A Supplier Register That Expires On Its Own
Almost every prequalified supplier list has the same defect: nothing removes anyone. A firm assessed three years ago on documents nobody has looked at since is still on it, still being invited, still winning work. Our prequalification module has a shelf life built into it — a validity period you set, a date stamped at approval, and a job that runs every morning and quietly takes expired suppliers out of circulation.
Ask to see a prequalified supplier list and you will usually be shown a spreadsheet. Ask when each firm on it was last assessed and the conversation changes. Somewhere on that list is a company that submitted a tax compliance certificate in 2022, has since changed directors, and is still being invited to quote because removing anyone from the list requires a decision and nobody wants to be the one who made it.
This is a register problem rather than an assessment problem. The assessment was probably fine when it happened. What was missing was an expiry date and something that acts on it.
Four of the six posts in this category describe something our product does not do. This one describes something it does, in detail, because a public entity evaluating software needs the specifics of both — and because a vendor who only publishes the flattering half is not worth reading on the other half.
The pipeline, end to end
Your organisation gets a public application page at a link you choose. Suppliers apply through it directly. There is no login, no account to create and no invitation required — you publish the link in a notice, on your website or in an advertisement, and applications arrive.
Four things are compulsory on the form: the company name, an email address, a phone number, and an incorporation document as a PDF or an image. Everything else is optional and captured if provided — contact person, KRA PIN, registration number, years in business, category, physical address, county and website. An email address that has already applied to you is caught as a duplicate.
| Status | What it means | What moves it on |
|---|---|---|
| Submitted | The application has arrived and is waiting | A reviewer opening it |
| Under review | Somebody is working on it | A decision, or a request for more |
| Information requested | You have asked for something specific | The applicant supplying it — through a public page, with no login |
| Approved | Qualified, with an expiry date stamped | Time, or a rejection later |
| Rejected | Declined, with the reason recorded | A fresh application |
| Expired | The qualification period has run out | The requalify action |
The information-request loop is worth dwelling on because it is where most prequalification exercises leak. You write a message, itemise what is missing, and the applicant gets a tracking page where they can see their status and submit exactly what was asked for. They still do not need an account. In a county context, where a supplier may be a two-person firm without an IT department, that difference decides whether the file gets completed or abandoned.
Approving an application creates or links a supplier record, so a qualified applicant becomes someone you can actually raise a [request for quotation](/glossary/request-for-quotation) against. Documents are stored with their type, size and original name, can be moved into the document vault, and are served to mobile devices through short-lived signed links rather than public URLs.
The part that matters most: it expires by itself
You set a validity period once — anything from one month to ten years, twelve months by default. When an application is approved, that period is added to the date and stamped onto the record as a qualified-until date.
Every morning at six, a scheduled job looks for approved suppliers whose date has passed. For each one it sets the status to expired and deactivates the linked supplier record, which is the part that makes it a control rather than a label. An inactive supplier drops out of the list you raise requests for quotation against. They stop being invited because they are no longer selectable, not because somebody remembered.
A prequalified list that nothing removes anyone from is not a register. It is a list of everyone who ever applied.
One supplier, one twelve-month cycle
The expiry is the feature. Everything before it is a form; the thing that makes it a register with integrity is that it removes people without anyone having to decide to.
Scoring, described precisely
There are two scores on an application and they are different animals. The first is a manual score, typed by the reviewer, which is exactly what it sounds like.
The second is an automated evaluation, and this needs describing carefully because "AI supplier scoring" is a phrase that invites people to imagine something it is not.
- What it produces. A score from nought to a hundred, a written rationale, a breakdown of the factors behind it, and a list of risk flags with severity levels.
- What it reads. The information typed on the application, and whether the expected documents are present. That is the whole of its input.
- What it does not read. The contents of any uploaded certificate. The language models behind it handle text, not images, so a scanned tax compliance certificate is a file it can see the existence of and nothing more.
- What it verifies. Nothing. No credential is checked against any registry or authority. A KRA PIN and a registration number are stored as the applicant typed them.
- How binding it is. Not at all. It is advisory, a person still approves or rejects, and if no provider is available or the response cannot be parsed it fails quietly and the reviewer simply sees that no evaluation is available.
The honest way to describe this in a procurement document
It is a structured second opinion on a written application, not due diligence. It will notice that a firm claims two years in business while applying for a category that usually needs more, and it will say so. It will not notice that the certificate attached expired last year, because it never opens it. Anyone relying on it to catch a forged document will be disappointed, and it was not built for that.
What it does not do, and why these five matter here
A commercial buyer can live with most of the list below. A public entity generally cannot, because its process is prescribed rather than chosen — so each of these is worth checking against your own regulations before you decide the module fits.
There is no evaluation criteria configuration
The entire settings screen for this module holds three things: your public link, whether you are currently accepting applications, and the validity period. There is nowhere to define criteria, weightings, a pass mark, or different requirements per category. The assessment is a reviewer reading an application and forming a view, supported by two scores. If your procedure specifies a scored matrix that must be applied consistently, that matrix lives outside this system.
There is no committee
The reviewer is a single field on the application, and it is overwritten by whoever acted last. One person approves. There is no panel, no independent second assessment, no record of several evaluators reaching a view, and no consensus requirement. Where a prequalification committee is mandatory, the committee's deliberation and its minutes are documents you hold elsewhere; what this system records is the decision, its author and its date.
There is no appeal
A rejection records the reason and that is where the record ends. There is no state for an application under appeal, no route for an unsuccessful applicant to contest a decision, and no second-stage review. An applicant who wants to challenge an outcome does so by whatever means your procedure provides, and the system is not part of it.
Nothing is verified against any registry
This is the one most often assumed. A KRA PIN, a registration number and a compliance certificate are captured, stored and shown to your reviewer. Nothing is checked against the tax authority, the companies registry or any other source. Verification, where your process requires it, is a human step performed outside this product.
Nobody is warned before an expiry
The qualified-until date is read by exactly one thing: the job that expires it. There is no reminder thirty days out, no notice to the supplier, and no list of qualifications approaching their end. Both sides find out on the morning it happens, when the supplier stops appearing in the selectable list. For a register this is survivable; for a working relationship it is abrupt, and it is the first thing we would add.
Built and working
- A public application page per organisation, no supplier login
- Six-state lifecycle including an information-request loop
- A public tracking page where applicants supply what was asked for
- Documents with type, size, vaulting and signed mobile streaming
- Manual and advisory automated scoring, with risk flags
- Approval creating a usable supplier record
- A validity period you set, stamped at approval
- Daily automatic expiry that deactivates the supplier
- A requalify action, and a preferred-supplier flag
- A complete token-authed API mirror of every review action
Not built
- Evaluation criteria, weightings or a pass mark
- A committee, a panel, or more than one recorded evaluator
- An appeal stage of any kind
- Verification of any credential against any registry
- Reading the contents of uploaded certificates
- Any warning before a qualification expires
How to use it well
-
Set the validity period to match your policy, not the default
Twelve months is the default because it is common, not because it is right for you. It takes one field and it determines the whole rhythm of the register.
-
Publish the link where suppliers already look
The page needs no login and no invitation, which is its main advantage over an emailed form. Put it in the notice, not in an attachment.
-
Use the information-request loop rather than rejecting incomplete files
An itemised request and a tracking page turn an abandoned application into a completed one, and the exchange stays on the record.
-
Keep your committee minutes alongside, and reference the application number
The system records the decision, its author and its date. If your process requires a panel, its deliberation is your document and it should point back to the record here.
-
Diary your own expiry reminders until we build them
Nothing warns you. A calendar entry a month before each cohort expires is a two-minute habit that avoids a supplier vanishing mid-procurement.
-
Treat the automated score as a prompt to look, not a finding
Its risk flags are worth reading and none of them is evidence. Verification stays with a person.
Built and verified in the code
- A public application page per organisation at a link you set, with no supplier login and no invitation needed. Retired links keep resolving, so old notices do not break.
- A six-state lifecycle — submitted, under review, information requested, approved, rejected, expired — with the reviewer, decision and timestamp recorded at each step.
- An information-request loop with a public tracking page, so an applicant can supply exactly what was itemised without creating an account.
- Document handling with type, original name, size and mime recorded, a vaulting action, and short-lived signed links for mobile viewing rather than public URLs.
- A validity period from one month to ten years, twelve by default, stamped onto the record as a qualified-until date at approval.
- Daily automatic expiry at 06:00 that sets the status to expired and deactivates the linked supplier so they drop out of the selectable list, with a count logged. A requalify action reverses it.
- Manual scoring, plus an advisory automated evaluation producing a score, a rationale, a factor breakdown and risk flags, failing soft when no provider is available.
- A preferred-supplier flag with the date it was set.
- A complete token-authed API mirroring every review action for mobile use.
Not built — verified absent
- No evaluation criteria, weightings or pass mark. The module's settings are the public link, whether applications are open, and the validity period. Nothing else is configurable.
- No committee or panel. The reviewer is a single field, overwritten by whoever acted last. There is no multi-evaluator record and no consensus requirement.
- No appeal stage. A rejection records its reason and the record ends there.
- No verification of any credential. Tax and registration numbers are stored exactly as typed and checked against nothing.
- The automated evaluation does not read documents. It scores the typed application and whether expected files are present; the language models behind it handle text, not scanned certificates.
- No warning before expiry. The qualified-until date is read only by the job that acts on it. Neither you nor the supplier is told in advance.
Where the line falls
- If you need a supplier register that collects applications properly and removes people when their qualification lapses, that is exactly what this is, and the expiry behaviour is the strongest part of it.
- If your procedure prescribes a scored evaluation matrix applied by a committee with an appeal route, those three elements live outside this system and your documentation has to carry them.
- If you need credentials verified rather than collected, that is a human step and no part of this module performs it.
Expiry warnings are the obvious first addition and a small piece of work — a configurable notice period, a list of qualifications approaching their end, and a message to both sides. A configurable criteria matrix with weightings and a recorded panel decision is larger but well understood, and it is the thing that would make this module fit a prescribed public process rather than sit alongside one.
Verified against the repository on 7 August 2026, including reading the automated evaluator to confirm what it does and does not read.
The reason this module gets a post of its own is that the expiry behaviour is unglamorous and rarely built. Everyone builds the form. Very few build the thing that quietly takes a firm off the list at six in the morning a year later, without anyone having to be the person who decided it. That is the part that keeps a register honest, and it is the part worth asking every vendor about.
Send us your prequalification procedure
If you run a prequalification exercise on a cycle, send the procedure and the criteria you are required to apply. We will tell you which steps the module covers today, which stay with your committee, and what it would take to bring the matrix inside the system.
Talk to us about supplier prequalification