Expense Management Software RFP Checklist for Kenya (Free Template)
A 50-point expense management software RFP checklist for Kenyan organisations: vendor questions on approvals, M-Pesa, ERP posting, eTIMS and audit trail, evidence requests and a free Excel scoring template.

Short answer: Score expense management software vendors on evidence from your own approval chains, payment rails and ERP, not on their standard demo. Our free checklist gives you 50 requirements in ten areas, the question to put to each vendor, the evidence to ask for, and a spreadsheet that weights and scores up to three shortlisted suppliers.
Download the expense management software RFP checklist and scoring template (Excel, 23 KB)
Every expense management brochure promises faster approvals and full control. The differences only show when you ask specific questions. Can finance add an approver without the vendor's developers? Is M-Pesa payment built in, or is it a file someone uploads after approval? Which ERPs does the vendor post to in production in Kenya today? Can the system produce the full evidence for last month's largest payment in minutes? A scored process also gives your board, auditors and donors a record of why you chose the vendor you did.
A word on who wrote this. Creodata sells expense management software for Kenyan organisations, so we have written criteria that any serious vendor, including us, should be able to evidence. Use the checklist to score us alongside everyone else. It is a procurement aid, not tax or legal advice: confirm current requirements with KRA guidance, your tax adviser and your auditors before you issue an RFP.
What is in the checklist
The workbook has three tabs. Read me explains how to use it and the scoring scale. Requirements holds the 50 requirements. Each one has a note on why it matters in Kenya, the question to ask, the evidence to request, a priority, an optional weight override and scores for up to three vendors. Scoring summary calculates the results.
| Area | Requirements | What it tests |
|---|---|---|
| 1. Request types and capture | 7 | Petty cash, reimbursements, supplier invoices, cashbook payments, imprest, per diem, capture with required documents |
| 2. Approval routing and delegation | 6 | Chains by department, request type and amount, KES thresholds, segregation of duties, delegation, reasons, budget and grant coding |
| 3. SLA and escalation | 4 | Deadlines per stage, automatic escalation, reminders, a live view of where requests wait |
| 4. Payments: M-Pesa and bank | 6 | M-Pesa B2C and B2B, status reconciliation, bank payments, duplicate and altered-payment controls, gateway arrangements |
| 5. ERP and general ledger posting | 5 | Automatic posting, GL and dimension mapping, failed postings, document links, supplier master data |
| 6. Documents and records (EDMS) | 4 | Governed document storage, versions, retention, receipt data extraction |
| 7. Tax and data protection | 4 | eTIMS invoice capture and validation, withholding tax and VAT, Data Protection Act, 2019 |
| 8. Security, access and audit trail | 5 | Single sign-on and MFA, role-based access, append-only audit trail, hosting and recovery, security testing |
| 9. Reporting and audit evidence | 4 | Role dashboards, standard reports and exports, a complete evidence pack per payment, BI access |
| 10. Vendor, delivery, commercials and exit | 5 | Kenyan references, local support, implementation plan, three-year cost, exit |
Of the 50 requirements, 30 are marked Must, 17 Should and 3 Could. By default a Must weighs 5, a Should 3 and a Could 1. You can change those defaults on the summary sheet, or type a number in the Weight override column to set the weight of any single requirement. Vendors are scored from 0 (not available) to 5 (exceeds the requirement, with evidence from production), and 3 means "meets it with configuration". The summary shows each vendor's weighted score, coverage, a must-have failures count of Must items scored below 3, and a score by area, so strength in one area cannot hide weakness in another. On the Requirements sheet, any Must scored below 3 is shaded red.
How to use the workbook
- Name your vendors. Type up to three shortlisted vendors in the yellow cells on the Scoring summary sheet. Their names flow into the score column headings.
- Set priorities before any demo. Finance, internal audit, IT and procurement agree which rows are Must, Should or Could for your organisation. Change priorities rather than deleting rows, so the record shows what you considered.
- Delete or add rows. Delete rows that do not apply. To add one, insert it inside the table and copy the formulas in columns I and M to O, so the summary picks it up.
- Send the questions. The "Ask the vendor" and "Evidence to request" columns are your RFP questions. Require written answers.
- Score after demos and evidence. Each panel member scores independently from 0 to 5, then the panel agrees one score per row.
- Read the summary. Look at the must-have failures count first, then the weighted score and the area scores.
How to run the process
- Define scope. List the request types you need (petty cash, reimbursements, supplier invoices, cashbook payments, imprest, per diem), your approval matrix, your payment rails and your ERP.
- Long-list by provider type. Global expense suites, local SME and petty cash apps, ERP expense modules and workflow-first finance systems solve different problems. Our buyer's guide to expense management software in Kenya maps each type. A short request for information built from your Musts removes vendors that cannot meet the basics.
- Issue the RFP. Send the vendor questions and evidence requests. For every payment rail, ERP and tax feature, ask whether it is live in Kenya, planned, or to be built for you.
- Run scripted demos on your own approval chains and sample requests (see below).
- Call references of a similar size and type, and ask what went wrong, not only what went right.
- Score independently, then calibrate as a panel. This stops the panel anchoring on whoever speaks first.
- Negotiate. Compare three-year costs on the same basis, read the exit clause, and agree what counts as configuration and what is a paid change request.
- Write the recommendation. Attach the workbook, area scores, must-have failures and reference notes.
The must-haves, area by area
These are the rows marked Must by default. Treat them as the minimum any shortlisted vendor should evidence.
1. Request types and capture
Petty cash with enforced floats and limits, reimbursement claims with a receipt on every line, supplier invoice requests with the order and delivery evidence attached, and required fields enforced for each request type. Imprest and per diem are marked Should and Could by default. Public-sector bodies, counties and many NGOs will raise imprest to Must, because the rule that a second imprest is not issued until the first is surrendered has to be enforced somewhere. Our guide to petty cash management in Kenya covers the controls in more detail.
2. Approval routing and delegation
Chains resolved by department, request type and amount, changed by finance without code. KES thresholds whose changes are approved and logged. No self-approval, and no one approving and releasing the same payment. Time-bound delegation during leave that is recorded against each approval, and mandatory reasons for returns and rejections. Route three requests of rising amounts in the demo and watch where each goes. Payment approval workflows in Kenyan banks explains maker-checker and delegated authority.
3. SLA and escalation
A deadline on every approval stage, and automatic escalation when it passes, with the escalation recorded. Let an approval breach its deadline during the demo and ask who is alerted and what the audit trail shows.
4. Payments: M-Pesa and bank
M-Pesa B2C on final approval for petty cash and reimbursements, payment status (success, failure, reversal) written back to the request with the M-Pesa reference, and controls that stop an unapproved, altered or duplicate request being paid. B2B supplier payments, bank payments and the gateway contract are Should by default. Organisations that pay most suppliers through the bank should raise bank payments to Must. Ask whose shortcode and contract the payments run on, and who resolves a failed payment. Reconciling M-Pesa B2C payments with Business Central shows what good reconciliation looks like.
5. ERP and general ledger posting
Automatic posting of approved and paid items to your ERP, GL and dimension mapping that finance maintains, and failed postings that are visible and retryable. Name your ERP in the RFP and ask which Kenyan organisations use that exact integration in production.
6. Documents and records (EDMS)
Every attachment stored with its request in a governed document store, not in email or on phones. Ask where documents are held, in whose tenant or data centre, and whether you can reach them without the expense system. Versions and retention are Should by default. Organisations with strict records obligations may raise them.
7. Tax and data protection
KRA has required business expenses to be supported by eTIMS electronic tax invoices to be deductible since 2024, and it checks expenses claimed in returns against eTIMS records. The Must row is therefore about capturing eTIMS invoice details with each supplier invoice and expense, and flagging expenses without one. Validation against KRA records, and where withholding tax is calculated, are separate Should rows because vendors differ widely. Ask for a plain answer on each. Support for the Data Protection Act, 2019 (a data processing agreement, data-subject requests, retention and deletion) is a Must. Our article on KRA eTIMS and expense claims covers what finance teams must keep. Confirm current rules with your tax adviser.
8. Security, access and audit trail
Single sign-on with your directory and multi-factor authentication, role-based access scoped by department or entity, an append-only audit trail no administrator can edit, and stated hosting and data location with tested backups and recovery. See audit-ready expense workflows for what auditors look for.
9. Reporting and audit evidence
Standard spend, open-request, ageing and payment reports exportable to Excel or CSV, and a complete evidence pack for any payment: request, documents, approvals, escalations, payment reference and ledger entry. Ask for the evidence on last month's largest payment in the demo system.
10. Vendor, delivery, commercials and exit
Comparable Kenyan references, support in East Africa Time with a clear escalation path, an implementation plan with named roles, and a three-year cost that itemises licences, payment gateway fees, ERP connectors, hosting, support and change requests. The exit clause should return requests, documents and audit history in open formats.
How to weight the requirements
Agree weights before you see any vendor, so scoring reflects your risks rather than the best demo. Start with the defaults, then adjust:
- A bank or financial institution may raise delegation (R2.4), bank payments (R4.4) and independent security testing (R8.5) and keep a strict red-flag threshold.
- An NGO or donor-funded programme will usually raise grant coding (R2.6), per diem (R1.6) and imprest (R1.5), and look hard at the evidence pack (R9.3).
- A public-sector body or county should raise imprest issue and surrender (R1.5) to Must.
- A legal or professional-services firm may raise document versions and retention (R6.2, R6.3) and cost coding for client-chargeable disbursements.
- A multi-entity enterprise may raise supplier master data (R5.5) and BI access (R9.4).
Read the must-have failures count alongside the total. A high score with two Musts below 3 still has gaps that strength elsewhere does not cover.
Six scripted demo scenarios to give every vendor
Send the script and your sample data a week ahead, and give every vendor the same time.
| Scenario | What to watch |
|---|---|
| Configure one of your real approval chains, with a KES threshold | Who does it, whether code is needed, and whether the change is logged |
| Route three supplier invoices of rising amounts, then try to approve your own request | Correct routing to each chain, and a blocked self-approval |
| Let an approval pass its deadline | Who is alerted, where the request goes, and what is recorded |
| Pay a reimbursement on M-Pesa in a test environment, then show a failed payment | Status and reference written back, and how the failure is retried |
| Post an approved item to a test copy of your ERP, then force a failed posting | Automatic posting, document link, and a visible, retryable error |
| Produce the evidence for last month's largest payment | How quickly the request, documents, approvals, payment reference and ledger entry appear |
Red flags
- The vendor will only demonstrate its own sample chains and data.
- Adding an approver or changing a threshold needs the vendor's developers.
- Payment means exporting a file and uploading it to a bank or M-Pesa portal.
- An integration is described as "available", but no Kenyan organisation uses it in production.
- eTIMS "support" turns out to be a free-text field with no reporting.
- An administrator can edit or delete audit entries.
- Must-have requirements are answered with roadmap dates.
- The three-year cost leaves out gateway fees, connectors, hosting or change requests.
Where Creodata fits
Score us alongside everyone else. Creodata's expense management system is a workflow-first finance EDMS, and its strongest rows are in areas 2 to 6 and 8. It handles three request types: supplier invoices, petty cash and cashbook payments. Each request is routed through a multi-stage chain such as Head of Department, Finance Reviewer and CFO, resolved per department and request type, with a configurable amount threshold (KES 10,000 on the reference configuration). Overdue approvals escalate automatically to the next approver, with an audit entry. On final approval, payments go out over M-Pesa through the KentaPay / Eclectics Swivel gateway: B2C for petty cash and reimbursements, B2B for suppliers. Callback and status reconciliation write the payment reference back to the request. Approved items post to Microsoft Dynamics 365 Business Central over OData, with their SharePoint Online documents linked. Sign-in is through Microsoft Entra ID, each role has its own dashboard, and the system runs on Microsoft Azure.
Where we score lower, we say so. We do not offer a dedicated imprest or per diem module, eTIMS validation, withholding-tax calculation, bank or PesaLink payments, posting to ERPs other than Business Central, on-premises deployment, corporate cards or travel booking. Pricing is quoted per organisation. For document management beyond finance, see our EDMS solutions. Ask us for the same evidence as everyone else, and book a demo with your own approval matrix.
Frequently asked questions
What should an expense management software RFP include?
Your scope (request types, approval matrix, payment rails and ERP), the requirements with the question each vendor must answer, the evidence you expect, the demo scenarios, and the information needed for a three-year cost comparison. Also ask about integrations live in Kenya, eTIMS handling, data location, implementation responsibilities and exit terms. These are the points most often left vague until contract negotiation.
How should we weight requirements when comparing expense management vendors?
Agree weights before you meet any vendor. The defaults weigh a Must 5, a Should 3 and a Could 1, and you can override any requirement. Read the must-have failures count as well as the total.
Does the checklist cover petty cash and imprest?
Yes. Petty cash is a Must by default. Imprest issue and surrender is a Should that public-sector bodies, counties and many NGOs should raise to Must, and per diem is a Could you can raise in the same way.
Does the checklist cover KRA eTIMS?
It asks whether the system captures eTIMS invoice details and flags expenses without them (a Must by default), and whether it validates invoices against KRA records (a Should). It is not tax advice: confirm current eTIMS and withholding tax rules with your tax adviser and add rows for your own obligations.
How many expense management vendors should we shortlist?
Long-list five to eight suppliers across provider types, then take two or three to scripted demos and reference calls. The summary is built for three vendors.
Is the checklist free to use and edit?
Yes. Download it, edit the requirements and priorities, add your own rows and share it inside your organisation. If you insert a requirement, insert it inside the table and copy the formulas in columns I and M to O so the summary includes it.
Download the expense management software RFP checklist and scoring template, read the buyer's guide to expense management software in Kenya, or see how Creodata's expense management software scores against it in a demo.





