Red Flags to Watch for When Choosing a Cheap Document Scanning Provider
A suspiciously low scanning quote is rarely the bargain it appears to be. The biggest warning signs are vague pricing that excludes preparation and indexing, missing security accreditations, no written quality control process, and silence on what happens to your original documents. Any one of these can turn a cheap project into an expensive failure — and because you’re handing over business records that may contain personal data, the risks aren’t just financial. Under UK GDPR and the Data Protection Act 2018, your business remains the data controller even when a third party is doing the scanning, so a careless provider’s mistakes become your compliance problem.
Red Flag 1: A Headline Rate That Doesn’t Say What’s Included
The oldest trick in the book is quoting a low per-image rate that covers only the moment paper passes through the scanner. Everything that makes scanned files usable is then billed as an extra: staple and binding removal, document preparation, indexing, OCR, file naming, secure collection, and return delivery or destruction of originals.
Preparation alone typically accounts for a large share of the labour in a scanning project — archive boxes full of stapled, clipped and bound paperwork don’t feed themselves through a production scanner. If the quote doesn’t itemise prep, assume it will appear later as a surcharge. Ask for a fully inclusive price per box or per project, in writing, with the exclusions listed. If a provider won’t commit to that, walk away.
Red Flag 2: No Security Accreditations or Vetted Staff
Professional scanning bureaus operate to recognised standards. The ones worth looking for include:
- ISO 27001 — information security management, covering how your data is handled from collection to delivery
- ISO 9001 — quality management, evidence of documented and audited processes
- BS EN 15713 — the standard for secure destruction, relevant if originals are shredded after scanning
- Staff vetting — screening such as BS 7858 for anyone handling confidential records
Budget operators frequently hold none of these, because certification costs money and requires discipline. That matters: the ICO can fine organisations up to £17.5 million or 4% of global turnover for serious data protection failures, and a breach caused by an unvetted subcontractor still lands at your door. Check certificates are current and issued by a UKAS-accredited body — a logo on a website is not evidence.
Red Flag 3: No Written Quality Control or OCR Accuracy Commitment
Scanning errors are silent. A missed page, a double-feed, a skewed image or a mis-indexed file won’t announce itself — you’ll discover it months later when someone needs the document and it isn’t there. A credible provider will describe, in writing, how they prevent this: double-feed detection on production scanners, image inspection sampling, page-count reconciliation against the original files, and a defined rescan process when problems are found.
Questions that expose a weak operation
- What percentage of images do you quality-check, and how?
- How do you verify that page counts match the source documents?
- What OCR accuracy do you achieve on typical office documents, and how is it measured?
- Who fixes indexing errors found after delivery, and at whose cost?
Hesitation, jargon, or “we’ve never had a problem” are all answers of a kind — just not reassuring ones. A cheap provider that skips quality control isn’t cheaper; it simply moves the checking work onto your team after delivery.
Red Flag 4: Vague Answers About Your Original Documents
Between collection and final destruction or return, your records should be traceable at every stage. That means barcoded box tracking, a documented chain of custody, secure vehicles, and an alarmed, access-controlled facility — not pallets stacked in a unit on an industrial estate. If originals are to be destroyed after verification, you should receive a certificate of destruction; if they’re to be retained, ask where and under what conditions. Many businesses pair a backfile scanning project with secure document storage for records that must be kept in paper form, which keeps everything under one accountable roof.
Retention matters here too. Records such as accounting documents (six years under the Companies Act 2006 for private companies) or employee liability insurance certificates carry defined UK retention periods, and destroying originals prematurely — or losing them mid-project — can leave you exposed in an audit or dispute.
Red Flag 5: No Pilot, No References, No Contract Detail
A professional bureau will happily scan a sample box first, so you can inspect image quality, file naming and indexing before committing the whole archive. They’ll also provide references from comparable UK clients and a contract that spells out turnaround times, liability, insurance and data processing terms — including the Article 28 processor clauses UK GDPR requires when personal data is involved. A provider who resists all three is asking you to take everything on trust, at scale, with your business records.
A Quick Pre-Signature Checklist
- Fully itemised quote covering prep, indexing, OCR and delivery — no open-ended extras
- Current ISO 27001 certification and vetted staff
- Written quality control and rescan process
- Clear chain of custody and a stated plan for originals
- Pilot project offered before full commitment
- GDPR-compliant data processing agreement in the contract
Price matters, but it’s the last filter to apply, not the first. Eliminate the providers that fail the checks above, then compare costs among the ones that remain — you’ll usually find the gap between a credible quote and a cheap one is far smaller than the cost of a failed project. For a deeper look at what a professional service should include, see our document scanning service page, or browse more guides in our resources library.








