A school may be genuinely interested in a supplier and still be unable to proceed because the necessary documents are missing.
The business may have appropriate insurance but cannot find the current certificate. Its safeguarding policy may describe procedures that no longer match the organisation. The quotation may use a trading name while the contract names a different company. A software provider may have a privacy notice but no data-processing agreement. A contractor may send a generic risk assessment that does not address the work taking place on the school site.
Each missing or inconsistent document creates another question, another email and another reason for the purchase to slow down.
Schools and multi-academy trusts manage public money and must take reasonable steps to understand who they are buying from, what risks the supplier creates and whether appropriate controls are in place. The documents requested will depend on the product, contract value, delivery model and level of risk.
A stationery supplier will not need the same pack as an online tutoring service. An EdTech platform processing pupil data will face different questions from a furniture manufacturer. A roofing contractor working during the school holidays will need different evidence from a consultant delivering a remote leadership workshop.
There is therefore no universal bundle of documents that automatically makes every business “approved to work with schools”.
The practical goal is to maintain:
- a core supplier-information pack that is ready for most school opportunities;
- specialist documents relevant to the business’s actual work;
- a clear process for keeping everything current;
- a secure way to share sensitive information during due diligence.
This guide explains what documents school suppliers should have ready, when schools are likely to ask for them and how to organise the pack so it supports rather than delays the purchasing process.
Start with a core supplier information pack
Every supplier should be able to identify the organisation that will provide the product, enter the contract and issue the invoice.
This is particularly important when the business uses a brand name that differs from its legal identity.
Your core supplier information sheet should normally include:
- full legal name;
- trading name, where different;
- business type, such as limited company, partnership, charity or sole trader;
- company or charity number, where applicable;
- registered office;
- main trading address;
- VAT number, where applicable;
- website address;
- main telephone number;
- sales contact;
- finance contact;
- contract and compliance contact;
- bank details supplied through an appropriately secure process.
UK limited companies are required to display specified company information on their websites and business correspondence. This includes the registered company name, company number, registered office and place of registration. Suppliers can check the current requirements in the government guidance on company signs, stationery and promotional material.
The legal information should remain consistent across:
- the website;
- sales pack;
- quotation;
- supplier-onboarding form;
- contract;
- insurance documents;
- purchase order;
- invoice;
- data-processing agreement.
Where different companies within a group perform different functions, explain the arrangement clearly.
For example:
“SchoolTech is the trading name of School Technology Services Ltd. School Technology Services Ltd will enter the contract, provide the service and issue all invoices.”
Schools may also request:
- a certificate of incorporation;
- recent accounts;
- credit information;
- proof of VAT registration;
- bank confirmation;
- a completed supplier-onboarding form;
- details of company directors;
- confirmation of financial or legal proceedings;
- details of parent or related companies.
These additional checks are more common for high-value, long-term or business-critical contracts.
Keep the core information in one controlled document rather than recreating it for every opportunity. This reduces the chance that the quotation gives one address, the invoice another and the contract a third.
Keep current insurance certificates and a clear coverage summary
Schools frequently ask suppliers for evidence of insurance.
The exact cover required depends on the activity, contractual terms and risks involved. There is no single insurance package or coverage limit that applies to every school supplier.
Common policies include:
Public liability insurance
This is particularly relevant where the supplier visits school premises, installs equipment, delivers activities or could cause injury to another person or damage to property.
Employers’ liability insurance
Most businesses employing staff are legally required to hold employers’ liability insurance. The certificate should name the correct employing entity and remain available to staff.
Professional indemnity insurance
This may be relevant where the supplier provides advice, assessment, design, consultancy, professional reports or specialist recommendations.
Product liability insurance
This may apply to businesses manufacturing, importing, distributing or selling physical products.
Cyber insurance
This may be relevant to software providers, managed IT companies and organisations holding substantial amounts of sensitive or personal information.
Specialist insurance
Depending on the work, the supplier may also require:
- medical malpractice or treatment liability;
- abuse-related cover;
- motor or fleet insurance;
- contract works insurance;
- environmental liability;
- business interruption cover;
- plant and equipment insurance;
- professional cover linked to registration with a regulatory body.
Your insurance pack should include:
- current certificates;
- the insured company name;
- policy numbers;
- coverage dates;
- indemnity limits;
- a brief description of the insured business activities;
- relevant endorsements or exclusions;
- broker or insurer contact details where appropriate.
Check that the declared business activities include the services offered to schools.
A supplier may hold public liability insurance but discover that the policy excludes a particular sport, treatment, construction activity or form of work with children. The certificate alone does not prove that every proposed activity is covered.
Where a school or trust asks for a specific level of insurance, confirm the requirement with your broker before agreeing to the contract.
Do not promise to increase cover after the school appoints you. Resolve any gap before the agreement is signed and delivery begins.
Prepare safeguarding, recruitment and DBS documentation
Suppliers working directly with children should have operational safeguarding arrangements in place before approaching schools.
A safeguarding pack may include:
- safeguarding and child-protection policy;
- name and contact details of the supplier’s safeguarding lead;
- staff code of conduct;
- safer-recruitment procedure;
- identity and reference-checking process;
- DBS eligibility and checking procedure;
- safeguarding induction and training records;
- procedure for reporting concerns;
- allegations-management procedure;
- whistleblowing procedure;
- online communication policy;
- photography and recording policy;
- one-to-one working arrangements;
- subcontractor safeguarding controls;
- template safeguarding assurance letter.
The supplier’s policy should reflect its actual service.
A tutoring company may need detailed arrangements for online one-to-one contact. A school-trip venue may need procedures for lost children, staff conduct and reporting concerns. A contractor whose engineers work in restricted plant areas may have much more limited contact with pupils but still needs to understand site rules and the school’s reporting process.
Current Keeping Children Safe in Education guidance sets out the legal safeguarding duties applying to schools and colleges. Suppliers need to understand the environment within which schools assess external staff, contractors and providers.
DBS documents should be handled carefully.
Do not maintain or distribute full copies of certificates unnecessarily. Instead, keep a secure internal record showing:
- the person’s identity;
- the role assessed;
- the level of check;
- whether barred-list information was included;
- the date of the check;
- who reviewed it;
- the recruitment decision;
- any use of the DBS Update Service;
- any required risk assessment.
Eligibility must be assessed role by role. Enhanced checks and barred-list information can only be requested where the law permits them. The DBS publishes current guidance explaining which activities qualify as regulated activity with children.
A supplier assurance letter may confirm:
- that relevant identity and recruitment checks have been completed;
- which type of DBS check applies to the assigned staff;
- that safeguarding training is current;
- that staff understand the provider’s reporting procedures;
- that the supplier will inform the school of material changes;
- that equivalent controls apply to relevant subcontractors.
Avoid describing employees as “DBS approved”. A DBS disclosure is one part of safer recruitment; it is not a certificate of personal safety or general approval to work in every role.
Maintain health and safety documents suited to the work
Health and safety documentation should be proportionate to the hazards created by the supplier’s activity.
The Health and Safety Executive describes risk management as a process of identifying hazards, assessing risks, introducing controls, recording significant findings and reviewing those controls.
Your health and safety pack may include:
- health and safety policy;
- general risk assessment;
- activity-specific risk assessments;
- site-specific risk assessment where required;
- method statements;
- COSHH assessments;
- manual-handling assessment;
- working-at-height procedure;
- equipment inspection records;
- electrical safety records;
- vehicle and delivery controls;
- first-aid arrangements;
- accident and near-miss procedure;
- emergency arrangements;
- personal protective equipment requirements;
- staff competence and training records;
- subcontractor assessment procedure.
A simple classroom workshop will not require the same documentation as a roof replacement, kitchen installation or science demonstration involving hazardous substances.
For work on school premises, schools may ask for a risk assessment and method statement, often called RAMS.
A useful method statement should explain:
- what work will be performed;
- who will perform it;
- which equipment or materials will be used;
- how the work area will be controlled;
- how pupils, staff and visitors will be protected;
- what supervision is provided;
- how waste will be handled;
- what happens during an emergency;
- how the work will be checked and handed over.
The HSE advises organisations using contractors to define the work, select competent providers, exchange relevant information, assess risks and coordinate activities.
Site-specific information may include:
- school access and sign-in arrangements;
- fire procedures;
- restricted areas;
- vehicle routes;
- asbestos information relevant to the work;
- working times;
- site contacts;
- first-aid arrangements;
- how the work will be separated from pupils.
Do not send the same generic risk assessment to every school when the site, participants or activity differ materially.
Have data protection and cybersecurity documents ready
Suppliers that process personal data need more than a generic privacy policy.
The first task is to determine whether the supplier acts as a controller, processor or joint controller for each processing activity.
The role depends on who decides the purposes and means of processing, not simply what the contract calls the parties. The Information Commissioner’s Office provides guidance on determining the correct roles.
A data-protection and security pack may include:
- privacy notice;
- record of processing activities;
- controller and processor assessment;
- data-processing agreement;
- data-flow diagram;
- categories of data processed;
- purposes of processing;
- list of subprocessors;
- hosting locations;
- international-transfer arrangements;
- retention schedule;
- data-deletion procedure;
- data-subject rights procedure;
- personal-data breach procedure;
- information-security policy;
- access-control policy;
- backup and disaster-recovery plan;
- business-continuity plan;
- penetration-test or security-assessment summary;
- relevant security certifications;
- technical contact for due diligence.
Where a school uses the supplier as a processor, there must be a written controller–processor contract covering the processing activities. The ICO states that this contract helps both parties understand their obligations, responsibilities and liabilities.
The agreement should address matters including:
- processing only on documented instructions;
- confidentiality;
- security measures;
- use of subprocessors;
- assistance with individual rights;
- assistance with breaches and impact assessments;
- data return or deletion;
- audit and compliance information.
The ICO provides a detailed explanation of the clauses required in controller–processor agreements.
EdTech and other digital suppliers should also be ready to explain:
- whether pupil, staff or parent data is processed;
- whether special-category data is involved;
- how accounts are created and removed;
- how access is controlled;
- whether multi-factor authentication is available;
- whether data is encrypted;
- how security incidents are detected;
- how quickly the school will be informed of a breach;
- whether information is used for advertising or unrelated analytics;
- whether data is used to train commercial AI systems;
- how the school exports its data when the contract ends;
- how deleted data is handled in backups.
Do not claim that a product is “100% secure” or automatically “fully GDPR compliant”. Explain the controls, responsibilities and limitations accurately.
Prepare product, professional and sector-specific evidence
Some suppliers require documents connected to the nature of the product or profession rather than school procurement generally.
Physical products
Depending on the product, schools may ask for:
- technical specifications;
- product-safety documentation;
- conformity declarations;
- test reports;
- manufacturer information;
- age or phase suitability;
- installation instructions;
- maintenance instructions;
- fire or flammability information;
- electrical safety information;
- load limits;
- warranties;
- recall procedure;
- spare-parts availability.
Food and catering suppliers
Documents may include:
- food-business registration;
- food-hygiene ratings or inspection evidence;
- allergen-management procedure;
- HACCP or food-safety management documents;
- temperature-control procedures;
- traceability records;
- staff food-hygiene training;
- menu and nutritional information;
- recall procedure.
Transport providers
Schools may ask for:
- operator licence;
- vehicle and driver details;
- motor and passenger insurance;
- vehicle-maintenance records;
- MOT evidence;
- driver-licence checks;
- seat-belt and accessibility information;
- journey risk assessment;
- breakdown and emergency procedures.
Clinical, therapeutic and specialist providers
Relevant documents may include:
- professional registration;
- qualifications;
- scope-of-practice statement;
- professional indemnity;
- clinical-governance procedure;
- consent documentation;
- record-keeping procedure;
- supervision arrangements;
- complaints procedure;
- referral and escalation criteria.
Construction and estates contractors
Documents may include:
- trade qualifications;
- competence records;
- construction-phase plans;
- CDM documentation;
- asbestos-awareness evidence;
- gas, electrical or specialist registrations;
- waste-carrier licence;
- permits to work;
- fire-safety information;
- project programme;
- handover and certification documents.
Training providers
Schools may want:
- trainer biographies;
- qualifications;
- learning objectives;
- course outline;
- assessment method;
- attendance or certification arrangements;
- quality-assurance procedure;
- participant feedback;
- details of any recognised accreditation.
Do not include irrelevant accreditations simply because they look impressive. Explain what each certification, membership or registration covers and how the school can verify it.
Include accessible service, quality and implementation documents
Compliance documentation shows whether a supplier appears safe and responsible. It does not show whether the service will be delivered well.
Schools may also need practical documents explaining quality, implementation and support.
These may include:
- implementation plan;
- project timetable;
- roles and responsibilities matrix;
- training plan;
- service-level agreement;
- support and escalation procedure;
- quality-assurance policy;
- complaints procedure;
- incident-management process;
- performance-reporting template;
- contract-review process;
- renewal timetable;
- exit and handover plan.
An implementation plan should clearly distinguish between supplier and school responsibilities.
| Stage | Supplier documents | School action |
|---|---|---|
| Planning | Project plan and requirements checklist | Nominate a lead and approve dates |
| Preparation | Data, site or technical specification | Provide agreed information or access |
| Training | Training plan and materials | Arrange staff attendance |
| Launch | Launch checklist and support contacts | Communicate the change internally |
| Review | Performance report | Provide feedback and agree actions |
A service-level agreement may state:
- service availability;
- support hours;
- response priorities;
- target response times;
- resolution or workaround expectations;
- planned maintenance arrangements;
- reporting;
- escalation contacts;
- service credits where applicable.
Digital products should also maintain accessibility information.
This may include:
- accessibility statement;
- testing standard;
- testing methodology;
- known limitations;
- workarounds;
- contact for reporting accessibility problems;
- remediation plan.
Documents shared with schools should themselves be usable. PDFs should contain selectable text, structured headings, meaningful links and readable contrast. Essential information should not exist only as an inaccessible image or scanned document.
Have commercial, contractual and procurement documents ready
An interested school may need formal commercial documents before it can approve the purchase.
The core commercial pack should normally contain:
- product or service overview;
- formal quotation template;
- proposal template;
- pricing schedule;
- standard terms and conditions;
- service-level agreement where relevant;
- data-processing terms where relevant;
- implementation plan;
- purchase-order instructions;
- invoice requirements;
- framework information where relevant;
- conflict-of-interest declaration;
- subcontractor information;
- renewal and exit terms.
A quotation should include:
- supplier’s legal identity;
- customer’s correct legal identity;
- quotation number;
- issue and expiry dates;
- itemised scope;
- quantities;
- net price;
- VAT;
- total price;
- delivery and implementation costs;
- payment schedule;
- contract term;
- contact details.
The standard contract should match the sales conversation.
It should not introduce:
- a longer term than was proposed;
- automatic renewal that was never disclosed;
- unexpected setup charges;
- unlimited rights to increase the price;
- major exclusions of responsibility;
- new restrictions on use;
- unclear data ownership;
- unreasonable exit charges.
Schools are advised to check their own procurement rules and select a route appropriate to the value and nature of the purchase. This may include direct purchasing, comparing quotations, using a framework or conducting a more formal competition.
Where the supplier is on a framework, keep a framework information sheet containing:
- framework title;
- framework provider;
- reference number;
- lot or category;
- start and expiry dates;
- geographic scope;
- available buying routes;
- official link;
- supplier contact familiar with the framework.
Do not describe your company broadly as “DfE approved” merely because it appears on one framework. State the precise appointment and scope.
The Department for Education’s buying guidance is intended to help schools obtain value while remaining compliant with procurement requirements.
Organise documents into a layered assurance library
Having the right documents is only useful if staff can find and share the correct versions.
A supplier should not send every file to every prospect.
Instead, create a layered document library.
Level 1: public website information
This can include:
- company details;
- service overview;
- pricing guidance;
- privacy notice;
- accessibility statement;
- general safeguarding statement;
- complaints procedure;
- framework information;
- case studies.
Level 2: sales and evaluation documents
This can include:
- sales pack;
- one-page summary;
- package details;
- indicative pricing;
- implementation overview;
- insurance summary;
- safeguarding overview;
- technical overview;
- relevant case studies.
Level 3: due-diligence documents
This can include:
- insurance certificates;
- full safeguarding policy;
- health and safety policy;
- risk assessments;
- data-processing agreement;
- security questionnaire;
- subprocessor list;
- business-continuity plan;
- standard contract;
- professional registrations;
- financial evidence.
Level 4: restricted confidential material
This might include:
- detailed penetration-test results;
- confidential financial records;
- sensitive employee information;
- DBS-related records;
- security architecture;
- incident reports;
- commercially sensitive subcontractor contracts.
Share restricted material only where necessary and through an appropriately secure route.
Use consistent filenames:
Public-Liability-Certificate-Expires-2027-03-31.pdfSafeguarding-Policy-Version-5-January-2026.pdfData-Processing-Agreement-Version-3-2.pdfImplementation-Plan-Single-School-Version-2.pdfStandard-School-Terms-Version-6.pdf
Each controlled document should contain:
- title;
- owner;
- version number;
- approval date;
- review date;
- confidentiality level where relevant.
The existing School Supplier Compliance Checklist can be used to identify which areas apply to the business and where evidence is still missing.
Create a document register and review schedule
Supplier documents become unreliable when no one is responsible for maintaining them.
Create a central register showing:
| Document | Owner | Current version | Review or expiry | Status |
|---|---|---|---|---|
| Public liability certificate | Operations director | 2026–27 policy | 31 March 2027 | Current |
| Safeguarding policy | Safeguarding lead | Version 5 | January 2027 | Current |
| DBS role assessment | HR manager | Version 2 | When roles change | Review new tutoring role |
| Data-processing agreement | Data protection lead | Version 3.2 | October 2026 | Current |
| Subprocessor list | Security lead | July 2026 | Quarterly | Current |
| Standard school contract | Commercial director | Version 6 | December 2026 | Current |
Assign an owner for each area:
- company information;
- finance;
- insurance;
- safeguarding;
- recruitment and DBS;
- health and safety;
- data protection;
- cybersecurity;
- accessibility;
- contracts;
- quality;
- subcontractors.
Review documents whenever:
- insurance renews;
- a policy reaches its review date;
- a new service launches;
- the business starts working directly with pupils;
- staff roles change;
- a subcontractor is appointed;
- a new category of personal data is processed;
- a technology or hosting provider changes;
- official guidance changes;
- an incident identifies a weakness;
- a school raises a question not covered by the existing pack.
Carry out a complete annual review even when individual documents have longer review periods.
Check the website at the same time. It should not display:
- expired accreditations;
- old employee profiles;
- outdated customer numbers;
- incorrect insurance limits;
- former subprocessors;
- unsupported compliance claims;
- broken policy links.
Record why a document is considered not applicable.
For example:
“Enhanced DBS checks are not requested for delivery drivers because their role is limited to supervised deliveries at reception and has been assessed as ineligible. Site access and supervision controls apply.”
This shows that the matter was considered rather than overlooked.
Frequently asked questions
Do all school suppliers need the same documents?
No. The required documents depend on the product, activity, contract value, personal data involved, contact with pupils and work performed on school premises. Every supplier should maintain accurate business and commercial information, but specialist documents should reflect the actual risk.
Which documents should every school supplier have?
Most suppliers should have clear legal business details, current insurance evidence, a formal quotation template, contract terms, complaints procedure, privacy information and a basic business-continuity plan. Other documents depend on the service.
Should suppliers send every document with the first email?
No. The first communication should normally contain a concise overview and relevant supporting information. Detailed compliance and due-diligence documents can be supplied when the school begins evaluating or approving the supplier.
Do schools need copies of employees’ DBS certificates?
Schools do not necessarily need to retain full copies of DBS certificates. Suppliers should handle certificate information securely and provide appropriate assurance about the checks completed. The precise evidence required depends on the role and the school’s safeguarding process.
Does every supplier need a safeguarding policy?
A supplier working directly with children should have safeguarding arrangements appropriate to the service. A business with no pupil contact may need more limited documentation but should still understand school visitor, conduct and reporting procedures.
Is a generic risk assessment sufficient?
Only where it accurately addresses the activity and circumstances. It should be reviewed against the specific school site, participants and hazards. Material differences should be covered through a site-specific assessment or amendment.
What data documents should an EdTech supplier prepare?
An EdTech supplier may need a privacy notice, data-processing agreement, data-flow information, subprocessor list, hosting and transfer details, retention schedule, security documentation, breach procedure, accessibility statement and data-exit process.
Is a privacy notice the same as a data-processing agreement?
No. A privacy notice explains processing to individuals. A data-processing agreement establishes the contractual obligations between a controller and processor where the supplier handles personal data on the school’s behalf.
Should insurance certificates be published online?
They can be, but this is not essential. Many suppliers publish a summary and provide full certificates during due diligence. The documents should be current, accurate and easy to supply.
What should be included in a safeguarding assurance letter?
It may confirm the recruitment, identity, DBS and safeguarding checks completed for relevant personnel, the training provided, the supplier’s reporting arrangements and how subcontractors are controlled. It should not contain unsupported or blanket assurances.
Do schools require three quotations?
Not for every purchase. Requirements depend on the school or trust’s procurement rules, delegated limits and contract value. Suppliers should ask which buying process applies.
What is a RAMS document?
RAMS commonly refers to risk assessments and method statements. Together they explain the hazards, controls and practical method by which work will be performed safely.
What financial documents might a MAT request?
For significant contracts, a MAT may request accounts, turnover information, credit checks, financial ratios, insurance, business-continuity information or a parent-company guarantee. The exact request should be proportionate to the contract.
Should a sole trader have the same pack as a limited company?
The legal identity documents will differ, but a sole trader may still need insurance, safeguarding, health and safety, data, contractual and professional documents appropriate to the service.
How should sensitive compliance documents be shared?
Use an appropriately secure method and share only what is necessary. Detailed security reports, DBS-related records, personal information and commercially sensitive documents should not be placed in a public download folder.
How often should supplier documents be updated?
Update them when they expire, when the business or service changes and when relevant law or guidance changes. Maintain a document register with named owners and review dates, and conduct a full review at least regularly.
What is the most important document to prepare first?
Start with a controlled supplier-information and document index. It should identify the legal business, list the available documents, show current versions and expiry dates, and direct school staff to the correct contact for further questions.