Help centre Procurement

How sealed bids are opened

Updated 07 Sep 2026

This page describes exactly what happens when a sealed tender is opened.
It is published so that suppliers and auditors can check we followed it.

Nothing opens early

Before the closing time the system refuses to open bids. This is not a
policy somebody could waive. There is no button, no override, and no
combination of people who can do it.

Step one: the list is fixed

After the closing time, one procurement officer freezes the list of bids.

This produces a fingerprint of exactly which bids are in the competition,
and it happens before anybody can see inside any of them. That order
matters. Once the list is fixed, a bid cannot be added to it or removed
from it without leaving an obvious hole.

Bids that were withdrawn or arrived late stay on the list. They get a
recorded outcome saying so. Nothing disappears.

Step two: two people confirm

At the same moment the list is frozen, we name who is allowed to open it.
They are chosen before anyone knows who bid, which stops a ceremony being
arranged around a result.

Each of those people then signs in on their own account and confirms.
One person cannot do this twice, and one person cannot confirm on behalf
of somebody else. The system records who confirmed, when, and from where.

Step three: the bids open

Only once enough people have confirmed. Every bid on the frozen list gets
a recorded outcome. There is no way to finish the ceremony with a bid
left unaccounted for.

The system checks each bid against the fingerprint taken when it was
submitted. If what opens is not what was sent, that is recorded as a
mismatch rather than quietly corrected.

Step four: it is sealed and notified

The whole ceremony, including who confirmed and when, is sealed together
and cannot be edited afterwards.

An email goes to somebody outside procurement the same day, saying a
tender was opened and by whom. It contains no bid contents and no supplier
names.

What we are honest about

A person with full control of our servers could read a bid before its
opening. No software prevents that. Only special hardware does, and for an
organisation of our size that cost is not justified.

What we do instead: we keep the list of people with that access short, we
keep them out of procurement decisions, and we make sure every opening is
noticed by somebody who is not part of it on the day it happens.

We would rather say this plainly than claim a protection we do not have.

Still stuck?

Sign in to the client portal to open a ticket.

Client sign in