LMS requirements checklist for compliance training
Most LMS requirement templates in circulation were written for corporate learning and development. They ask about course catalogues, gamification, social features and mobile learning. They are not wrong, they are just answering a different brief, and a compliance buyer who uses one ends up scoring vendors on things that will never matter and missing the two or three that will.
This is a requirement list built the other way round, starting from what a compliance programme has to be able to prove. Use it as the spine of an RFP or as a scorecard for a shortlist. The sections are ordered by how often they turn out to be the thing that breaks.
Before you write requirements, define the population
Almost every failed LMS selection I have seen started with a requirement list and skipped this step. The requirement list is downstream of one question: who has to be trained on what, and what decides that?
Write down, before you talk to a vendor:
- How many people, in how many legal entities, in how many countries
- How many distinct curricula, and what determines who gets which
- How many languages you need content in, and which are legally required rather than preferred
- Which populations are not in your HR system at all: contractors, agency staff, board members, seasonal workers
- Whether external parties such as suppliers or franchisees need training
That last two lines catch more organisations than any technical requirement. Board members and contractors are frequently in scope for training obligations and almost never in the HR feed, so they arrive as a manual process nobody planned for. Article 47 covers how to build the matrix that answers the second point properly.
Assignment and enrolment
This is where a compliance platform earns or loses its keep. Manual enrolment does not scale and does not stay correct.
- Rule-based automatic assignment on attributes from the HR system: role, entity, country, department, employment type
- Re-evaluation on change, so a role or country change updates the curriculum without manual intervention
- Support for a country axis as well as a role axis, so a Finnish controller and a Swedish controller can receive different course versions
- New joiner rules with a defined start date offset
- Leaver handling: what stops, what is retained, what is anonymised
- Manual override with a recorded reason, because there is always an exception
- Bulk assignment for populations outside the HR feed
The demo test: transfer an employee between entities and watch what happens without anyone touching the record.
Deadlines, reminders and escalation
- Per-course deadline logic, configurable by population rather than globally
- Reminder cadence set by you, including how many, how far apart, and in which language
- Manager escalation with a defined trigger point
- Manager visibility of their own team’s status without administrator rights
- Reporting on overdue status by entity and by manager
Recurrence and versioning
- Support for at least three recurrence patterns: fixed interval, triggered by event such as role change, and one time only
- Course versioning that distinguishes substantive from cosmetic changes
- A rule for what happens to existing completions when a course version changes: do they remain valid, expire, or trigger reassignment
- Ability to report completions against a specific version, not just against a course title
The versioning requirement is the one buyers most often discover late. If a substantive change to your anti-bribery course cannot be distinguished from a typo fix, you cannot answer the question of whether a person was trained on the current material.
Language and content
- Independent language versions of the same course, separately versioned and separately publishable
- Defined fallback behaviour when a language version does not exist for a learner
- Interface language independent of content language, since a Finnish speaker may be assigned an English course
- Support for the character sets and sorting rules of the languages you use
- Ability to run a course in a language not tied to the learner’s country, for people who work across borders
Standards and content portability
- Which standards the platform imports: SCORM 1.2, SCORM 2004, xAPI, cmi5
- Whether an external learning record store can be connected, if you have one
- Export of your own uploaded content in its original packaged form
- Whether courses licensed from the vendor can run on another platform if you leave
Article 53 explains what these standards do and which one you actually need. The commercial point is simpler: if your content cannot leave, your pricing negotiation at renewal is not really a negotiation.
Reporting and evidence
Ask for these as outputs, not as dashboard screenshots.
- Per-person completion record with course title, version, date, score where applicable
- Per-entity, per-year evidence export in a format an auditor accepts
- Historical reporting on populations as they were at the time, not as they are now
- Self-service report building without vendor involvement or professional services fees
- Scheduled reports to named recipients
- API access to completion data
The single most useful requirement in this list: ask the vendor to produce a full evidence export during the evaluation, using demo data, and look at the file. Article 49 covers what the pack should contain.
Integration
- Single sign-on: SAML 2.0 or OpenID Connect
- Automated user provisioning and deprovisioning, ideally SCIM
- Named connectors or documented API support for your HR system specifically
- Frequency of the user sync and what happens when it fails
- Whether the vendor charges separately for integration work
Article 54 covers what to ask about the HR side, including the Nordic HR systems that rarely appear on a vendor’s connector list.
Data protection and hosting
- Hosting location and whether it can be restricted to the EU or EEA
- Sub-processor list and notification terms for changes
- Retention configuration: can you set retention rules yourself, per data category
- Deletion and anonymisation routines, and what they leave behind
- Whether the vendor will sign your data processing agreement or only offer their own
- Audit log of administrator actions
Article 55 covers the substance of what you may keep and on what basis.
Accessibility
- Conformance level claimed, against which version of WCAG
- Whether a conformance report exists, and its date
- Whether that claim covers the authored course content as well as the platform interface
- Keyboard operability of the course player and the assessment engine
- Caption and transcript support for video content
The distinction between platform conformance and content conformance is where most vendor claims quietly fail. Article 56 covers it.
Administration and cost of ownership
- How many administrators the licence includes and what they cost
- Whether reporting, integration and additional languages are included or priced separately
- Sandbox or test environment availability
- Support hours, language and response commitments
- Notice period, renewal terms and price escalation clauses
- Data export at termination: format, cost, and how long you have
Article 62 covers what actually drives the total cost, which is rarely the per-user price on the first page of the quote.
Turning this into a scoring model
Do not weight every line equally. Split the list into three tiers before you send it out.
Must have. A no here removes the vendor. Keep this list short, ideally under fifteen items. For a Nordic compliance buyer it usually contains multi-language content versioning, country-aware assignment, per-person evidence export, EU hosting, and SSO.
Should have. Scored, weighted, and where most of the differentiation happens.
Nice to have. Recorded, unweighted or lightly weighted, so you do not pay a premium for features nobody has asked for.
Then insist that responses to must-have items are demonstrated rather than declared. Written responses to feature questions are compiled by people whose job is to win the bid. A five minute demonstration of the transfer scenario, the evidence export and the language version change tells you more than forty pages of it.
Frequently asked questions
How long should an LMS RFP be?
Shorter than most. A tight requirement list of sixty to eighty items, split into must have, should have and nice to have, produces better comparability than a three hundred line matrix, because vendors answer a short list carefully and a long one with copy and paste.
Should we run a pilot before signing?
Yes, where the vendor allows it. A pilot with one real course, one real population and one real reporting requirement surfaces integration and data quality problems that no demo does. Keep it to a single entity and a fixed four to six week window so it does not become a permanent state.
Who should be in the evaluation team?
At minimum compliance, HR, IT and data protection. Compliance owns the obligation, HR owns the data feeding assignment, IT owns integration and security, and the data protection function owns the retention and processing questions. Missing the last one is how organisations end up renegotiating a data processing agreement after signature.
What is the most common requirement people forget?
Leaver handling. Everyone specifies what happens when a person joins and changes role. Far fewer specify what the platform does with the record when they leave, which is exactly the record you will be asked to produce later.
Sources and further reading
- Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML) V2.0 – OASIS Standard
- OpenID Connect Core 1.0 – OpenID Foundation
- RFC 7644: System for Cross-domain Identity Management (SCIM): Protocol – IETF
- cmi5 specification: SCORM vs cmi5 comparison – AICC / ADL
- xAPI SCORM Profile – ADL Initiative
- Web accessibility laws and policies: European Union – W3C Web Accessibility Initiative
- Regulation (EU) 2016/679 (GDPR) – EUR-Lex, for the hosting, sub-processor and retention requirements
