What Quality Control Standards Should a Scanning Provider Follow?
A professional scanning provider should be able to show you a documented, auditable quality control process covering four things: image capture accuracy, indexing accuracy, completeness of the batch against the original file, and a chain of custody that survives legal scrutiny. In practice that means working to BS 10008:2020, sampling every batch rather than every hundredth one, running a two-stage check on indexed metadata, and keeping a rejection and rework log you are allowed to see. If a supplier cannot describe their QC in those terms, they are inspecting on hope rather than on process — and you only find out when a file you need in court turns out to be missing pages three to seven.
The standards that actually matter in the UK
Scanning is an unregulated market, so any supplier can claim to be “fully compliant”. These are the benchmarks that carry real weight with auditors, regulators and courts:
- BS 10008:2020 — the core UK standard for evidential weight and legal admissibility of electronic information. It governs how you capture, index, store and reproduce a document so a court will accept the scan as a faithful copy of the original. This is the one that matters most if you plan to destroy paper after scanning.
- BIP 0008 — the accompanying code of practice. A provider working to BS 10008 should be able to hand you their BIP 0008-style documented procedures, not just quote the standard number.
- ISO 9001 — quality management. Confirms there is a defined process with corrective actions, not just careful individuals.
- ISO 27001 — information security management. Relevant to QC because audit logging determines whether you can prove nobody altered an image post-capture.
- ISO 19005 (PDF/A) — the archival file format standard. A provider outputting standard PDF rather than PDF/A for long-term records has skipped a QC decision, not made one.
- UK GDPR and the Data Protection Act 2018 — accuracy is a statutory principle, not a nice-to-have. A misindexed personal file is an accuracy failure the ICO can act on.
Ask for certificate numbers and the certification body, then check them. “Working towards ISO 27001” is not the same as holding it.
Image quality control: what good looks like
Every scanned page should be checked against defined, written acceptance criteria — not one operator’s judgement on the day. A credible provider will specify:
- Resolution — 300 dpi as the working minimum for business records, 400–600 dpi for small print, engineering drawings, carbon copies or anything destined for OCR under difficult conditions. 200 dpi is a red flag for anything you intend to rely on.
- Colour mode — bitonal for clean typed text, greyscale or 24-bit colour where the colour carries meaning (highlighter, signatures in blue ink, RAG-rated forms, medical charts, stamps).
- Deskew, despeckle and crop — applied consistently, and critically, applied so nothing at the page edge is clipped. Over-aggressive auto-crop that shaves a margin annotation is a silent data loss.
- Legibility check — an operator confirms the page is readable at 100% zoom, not just that a file exists.
- Blank page handling — a documented rule about what counts as blank. Auto-blank-removal has been known to delete faintly printed reverse sides.
Sampling rates and 100% inspection
Ask directly: what percentage of images does a human actually look at? Bulk providers competing purely on price often sample 1–2% of pages. For low-value archive that may be acceptable; for HR, legal, medical or finance records it is not. A serious provider will offer tiered QC — 100% visual inspection for critical batches, statistically valid sampling for the rest, with the sampling rate written into the contract.
Completeness: proving nothing went missing
The failure that hurts most is not a blurry scan — it is a page that never made it through the feeder. Double-feeds, staples missed at prep, and pages stuck together with age all cause silent losses. Controls that catch them:
- Page counting at prep and reconciliation after capture — the count going in must match the count coming out, and any variance must be investigated and logged, not adjusted away.
- Ultrasonic double-feed detection on production scanners, with the batch stopped and rescanned when it triggers.
- Separator sheets and barcode patch codes so document boundaries are defined mechanically rather than guessed at afterwards.
- Batch-level reconciliation reports issued to you, showing pages in, pages out, rejects and rescans.
- Retention of the paper until sign-off — originals should never be shredded before you have accepted the digital files. Any provider that destroys on completion rather than on your approval has removed your only means of correcting an error.
Indexing and OCR accuracy
A perfect image with the wrong index value is an unfindable document. Quality control on metadata should be explicit and measurable:
- Double-key verification for critical fields — two operators key the same value independently and the system flags mismatches. This is standard practice for names, dates of birth, NI numbers, account numbers and case references.
- Validation rules — date formats, postcode patterns, checksum-validated reference numbers, and lookups against a supplied master list so a client reference that does not exist cannot be entered.
- A stated accuracy target — 99.5% or better at field level is a reasonable commercial benchmark; ask what the measured figure was on their last three comparable projects.
- OCR confidence reporting — for searchable PDFs, the provider should report character confidence and route low-confidence pages to manual review rather than shipping unreliable text silently.
Be wary of a single headline “99.9% accurate” claim with no definition. Accurate at character level, page level or field level are wildly different things — 99.9% character accuracy still means roughly two errors on a dense A4 page.
Chain of custody, security and audit trail
Quality control extends to the handling of the paper itself. Under UK GDPR you remain the data controller; the scanning bureau is your processor, and Article 28 requires a written processing agreement. Expect barcoded box tracking from collection onward, sealed vehicles, DBS-checked staff, a secure production area with no personal devices or removable media, and a full audit log showing who touched each batch and when. Encrypted delivery — SFTP or encrypted media, never an unprotected email attachment — should be the default. If you are weighing up the wider security picture, our guide to the security risks of sending confidential files for scanning covers the handover points in more detail.
How to verify the claims before you commit
- Run a paid pilot on 5–10 of your worst boxes — poor condition, mixed sizes, handwriting — and inspect the output yourself against your own criteria.
- Ask to see a redacted QC report and rework log from a live project.
- Request a facility tour and watch an actual QC station in use.
- Get the acceptance process, sampling rate, defect definitions and remedy period written into the contract, with a stated window in which you can reject work at no cost.
- Confirm originals are retained until you sign off, and that secure destruction only happens on your written instruction with a certificate issued.
Quality control is the single clearest signal of whether a supplier is running a process or running a price. A provider with genuine standards will have the paperwork ready; one without will steer you back to the per-page rate. EvaStore’s document scanning service and secure document storage are built around documented, auditable procedures, and there is more practical guidance across our resources library.








