Choosing a translation provider for regulated work is not primarily a question of finding the broadest assurance statement. It is a procurement decision about whether a supplier’s documented processes, people, data controls and operating model fit the content and risk involved.
This guide helps UK procurement teams structure that decision. It is not legal advice, and it does not treat a standard, certification claim or supplier questionnaire as proof that a service is suitable in every context.
What regulated teams need from a translation service
Regulated teams may need translation support for customer communications, policies, product information, training, case material, complaints, research or other business content. The appropriate service model depends on what is being translated, who will rely on it, the consequences of an error, the languages required and the information that must pass through the workflow.
Start with the organisation’s own requirements. Define the content types, intended audiences, jurisdictions, volume pattern, turnaround expectations, accessibility needs, review responsibilities and acceptance criteria. Then identify whether the work includes personal data, confidential commercial information, special-category data, legally sensitive wording or specialist terminology. These choices shape the diligence needed; they should not be left for a supplier’s generic proposal to resolve.
UK GDPR guidance is relevant where a translation workflow involves personal data. The Information Commissioner’s Office (ICO) provides UK GDPR guidance and resources for organisations, giving procurement a useful starting point for involving the appropriate privacy and information-governance stakeholders. ICO UK GDPR guidance
A useful comparison therefore covers four connected areas: service capability, quality controls, data handling and governance. A supplier can look strong in one area while being a poor fit in another—for example, it may offer the required language pair but lack an agreed escalation route for subject-matter review. Treat the selection as evidence-led matching, rather than a search for a universally “compliant” provider.
Assess quality controls and service capability
AI-generated generic editorial illustration — not a retailer product photo and does not depict the reviewed product or service. Make the quality-control questions tangible without implying that a standard alone guarantees supplier performance.
Ask shortlisted suppliers to show how work moves from instruction to delivery. ISO 17100:2015 specifies requirements for core processes, resources and other aspects needed to deliver a translation service meeting applicable specifications. ISO says that application of the standard can give a translation service provider a means to demonstrate conformity of specified services and the capability of its processes and resources to meet client and other applicable specifications. ISO 17100:2015
For procurement, that makes process evidence more useful than a broad quality promise. Request a clear account of how the supplier captures the brief, assigns resources, handles terminology and reference material, performs review, records queries, corrects issues and manages version control. Ask what documentation can be supplied for the proposed scope, rather than assuming one document applies to all services.
Questions worth putting to a supplier include:
- Which resources, competence criteria and review steps apply to our language pairs and subject areas?
- How are client specifications, terminology and style instructions controlled and kept current?
- What evidence is available for quality checks, query management, corrective action and escalation?
- Who is accountable when a delivery does not meet agreed requirements, and how is that outcome recorded?
- Can the proposed workflow be demonstrated using representative, appropriately protected sample material?
Industry standards can provide objective criteria and quality expectations for language-service providers, according to the Association of Translation Companies (ATC). That is a useful due-diligence signal, but it remains a starting point for assessment—not a substitute for reviewing the provider’s actual proposal, scope and evidence. ATC ISO standards overview
Recognise the limits of standards and supplier claims
A standard can help describe a service framework; it cannot answer every question that matters to a regulated buyer. ISO 17100 is scoped to translation services and explicitly does not apply to interpreting services. ISO also states that raw machine-translation output plus post-editing is outside the scope of ISO 17100:2015. ISO 17100:2015
That means procurement should not use an ISO 17100 reference as shorthand for every language-related service in a supplier’s offer. Check which exact services, sites, language pairs, subcontracted arrangements and workflow stages are included in the evidence presented. If the proposed model includes machine translation, post-editing, transcription, interpreting, localisation or content adaptation, require a separate explanation of the controls, review expectations and acceptance criteria for that model.
Similarly, a claim that a supplier has qualified linguists does not by itself show that the right expertise will be available when needed. Ask how specialist availability is planned, how terminology disputes are escalated, how emergency work is governed and when the client must provide a subject-matter reviewer. Make the limits visible in the scorecard rather than treating them as exceptions to be resolved after contract award.
The practical test is whether the supplier can evidence a workflow that fits your stated requirements. A standard-aligned process may be relevant evidence, but it does not remove the buyer’s responsibility to assess risk, scope and operational fit.
Check data protection and confidentiality controls
AI-generated generic editorial illustration — not a retailer product photo and does not depict the reviewed product or service. Support a focused review of confidentiality and personal-data handling when assessing a translation supplier.
Where translation work involves personal or confidential information, map the information flow before comparing promises about security. Identify what data will be shared, the purpose of each transfer, who needs access, where files are stored or processed, how long material is retained, and what happens when a job closes. Include portals, email, translation tools, terminology systems, client reviewers and any downstream parties in the map.
Use that map to ask focused diligence questions. For example: what access-control model applies to assigned linguists and project staff; how are credentials and permissions managed; how is data separated between clients; what retention and deletion arrangements are proposed; what subprocessors or technology providers are involved; and how will incidents, requests and changes be communicated? The answers should be evaluated by the organisation’s appropriate privacy, security and legal stakeholders in light of the actual processing arrangement.
The ICO’s UK GDPR guidance and resources are an authoritative reference point for organisations considering their data-protection responsibilities. They do not turn a supplier questionnaire into a finding of compliance. ICO UK GDPR guidance
Confidentiality requires the same operational specificity. Request the contractual commitments, but also ask how they are implemented in day-to-day work: onboarding, permitted tools, remote working, access revocation, incident escalation and subcontractor management. If sensitive content is involved, document which controls are mandatory, who verifies them and what evidence must be retained.
Avoid relying solely on policy wording or a security badge. A defensible decision links the supplier’s stated controls to the particular content, data flow, contractual terms and internal governance model.
Run a proportionate supplier-selection process
Begin with a short, written requirements pack. Set out the content categories, languages, expected volumes, service hours, turnaround bands, specialist needs, quality expectations, data-handling constraints, reporting needs and contract owners. Separate mandatory requirements from desirable features so suppliers can identify gaps early.
Next, apply a consistent evidence request to each shortlisted provider. Ask for a proposed workflow, scope statement, relevant process documentation, resource approach, data-flow explanation, subcontractor information, escalation model and sample reporting. Score the response against published criteria rather than relying on presentation quality or a single assurance claim.
A practical sequence is:
- Confirm the internal risk and content profile, including who owns acceptance of translated material.
- Screen suppliers against non-negotiable scope, language, confidentiality and operating requirements.
- Evaluate documented process and resource evidence against the same scorecard.
- Test the proposed service through a proportionate pilot or scenario where the risk and volume justify it.
- Record outcomes, unresolved risks, acceptance criteria and required contractual controls before award.
- Establish governance after award: named contacts, service reporting, issue escalation, periodic review and a controlled route for changing scope.
A pilot is not independent testing of the provider in the abstract. It is a controlled way to check whether the agreed workflow, communication path and acceptance criteria work for representative material. Define what may be used, how it is protected, who reviews it and what result would trigger remediation or rejection.
Keep a decision record showing the evidence considered, the assumptions made and the owners of any residual risk. This supports accountable procurement and avoids overstating what standards or supplier declarations prove. Where a question turns on legal interpretation, privacy obligations or specialist subject matter, bring in the relevant internal or external adviser rather than asking a generic supplier assurance to settle it.
Frequently Asked Questions
Does ISO 17100 certification guarantee that a translation service is suitable for our regulated content?
No. ISO 17100:2015 sets requirements for translation-service processes, resources and related aspects, and can help a provider demonstrate conformity of specified services. However, suitability still depends on your content, risk profile, specifications, language coverage, service scope and governance. ISO also states that interpreting is outside its scope, as is raw machine-translation output plus post-editing. ISO 17100:2015
What UK GDPR evidence should we request from a translation supplier?
Request evidence that lets your organisation assess the proposed data flow: the information involved, access roles, storage or processing arrangements, retention and deletion, subprocessors, incident communication and contractual responsibilities. Evaluate it with the relevant privacy, security and legal stakeholders. The ICO’s organisational guidance is a useful authoritative reference, but the correct diligence will depend on the processing context. ICO UK GDPR guidance
How should we assess machine translation and post-editing in a regulated workflow?
Assess it as a distinct service model. ISO 17100:2015 says raw machine-translation output plus post-editing is outside its scope, so ask separately about the technology, data handling, post-editing criteria, human review, terminology controls, error escalation and acceptance process. Determine whether that model is appropriate for each content category rather than applying one rule to all work. ISO 17100:2015
When should procurement involve legal, privacy, or subject-matter specialists?
Involve them when the decision depends on legal meaning, data-protection obligations, sensitive information, regulated terminology or the consequences of an inaccurate translation. Their role is to help set requirements and assess residual risk; a translation supplier’s general claim or standard reference should not replace that judgement.
Related reading
- Business Services Provider Evaluation
- DeepL for Business for UK teams
- Translation agency vs language-AI platform: procurement trade-offs for UK teams
- Best business translation service models for UK procurement teams
Editorial information: About our editorial team · Read our editorial policy · Read our affiliate disclosure.