Do not skip references. Ask to speak to schools of a similar size and structure, and ask them the awkward questions: what went wrong during setup, how responsive is support, and would they choose the same system again. The UK and Irish market has several established providers, so you have room to compare rather than settle.
Build a simple total-cost model across the contract term. Put licensing, onboarding, training, add-on modules, transaction fees and support side by side for each provider, projected over three to five years. A modular provider such as Compass Education makes this easier to reason about, because you can see which functions you are paying for and add others only when you need them, rather than buying a bundle you half use.
None of this means throwing every spreadsheet away. A quick model or a one-off analysis still has its place. The point is that the system of record, the place your live data lives, should not be a shared file that anyone can overwrite. As a trust adds schools, the case for a single, permission-controlled MIS only gets stronger. Start by mapping what each school records today, agree a common structure, then move to a platform that holds all of it in one place.
The cheapest headline price often is not the cheapest system to own. Ask for every cost in writing, model the full term, and compare providers on the total rather than the quote. That is the figure governors will ask about, so bring it to the table first.
Any vendor claiming ISO 27001 or PCI-DSS Level 1 certification, Compass Education UK Education included, should be able to produce current, dated certification evidence on request rather than a general assurance statement. A useful due diligence exercise is to ask every vendor on a shortlist for that evidence side by side. A vendor that can produce an up-to-date certificate on request has clearly built the audit process into how it runs the business; one that cannot has usually not been through that audit at all.
Beyond hosting location and certification, a few further questions round out proper due diligence: how often is the system independently penetration-tested, what is the vendor's data breach notification process, and does the school retain the ability to export its full data set on request rather than being dependent on the vendor for access.
