Buyer's Tool

The ASP selection scorecard.

Twenty-seven criteria, weighted to 100, for choosing an e-invoicing service provider. Score any vendor with it. Score us with it — we will answer every line in writing.

Most e-invoicing provider comparisons are feature matrices, and feature matrices are the wrong instrument. Every serious provider will clear a feature list, because the features are largely dictated by the standard. What separates them is what happens in year three: whether you can leave, who pays when the specification changes, and whether you can get at your own data without asking.

This scorecard is weighted accordingly. Custody and exit carry as much weight as accreditation, and more than every feature question combined. It is deliberately unflattering to a certain kind of vendor — including, on some lines, to us.

One piece of timing before the criteria. In the UAE, failing to appoint an accredited service provider within the prescribed timeline is itself a penalised violation, at AED 5,000 for each month of delay under Cabinet Decision No. 106 of 2025 — the first line of the annexed table, accruing whether or not you have issued a single invoice. A leisurely selection process is not a neutral act. See what non-compliance costs across the GCC.

How to use it

Score each criterion 0 to 3 as you work through a vendor's answers. Nothing is stored or sent anywhere — the total is calculated in your browser and disappears when you close the tab. Run it once per shortlisted provider and compare the shapes, not just the totals.

1. Data custody & exit

Weight 20

If we terminate, what do we get back — in what format, at what cost, and within what timeframe?

Good: a defined export of the full archive in the original structured format, at no charge, inside a stated number of days, written into the contract.

Poor: "we'll provide an export" with no format, price or deadline attached.

Red flag: the answer arrives verbally and never makes it into the agreement.

Who physically holds the private key or certificate used to sign our invoices?

Good: you hold it, or it is held on your behalf under documented access, renewal and hand-back terms.

Poor: the provider holds it and the contract is silent on what happens to it at termination.

Red flag: nobody on the vendor's side can tell you where the key lives without checking.

Can we extract our own structured invoice data — the XML, not a PDF or a report — on demand?

Good: continuous programmatic access into systems you control.

Poor: a support ticket, a delay, and a CSV.

Red flag: "what would you need the XML for?" — the data is yours; the question is misdirected.

Who owns the integration code built between our ERP and your platform?

Good: you do, with the repository handed over, whoever wrote it.

Poor: the provider owns it, so leaving means rebuilding the integration as well as migrating.

Red flag: the integration is described as "included" and its ownership is never stated.

2. Accreditation & mandate coverage

Weight 18

Are you accredited in each specific jurisdiction we file in — and can you evidence it?

Good: a named accreditation per country, with the registration reference, for every jurisdiction on your list.

Poor: regional language — "GCC-accredited", "Middle East coverage" — which is not a status any authority grants.

Red flag: accreditation in one country presented as though it covered the others. It never does.

What is your position in the jurisdictions we will enter in the next 24 months?

Good: a candid split between where they are accredited today, where an application is filed, and where they are not going.

Poor: everything answered as "on the roadmap".

Red flag: no jurisdiction is ever ruled out. A provider covering everywhere is describing ambition, not accreditation.

Have you taken a live production participant through clearance in our jurisdiction?

Good: yes, with a date, and a reference you can speak to.

Poor: test-environment conformance presented as production experience.

Red flag: "certified" and "live" used interchangeably. They are different claims and the gap between them is where programmes slip.

Who monitors mandate changes, and how would we hear about one?

Good: a named owner, a stated channel, and evidence of a change they pushed to clients before it took effect.

Poor: you find out when something is rejected.

Red flag: the provider's own published material still cites superseded phase dates.

3. Certification & security posture

Weight 14

What formal certifications do you hold, and can we see the certificates?

Good: current certificates produced on request, with scope statements — the scope matters more than the logo.

Poor: "aligned with", "compliant with", "built to the principles of".

Red flag: a certification badge whose scope excludes the platform you are buying.

In which country does our invoice data physically reside, and can you keep it there?

Good: a named region, contractually committed, with in-country hosting available where a mandate or your policy requires it.

Poor: "the cloud", or a region that moves at the provider's convenience.

Red flag: residency described as a roadmap item while the contract is silent.

When was the platform last penetration-tested by an independent party, and will you share the summary?

Good: within the last 12 months, with a summary or attestation available under NDA.

Poor: internal testing only, or a date nobody can produce.

Red flag: the test predates the current architecture.

How is administrative access to our tenant controlled and logged?

Good: role-based access, enforced multi-factor authentication on privileged accounts, and an audit log you can read yourself.

Poor: MFA available but optional; audit logs visible only to the vendor.

Red flag: "supported" doing the work of "enforced". Ask which it is, in writing.

4. ERP fit & integration depth

Weight 14

Is there a real connector for our ERP and version, or an API we would build against?

Good: a named, versioned connector with live clients on your ERP release.

Poor: "we integrate with everything via REST" — true of everyone, and it means the work is yours.

Red flag: your ERP appears on the logo wall but nobody can name a client running it.

What happens to the integration when we upgrade the ERP?

Good: a stated support window per ERP version and a documented upgrade path, at a known cost.

Poor: "we'd need to scope that at the time".

Red flag: your upgrade cycle and their support window have never been compared.

Which fields will you need that our ERP does not currently hold?

Good: a specific gap list produced from your data, before contract.

Poor: a generic field list handed over for you to reconcile yourself.

Red flag: master-data readiness treated as entirely your problem. It is mostly your problem — but a provider who has never raised it has not done this before.

How do inbound documents reach us, and in what state?

Good: structured inbound delivered into your ERP, with a defined handling path for what fails validation.

Poor: inbound treated as a portal to log into.

Red flag: the demo covers only outbound. In several GCC sectors most of the volume is inbound.

5. Operational resilience

Weight 10

What is the SLA, and what actually happens when you breach it?

Good: a stated availability figure with a defined measurement window and a remedy that is not purely a service credit.

Poor: a percentage with no measurement definition, which is unfalsifiable.

Red flag: the SLA is a marketing number that does not appear in the contract.

What happens to our invoices when the tax authority's platform is unavailable?

Good: queue, automatic retry, and a documented notification path — plus the authority's own malfunction-reporting duty handled on your behalf where the rules require it.

Poor: failures surface as errors for your team to chase.

Red flag: in the UAE, failing to notify the Authority of a system failure carries AED 1,000 per day. Establish whose obligation that is before you need to know.

What are the stated recovery objectives, and have they been tested?

Good: an RPO and RTO with a date for the last restoration test.

Poor: numbers offered with no evidence anyone has exercised them.

Red flag: recovery objectives quoted from a sales deck rather than a runbook.

6. Change absorption

Weight 10

When the authority revises the specification mid-contract, who pays?

Good: mandated regulatory changes absorbed by the provider within the subscription, stated in the contract.

Poor: every revision becomes a change request against your budget.

Red flag: this is the single most reliable source of unbudgeted spend in year two, and the easiest to fix before signature.

How quickly did you ship the last mandate change, and can you show it?

Good: a specific recent example with dates — spec published, change shipped, clients live.

Poor: a general assurance of agility.

Red flag: no example exists because they have not yet lived through one.

7. Commercials & lock-in

Weight 8

What is the pricing basis, and what happens if our volume doubles?

Good: transparent bands, with the cost of growth modelled before you sign.

Poor: per-document pricing with no ceiling, which turns your own growth into a penalty.

Red flag: nobody has modelled your actual volumes against the price list.

What is the term, the notice period, and the auto-renewal behaviour?

Good: a term you chose, with a notice window wide enough to run a migration inside.

Poor: a three-year term with a 90-day notice window and automatic renewal.

Red flag: the notice period is shorter than the time it would take to migrate. That is not an accident.

What is priced separately, and what does onboarding actually cost?

Good: a single fixed onboarding figure with the scope written down.

Poor: a low headline subscription with implementation, connectors, entities and support priced separately.

Red flag: the second entity costs almost as much as the first. Ask for group pricing before, not after.

8. Support model

Weight 6

Who answers when an invoice is rejected at 4pm on the last day of the month?

Good: named support in your timezone, with an escalation path to someone technical.

Poor: a ticket portal with a next-business-day target.

Red flag: support hours are quoted in a timezone that is asleep during your month-end.

Is support available in the languages our finance team actually works in?

Good: Arabic and English support where the deployment needs it, including written material.

Poor: English-only support for an Arabic-first finance function.

Red flag: the portal is localised but the humans behind it are not.

Are rejections analysed, or just resubmitted?

Good: rejections categorised and fed back into master-data fixes, with reporting you can see.

Poor: each failure corrected individually, forever.

Red flag: no rejection reporting exists, so nobody can tell you why last month was worse than the one before.

0 / 100
0 of 27 criteria scored

Start scoring to see a running total.

Reading the score.

The total is less informative than the shape. A provider scoring 80 with everything lost in section 1 is a worse risk than a provider scoring 70 evenly, because custody failures are the ones you cannot fix later without changing provider — which is exactly the thing custody failures prevent.

Bands
  • 85–100. Strong. Verify the top three claims in writing and proceed.
  • 75–84. Sound. Fix the weakest section contractually before signature — it is far cheaper now than in year two.
  • 60–74. Workable only with specific contractual remedies. Identify the three lowest lines and make them conditions.
  • Below 60. Keep looking, or accept that you are buying a dependency rather than a service and price the eventual exit into the business case.

Score us too.

We will answer all twenty-seven lines in writing, including the ones where the answer is no. That is not a rhetorical offer: some of these criteria have answers we would rather were different, and you should have them before you decide rather than after.

The reason we publish the scorecard at all is that a buyer who asks these questions of everyone gets better outcomes than one who asks them of nobody — and we would rather compete on the answers than on the questions being left unasked. The five lock-in questions are the shortest version if you only have one meeting.

Send us the scorecard →

Mandate Monitor

Changes to these mandates, when they happen.

Occasional notes on GCC e-invoicing from practitioners working inside these programmes. No sequence, and you can leave in one click.

See our privacy policy.