Strategy

How to Check a Software Supplier Before You Sign

SKIMBOX Team

A portfolio proves somebody was involved, not that this team built it. Here are the checks that actually verify a UAE supplier exists, does the work it claims, and will still be there in two years.

How to Check a Software Supplier Before You Sign

Most buyers check a software supplier by looking at their website, glancing at a portfolio, and forming an impression during a meeting where the supplier was at their most prepared.

That process filters for presentation. It does not test whether the company exists as claimed, whether the people in the room will do the work, or how the supplier behaves when a project goes badly, which is the only condition under which you will really find out what you bought.

Most of what follows takes an afternoon, and the first two checks take five minutes.

The five-minute checks

Verify the company exists. The UAE operates the National Economic Register, a federal platform run by the Ministry of Economy and Tourism together with nine local economic departments including Abu Dhabi's and Dubai's [1][2]. You can search by business name, licence number, economic register number or business activity, and it returns the licence details the government holds.

Check three things while you are there. That the entity exists. That the trading name matches the name on the proposal, and later the name on the bank details. And that the licensed activity actually covers software development rather than general trading or management consultancy. A supplier operating outside its licensed activity has a regulatory exposure that can quietly become your delivery problem.

If the supplier is registered in a free zone, it is licensed by that zone's authority rather than the local economic department, so ask which one and verify there. That is a normal structure for technology businesses and a question about where to look, not a warning sign.

Verify tax registration. The Federal Tax Authority provides a status check on its own portal [3]. Any supplier charging you VAT should hold a valid registration. If an invoice shows VAT and the number does not verify, that is a problem for your records as much as a question about them, and it is much better found before the first invoice than during an audit.

Neither check proves competence. Both eliminate a category of problem entirely, for almost no effort, and it is surprising how rarely they get done.

A portfolio proves less than you think

A portfolio establishes that somebody was involved in a piece of work. It does not establish that this company did it, that the people still there did it, or what "did it" means.

Agencies subcontract. Staff move between firms and take their portfolio with them, quite reasonably. A screenshot demonstrates that a product exists, which was never in doubt.

So treat the portfolio as a list of things to ask about rather than as evidence. For any piece that matters to you: who on your current team worked on this, what specifically did they do, what was the hardest problem in it and how was it solved, and would that client speak to me?

That last question does most of the work. It separates projects a supplier is proud of from projects they would rather you admired from a distance.

Reference calls, asked properly

The standard reference call is useless because the standard question is useless. Asking whether somebody was satisfied invites a polite answer, and you get one.

Two changes fix it.

First, ask for the right reference. Request a client whose project was comparable in size and type, and specifically one that went through something difficult rather than one that went smoothly. A supplier who can only produce their happiest client is showing you a curated view. One willing to introduce you to a project that hit trouble and recovered is showing you something considerably more valuable, and is also telling you something about their confidence.

Second, ask better questions:

What went wrong, and how did they handle it? What would you do differently if you started again? Were the people who pitched the people who did the work? Did the final cost match the quote, and if not, why? Would you use them again for something bigger?

The last one produces more honest answers than any general rating, because it asks for a decision rather than an opinion.

If every reference is glowing, ask what the low point was rather than concluding there wasn't one. Every real project has a difficult period, and a reference who cannot recall one has either forgotten or is not describing an engagement in much depth.

Will the people pitching do the work?

This is the most common disappointment in the industry and it is entirely visible in advance.

Ask directly, in writing: who will work on this, what are their names, and what share of their time do we actually get? Then ask to meet them before signing rather than at kickoff.

Treat reluctance as the answer. A supplier confident in their team will arrange it happily, because meeting good people helps them win the work. One who deflects into process and account management may be planning to assign whoever is free when you start. Fifteen minutes with the person who would write the code tells you more than an hour with anybody else in the company.

The question about one person

Headcount matters less than concentration. What you want to know is whether more than one person would understand your system.

Ask what happens if the person leading your project is unavailable for a month. A good answer names who else knows the work, describes how it is written down, and is honest about what would slow. A vague answer, or a promise that it will not happen, is the finding.

This applies to a fifty-person agency as much as to a freelancer. Large suppliers can have exactly the same concentration risk on your specific account, and it is less visible because the company is big enough to look safe.

If your supplier is a freelancer, this stops being one item on a list and becomes the whole conversation: where the code lives, who else could pick it up, what happens if they are unavailable. Freelancers can be an excellent choice. The arrangement needs different safeguards rather than fewer.

Will they still be here in two years?

You will not get audited accounts from a small firm, and asking for them is usually unrealistic. There are still fair questions.

How long has the company been trading? Is there other committed work, or would ours be most of it? What happens to our project if our next invoice is thirty days late?

That last question is more revealing than any financial statement, because it asks about dependency rather than solvency.

A new company is not a warning sign in itself. Many are formed by experienced people leaving somewhere else, and the individuals may have long track records even where the entity does not. What matters is whether those individuals have done this work, and whether the business could survive a slow quarter without your project becoming its lifeline.

Which raises the question people avoid: is it a problem to be a supplier's biggest client? It is a risk in both directions. You get attention and priority, which is real. You also become the client they cannot afford to disagree with, which is how a supplier stops telling you when you are wrong. That second effect is subtle, expensive, and almost never discussed until afterwards.

Ask about capacity rather than client names, since confidentiality is legitimate: how many active projects, how many people, and who else is working on yours at the same time. Suppliers rarely fail because they are incompetent. They fail because they accepted more than they could deliver and did not say so.

What you are actually buying

Worth stating plainly, because it reframes every check above.

You are not buying code. Code is the cheapest thing in the transaction and increasingly the most replaceable part of it. What you are buying is judgement applied to your problem over a period of months, by specific people, under conditions neither side can fully predict at signing.

That is why a portfolio is weak evidence and a reference from a difficult project is strong evidence. The portfolio shows you the output of good conditions. The difficult reference shows you what the supplier does when an integration turns out to be twice the work, when your own team goes quiet for three weeks, or when something they estimated confidently turns out to be wrong.

Every supplier is competent on a good day. The variation between them, and the variation that costs you money, is almost entirely in how they behave on the bad ones. Do they tell you early or late? Do they propose options or excuses? Do they absorb a mistake they made, or reclassify it as a change request?

None of that appears in a proposal, and no supplier will describe themselves inaccurately when asked directly. It only becomes visible through somebody who has already lived through it with them, or through a small piece of paid work where something goes slightly wrong and you get to watch.

That is the argument for spending your due-diligence effort on references and a trial rather than on studying documents. Documents describe intentions. The other two show you conduct.

The warning signs, ranked

A quote produced without any questions being asked. A refusal to name who will do the work. Reluctance to provide any reference at all. Pressure to sign quickly for a discount that expires. A portfolio that cannot be discussed in specifics. And, most tellingly, answers that become vaguer the more precisely you ask.

None of these is fatal on its own. Two or more together usually is.

The inverse is also true, and worth valuing when you see it. A supplier who asks searching questions about your business, your constraints, and what happens when things go wrong is trying to work out what you actually need. A supplier who produces a number without asking anything has either built this exact thing before, which they should say, or is guessing, and will discover the truth using your budget.

Test delivery, not description

Every check above verifies a claim. Only one tests behaviour: give them a small piece of paid work first.

Make it small enough to finish in days, real enough to matter, and specify it the way you would specify the real project. A genuine fix you need, a small feature you actually want, an integration you would have to do anyway. Pay properly for it rather than asking for free work, because what you are observing is how they behave when engaged, not how they behave when auditioning.

What you learn: how they scope it, what they ask before starting, whether the estimate held, what arrived against what was promised, and how they communicated when something was unclear. That is a fair preview of the project, and it costs a fraction of it.

Scaling the effort to the stake

Not every engagement justifies every check, and running all of them for a small piece of work signals the wrong thing about how you will be to work with.

For anything below the point where losing the money would be painful rather than merely annoying, the registry check and the tax check are enough. Five minutes, and they eliminate the failure mode where the entity is not what it claims to be.

Above that, add references and a conversation with the person who will do the work. Perhaps two hours of your time, and it addresses the two most common disappointments: a supplier whose real track record is thinner than the portfolio suggests, and a delivery team who turn out to be different people from the ones you met.

Where a wrong choice would cost you months as well as fees, add the paid trial. The arithmetic at this tier is obvious: a few thousand dirhams spent finding out how somebody actually works, set against a much larger decision otherwise made on impressions.

And for a long-term or business-critical dependency, add the contract terms below and the capacity questions above. At that level you are not choosing a supplier for a project. You are choosing who your business depends on, and how you would leave matters as much as how you start.

Before you sign

Four contract points are much easier to agree at the start than to negotiate once a relationship has soured: code ownership, access to accounts and infrastructure, what happens on termination, and what a handover has to include. Our guides on who owns your code and the accounts your business must own cover those, and changing your development agency covers what a handover should contain.

If the supplier is registered outside the UAE, none of the registry checks above apply. Find the equivalent public register in that jurisdiction and think carefully about which country's courts would hear a dispute. Our guide on Dubai agencies versus offshore teams covers that trade-off properly.

Scale the effort to the stake. The registry and tax checks take five minutes and are always worth doing. References and meeting the team are proportionate once losing the money would genuinely hurt. A paid trial makes sense when a wrong choice costs you months as well as fees.

We can review the technical side of a proposal, meaning whether the approach is sound, whether the scope matches the price, and what is missing that will surface in month three. That starts from around AED 1,500 with us and final pricing depends on scope. These are our own figures rather than a market survey.

If you only do one thing beyond the registry check, speak to a client whose project went wrong and recovered. Every other check verifies a claim. That one shows you how a supplier behaves under pressure, which is the thing you are actually buying.

References

  1. UAE Government, National Economic Register
  2. Ministry of Economy and Tourism, enquire about a commercial companies licence
  3. Federal Tax Authority, status check
  4. UAE Government, verify business licences
  5. SKIMBOX, who owns your code in the UAE
  6. SKIMBOX, the accounts your business must own
  7. SKIMBOX, changing your development agency in the UAE
  8. SKIMBOX, Dubai agency versus offshore team
  9. SKIMBOX, why app quotes vary in the UAE

Government services, registries and their access requirements change. Check the linked official pages directly rather than relying on this article for procedure. This is not legal advice.

Frequently asked questions

  • How do I check a UAE company actually exists?

    Use the National Economic Register, a federal platform operated by the Ministry of Economy and Tourism together with nine local economic departments. You can search by business name, licence number, economic register number or business activity, and it returns the licence details government holds on record. It takes about two minutes, costs nothing, and rules out the most basic category of problem entirely before you spend anything else on checking.

  • What should I look for in the licence record?

    That the entity exists, that the trading name matches the one on the proposal and the bank details, that the licence is current, and that the licensed activity actually covers software development rather than something adjacent. A mismatch between the name on the quote and the name on the licence record is worth asking about before anything else happens, and there is often an innocent explanation, but you want to hear it early.

  • Does the licensed activity really matter?

    It matters more than people expect. A licence issued for general trading or management consultancy does not cover software development, and a supplier operating outside its licensed activity has a regulatory problem that can become your delivery problem. It is a two-minute check and it occasionally surprises people who have already been working with a supplier for months without ever having looked.

  • How do I verify tax registration?

    The Federal Tax Authority provides a status check service on its own portal, and a supplier charging you VAT should hold a valid tax registration number. If an invoice shows VAT and the registration number does not verify, that is a serious problem for your own records as well as a question about the supplier. Check it before you pay the first invoice rather than discovering it during an audit, when the cost of the discovery lands on you rather than on them.

  • What about free zone companies?

    Free zone entities are licensed by their own authority rather than the local economic department, so the registry to check may differ. Ask which free zone the company is registered in, then verify directly with that authority rather than assuming the federal registry holds the record. It is a completely legitimate structure used by a great many technology businesses in the UAE, so treat it as a question about which registry to look in rather than as a warning sign in itself.

  • Is a portfolio good evidence?

    It is weak evidence on its own, because it proves somebody was involved rather than that this team did the work. Agencies subcontract, staff move between firms and take their work with them, and a screenshot proves nothing about who wrote what. Treat the portfolio as a useful list of things to ask specific questions about, rather than as proof of anything on its own, and the questions will tell you far more than the images did.

  • What should I ask about a portfolio piece?

    Who on your current team worked on it, what specifically they did, what the hardest problem was and how they solved it, and whether that client would speak to me. The last question is the sharpest of the four, because it cleanly separates work a supplier is genuinely proud of from work they are hoping you will admire from a comfortable distance.

  • How do I ask for references properly?

    Ask for a client whose project is comparable in size and type, and ideally one that went through something difficult rather than one that went smoothly. A supplier who can only offer up their single happiest client is showing you a carefully curated view rather than a representative one. A supplier willing to introduce you to a project that hit real trouble and recovered is showing you something far more useful, and is also telling you something about their own confidence.

  • What should I actually ask a reference?

    What went wrong, and how they handled it. What you would do differently if you started again. Whether the people who pitched were the people who did the work. Whether the final cost matched the quote and why not. And whether you would use them again for something bigger. That last question gets more honest answers than any general satisfaction rating ever will, because it asks the person for a decision rather than for an opinion.

  • What if all the references are glowing?

    Then ask a sharper question rather than concluding anything. Every project has a difficult period, and a reference who cannot recall one either has a short memory or is not describing a real engagement. Asking what the low point of the project was, specifically, produces useful answers far more often than asking whether somebody was satisfied with the outcome overall.

  • How do I know the people pitching will do the work?

    Ask directly, in writing, and ask for names and the share of their time you actually get. Then ask to meet those people before signing rather than at the kickoff meeting, by which point the assignment has already been made. The gap between the senior people who sell the work and the more junior people who deliver it is among the most common disappointments in this industry, and it is entirely visible in advance to anybody who asks the question directly.

  • Should I meet the actual developers?

    Yes, and treat reluctance as information. A supplier confident in their team will arrange it, because it helps them close. One who deflects with talk about process and account management may be planning to assign whoever is free in three weeks. Fifteen minutes with the person who would actually write the code tells you more than an hour with anybody else in the company, including whoever is best at presenting.

  • How many people should a supplier have?

    It depends far more on the shape and duration of your project than on any particular headcount, and a larger firm is not automatically the safer choice. What matters is whether more than one person would understand your system. A supplier where a single individual holds all the knowledge carries the same risk as hiring that individual directly, except that you have no visibility of whether they are happy and no control over whether they stay.

  • How do I test for that single-person risk?

    Ask what happens if the person leading your project is unavailable for a month. A good answer describes who else knows the work, how it is documented, and what would slow down. A vague answer, or a reassuring promise that it simply will not happen, is itself the finding. This applies to a fifty-person agency exactly as much as to a freelancer, and is less visible in the large one because the company looks safe.

  • Should I worry about how new a company is?

    Less than you might think, but ask about it. New companies are often formed by experienced people leaving somewhere else, which is fine and worth understanding. What matters is whether the individuals involved have the track record even though the entity does not, whether the business could survive a slow quarter, and whether your work would be a large enough share of their revenue that losing you would be existential for them.

  • Is it a problem if I would be their biggest client?

    It is a risk in both directions and worth naming openly. You get attention and priority, which is genuinely valuable. You also become the client they cannot afford to disagree with, which is how a supplier stops telling you when you are wrong. That second effect is subtle, genuinely expensive, and almost never discussed before it has already happened, which is why it is worth naming openly at the start.

  • What financial checks are reasonable?

    For a substantial engagement, ask how long the company has been trading, whether it has other committed work, and whether it would be dependent on your payments to meet payroll. You will not get audited accounts from a small firm and asking for them is usually unrealistic. The question you can ask instead is what happens to your project if your next invoice is thirty days late, which tests dependency rather than solvency and gets a much more revealing answer.

  • Should I ask about their other clients?

    Ask about capacity rather than names, since client confidentiality is legitimate. How many active projects are they running, how many people do they have, and who else is working on yours at the same time. Suppliers rarely fail their clients because they are incompetent. They fail because they accepted more work than they could deliver in the time available and did not say so until it was obvious.

  • What contract terms should I check before signing?

    Code ownership, access to accounts and infrastructure, what happens on termination, and what a handover includes. Our guides on who owns your code and the accounts your business must own cover those in detail, and our guide on changing agency covers what a handover must contain. All four are far easier to agree at the start, while everybody is optimistic, than to negotiate later once a relationship has soured.

  • Should I ask for a paid trial before a full engagement?

    Where the commitment is significant, yes. A small piece of real work tests how they scope it, what they ask before starting, whether the estimate holds, and what actually arrives against what was promised. It costs a small fraction of the project, and it is the only check on this entire list that tests actual delivery rather than a description of it. Everything else verifies what somebody has told you.

  • What does a trial piece of work look like?

    Small enough to finish in days, real enough to matter, and specified the way the eventual project would be. A genuine fix you need, a small feature you actually want, or an integration you would have to do anyway. Pay properly for it rather than asking for speculative free work, because what you are trying to observe is how they behave when engaged and accountable, not how they behave while auditioning.

  • What are the clearest warning signs?

    A quote produced without any questions being asked. A refusal to name who will do the work. Reluctance to provide any reference. Pressure to sign quickly for a discount that expires. A portfolio that cannot be discussed in specifics. And any answer that becomes vaguer the more precisely you ask. None of these is necessarily fatal on its own, and each can have an innocent explanation that is worth hearing. Two or more of them appearing together usually is.

  • Is being asked lots of questions a good sign?

    It is one of the better ones. A supplier who asks about your business, your constraints and what happens when things go wrong is trying to work out what you need. One who produces a number without asking anything has either done this exact project before, which they should say, or is guessing and will discover the truth on your budget.

  • Should I be suspicious of a low quote?

    Investigate it rather than dismissing it. The difference is usually scope, seniority, testing or what happens after launch rather than efficiency. Ask specifically what is not included, what happens when something breaks a month after handover, and who exactly does the work. Our guide on why app quotes vary covers what genuinely moves the number and what a low figure usually signals.

  • Does a big client logo mean anything?

    Less than it appears. A logo can represent a small piece of subcontracted work, a project from six years ago, or a relationship that ended badly. It is worth asking what specifically they did for that client, when, and whether the relationship continues. The answers separate a genuine credential from a piece of decoration on a slide, and most suppliers will tell you honestly when asked directly.

  • How much of this is proportionate for a small project?

    The registry check and the tax check take about five minutes between them and are always worth doing. References and meeting the team are proportionate above roughly the point where losing the money would hurt. A paid trial makes sense once the engagement is large enough that a wrong choice would cost you months of lost time as well as the fees. Scale the effort to what is genuinely at stake.

  • Can I check a supplier outside the UAE the same way?

    Not through the UAE registries, no, and that changes the risk rather than eliminating it. If a supplier is registered elsewhere, find the equivalent public register in that jurisdiction, and think carefully about which country's courts would hear a dispute. Our guide on Dubai agencies versus offshore teams covers that trade-off in full, including what changes about recourse when your supplier and your courts are in different countries.

  • What if the supplier is a freelancer?

    Then the single-person risk is the whole conversation rather than one item in it, and you should plan for it explicitly: where the code lives, who else could pick it up, and what happens if they are unavailable. Freelancers can be an excellent choice and frequently deliver better value than an agency. The arrangement simply needs a different set of safeguards around continuity, not fewer of them overall.

  • Can you review a supplier or a proposal for us?

    We can review the technical side of a proposal, meaning whether the approach is sound, whether the scope matches the price, and what is missing that will surface later. That starts from around AED 1,500 with us and final pricing depends on scope. We cannot verify a supplier's finances or give you legal advice. These are our own figures rather than a market survey.

  • What is the single highest-value check?

    Speaking to a client whose project went wrong and recovered. It is the only check that shows you how a supplier behaves under pressure, which is the thing you are actually buying and the thing no proposal describes. Everything else on this list verifies a claim somebody has made about themselves. That one shows you how they actually conduct themselves when a project stops going to plan, which is the only thing you cannot find out any other way.

SKIMBOX Team

Tech Consultancy

Get fresh writing in your inbox

One email a fortnight. No filler.

By subscribing, you agree to our privacy policy.

Want us to build something?

We work with teams across MENA, UK, USA, and India to build products, run programs, and grow.

Get in touch

Continue reading