliers find them easier to answer before a contract than after one, and the quality of the answer tells you a great deal about the relationship you are entering.

The twelve areas
01Security certification
07Attendance in non-standard settings
02Alignment to the DfE standards
08Multi-agency information sharing
03AI: governance, not just capability
09Data protection and special-category data
04Filtering, monitoring and the annual review
10Data portability and exit
05Purpose-built or adapted
11Service levels and support
06Evidence and audit trails
12Track record and partnership
Things Schools Should Consider · Bitnet Solutions2
01

Security certification

Ask
  • Do you hold Cyber Essentials? Cyber Essentials Plus?
  • When was it last renewed, and when does it expire?
  • Do your subcontractors and hosting partners hold equivalent certification?
  • Do you hold ISO 27001 or an equivalent information security standard?
Request
  • The current certificate, with dates
  • Confirmation of who in your supply chain holds what
Pause if
  • Certification is described as "in progress" with no date
  • The certificate has expired or renewal is unclear
  • They cannot say what their subcontractors hold
Why it matters  Cyber Essentials is expected under the DfE's digital and technology standards and increasingly cascades from procurement frameworks to supplier selection. It has moved from a differentiator to a condition of entry.
02

Alignment to the DfE digital and technology standards

Ask
  • Which of the six core standards does your product help us meet, and how specifically?
  • Where does responsibility sit between us and you?
  • Do you offer a gap review against the standards?
Request
  • A written mapping of product capability against the standards
  • A clear statement of the split of responsibility
Pause if
  • They cannot name the standards
  • Everything is claimed as covered, with nothing left for the school to do
  • Alignment is asserted but never demonstrated
Why it matters  All schools are expected to meet the core standards by 2030. A supplier who understands them reduces your workload. One who does not will add to it.
Things Schools Should Consider · Bitnet Solutions3
03

AI: governance, not just capability

Ask
  • Does your product use AI, and where exactly?
  • What data is processed, where is it processed, and is it used to train models?
  • Can we turn AI features off?
  • Can filtering and monitoring identify AI-generated content?
  • Do you have a published AI use policy of your own?
Request
  • A written statement of AI use and data handling
  • Their own internal AI policy
Pause if
  • AI is a headline feature but nobody can explain what it does with your data
  • Training data use is vague or answered only verbally
  • They advise on AI governance but have no policy themselves
Why it matters  KCSIE 2026 places AI inside safeguarding, online safety, filtering and monitoring, staff training and governance. Introducing an AI tool is a governance event, not just a purchase.
04

Filtering, monitoring and the annual review

Ask
  • How does your product support the annual review of filtering and monitoring effectiveness?
  • Does it cover all internet-connected devices in all our locations, including sites we do not own?
  • What record does it produce that we can keep as evidence?
Request
  • A sample of the evidence output
Pause if
  • Coverage is device-limited or location-limited in ways that do not match how you operate
  • No dated, exportable record is produced
Why it matters  KCSIE 2026 requires the review to be led by the responsible senior leader with DSL and IT support, to cover all internet-connected devices in all relevant locations, and to be formally recorded. A review you cannot evidence is a review that did not happen.
Things Schools Should Consider · Bitnet Solutions4
05

Purpose-built or adapted

Ask
  • Was this designed for settings like ours, or adapted to accommodate us?
  • Which of your existing customers are genuinely comparable to us?
  • What did you change to make it work for the last setting like ours?
  • Who did you design it with?
Request
  • Named reference customers in a comparable setting
  • A direct conversation with one of them, without you present
Pause if
  • References are aggregate — "over 300 schools" — with no names
  • The comparable customers are all mainstream
  • The workflow for your setting is described as configurable rather than designed
Why it matters  Alternative provision, SEND and hospital settings differ from mainstream in kind, not degree. A configurable mainstream system still assumes a stable cohort on a predictable timetable in one building.
06

Evidence and audit trails

Ask
  • Can we produce inspection-ready evidence without exporting to a spreadsheet first?
  • Is there a full audit trail — who recorded what, when, and what changed?
  • Can we show a pattern across time, staff and location, or only a list of events?
  • How is evidence for EHCP reviews and Individual Support Plans assembled?
Request
  • A live demonstration of producing one piece of evidence end to end
  • A sample audit trail
Pause if
  • Every answer involves an export
  • The audit trail records the entry but not subsequent edits
Why it matters  With overall effectiveness grades removed, inspection looks harder at the evidence underneath. And the requirement across recent policy is consistently to show the work, not simply to do it.
Things Schools Should Consider · Bitnet Solutions5
07

Attendance in non-standard settings

Ask
  • How do you handle dual registration, part-time timetables and short placements?
  • How quickly do you implement changes to attendance codes?
  • How is attendance recorded for a pupil attending irregularly for medical reasons?
  • Can we generate a statutory return without reconciling between systems?
Request
  • A demonstration using a genuinely awkward case from your own setting — bring one
Pause if
  • Non-standard patterns are handled through workarounds
  • Code changes take a long time or attract a charge
Why it matters  In specialist settings attendance is the highest-volume, highest-consequence data you hold, and the point at which generic systems most often fail.
08

Multi-agency information sharing

Ask
  • How do health, social care, local authority and home-school colleagues access what they need?
  • How granular is access control?
  • Is sharing logged?
  • What happens when a pupil moves between provisions — does the record follow?
Request
  • The access control model in writing
  • A worked example of a transition between settings
Pause if
  • Sharing means emailing an export
  • Access is all-or-nothing
Why it matters  In specialist settings the picture of a child is held by several organisations. Fragmented sharing is where safeguarding oversight most commonly fails.
Things Schools Should Consider · Bitnet Solutions6
09

Data protection and special-category data

Ask
  • Where is our data hosted, and under which jurisdiction?
  • How is special-category data handled?
  • Who at your organisation can access our data, under what circumstances, and is that logged?
  • What are your breach notification timescales?
  • Can we see your data processing agreement before we commit?
Request
  • The DPA and a completed data protection impact assessment template
  • Hosting and sub-processor detail
Pause if
  • Hosting location is unclear
  • Staff access to customer data is not logged
  • The DPA is only available after signature
Why it matters  SEND and medical information is Article 9 special-category data under UK GDPR. The obligations are higher and so is the consequence of getting it wrong.
10

Data portability and exit

Ask
  • If we leave, what do we get back, in what format, and how quickly?
  • Is there a charge for extraction?
  • Does the export include historical records, audit trails and attachments, or only current data?
  • How long do you retain our data after termination, and how is deletion evidenced?
  • What are the notice periods?
Request
  • A sample export from a comparable customer
  • Exit terms in writing before signature
Pause if
  • Extraction attracts a significant fee
  • The export excludes historical data or audit trails
  • The question visibly makes them uncomfortable
Why it matters  This is the most revealing section in the checklist. A provider confident in the relationship will answer it straightforwardly. It is also the question schools most often skip, and the one they most often regret skipping.
Things Schools Should Consider · Bitnet Solutions7
11

Service levels and support

Ask
  • What are your response commitments by severity, and what counts as critical?
  • Do you commit to response, resolution, or both?
  • What happens if a commitment is missed?
  • Is support UK-based, and what are the hours?
  • Who is our named contact?
Request
  • The published service level agreement
  • Recent performance against it
Pause if
  • Service levels are described but not documented
  • Nobody will say what happens when a target is missed
  • "Critical" is defined so narrowly that nothing qualifies
Why it matters  A service is judged on what happens when something breaks, not when everything works.
12

Track record and partnership

Ask
  • How long have you worked in this sector?
  • How long have your longest-standing customers been with you?
  • Who will actually deliver our implementation, and will they still be there afterwards?
  • How are product changes decided, and do customers influence the roadmap?
  • What went wrong on your last implementation, and how did you handle it?
Request
  • Named references in a comparable setting
  • The implementation plan with named roles
Pause if
  • The sales team and the delivery team have never met
  • No supplier can describe a single implementation that hit difficulty
  • Roadmap influence is promised but has no mechanism
Why it matters  The last question is the most useful one in this document. Every implementation encounters something. A provider who describes a problem and how they resolved it is telling you the truth. A provider who claims a flawless record is telling you something else.
Things Schools Should Consider · Bitnet Solutions8
Scoring

One sheet per supplier

Photocopy or print this page for each supplier.

#AreaWeight 1–3Score 1–5Evidence seenNotes
01Security certification
02DfE standards alignment
03AI governance
04Filtering and monitoring
05Purpose-built for our setting
06Evidence and audit trails
07Attendance handling
08Multi-agency sharing
09Data protection
10Portability and exit
11Service levels
12Track record

Weight each area 1 to 3 for your setting before you meet anyone. Deciding what matters after you have seen the demonstrations is how organisations talk themselves into the wrong product.

Things Schools Should Consider · Bitnet Solutions9
A note from us

We think schools should be asking all of them, of everyone

Bitnet Solutions has worked with UK schools for twelve years, largely in the settings other providers find difficult — special schools, alternative provision, pupil referral units, hospital and residential education, and the trusts that run them. We are Cyber Essentials certified.

We wrote this checklist because we are asked most of these questions and we think schools should be asking all of them, of everyone. If it helps you run a better procurement process and you choose a different supplier at the end of it, it has still done its job.

If you would like to work through it with us — against our products or in general — we are happy to.

Bitnet Solutions
bitnets.co.uk
info@bitnets.co.uk
0121 318 7900

This checklist is general guidance and not legal or procurement advice. Requirements change; verify current DfE standards and statutory guidance at the time of purchase.