3 questions from the package
From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.
1. Can an automation created in your business-user authoring tool be opened and edited in your professional developer designer without being rebuilt?
Why it matters. If the two authoring tools produce different artifacts, any business-built automation that outgrows its tool must be rebuilt from scratch by developers. The buyer then pays for that work twice.
Good answer
- Both tools read and write the same automation file or package format.
- The vendor names any activities or features that do not carry over between the tools.
- Edits made in the developer designer can still be opened in the business-user tool, or the vendor states clearly that they cannot.
Red flags
- Moving between the tools requires an export, a conversion utility or a manual rebuild.
- The answer describes a planned capability rather than current behavior.
- The vendor offers only one authoring tool but describes it as serving both audiences, with no detail on how.
2. For each of these interface types, state whether your bots target individual elements through the interface's object or accessibility model, through image or text recognition on the screen, or not at all: browser, installed desktop application, remote desktop or virtual app session, mainframe terminal emulator, ERP thick client.
Why it matters. Interfaces that a bot can reach only through image or text recognition depend on resolution, scaling and theme settings. If the buyer does not know which method applies to each target, the maintenance budget is set without that dependency in view.
3. Does your designer let a developer raise a business exception as a type distinct from a system exception?
Why it matters. If invalid data and application failures are handled the same way, bots retry records that can never succeed. Those retries waste runner time and hide real system faults among data problems.
Capability areas
Bot Design & Development (10)
The designer, recorder, low-code and code-level authoring, reusable components and libraries, variables and data handling, and step-through debugging used to build automations. Excludes selector resilience (RES), release management (ALM) and AI or document services (AGT, DOC).
UI Targeting & Selector Resilience (12)
How bots locate and act on elements in web, desktop, Citrix or virtual-desktop, terminal and SAP GUI interfaces, including fallback targeting, computer-vision targeting, self-healing behavior and the effort needed to repair a bot after a screen change. Excludes general exception logic (EXC) and API-based alternatives (API).
Exception Handling & Recovery (10)
Business and system exception modeling, retry and back-off rules, checkpointing and resume of long runs, recovery of half-completed transactions, and how a failed bot reports its state instead of stalling silently. Excludes queue-level retry configuration in the orchestrator (ORC) and estate-wide dashboards (MON).
Orchestration, Scheduling & Work Queues (12)
Central control of unattended bots: triggers and schedules, work queues and item priority, load balancing across bot runners, runner and machine pool management, concurrency limits and calendar-aware scheduling. Excludes the hosting substrate and region selection, which the deployment-hosting module covers.
Attended Automation & Human Handoffs (8)
Bots that run on a user's desktop alongside a person, user-triggered automations, in-flow forms and prompts, and handing work items between bots and people for review or approval. Excludes AI-specific oversight controls, which the ai-human-oversight topics in AGT and the ai-agentic-autonomy module cover.
Version Control, Testing & Release Management (10)
Source control of automation packages, branching and peer review, environment promotion from development to test to production, automated testing of bots, dependency and package versioning, rollback, and conversion of automations built on another RPA platform. Excludes the platform vendor's own software release practices.
Bot Credentials, Access & Estate Governance (11)
Vaulting and rotation of the credentials bots use to log in to target applications, orchestrator role-based permissions, the audit trail of every bot action, center-of-excellence controls, and guardrails that keep citizen-developer automations inside policy. Excludes vendor-level security posture and certifications (security and compliance-certifications modules).
Document Understanding & IDP (11)
Classification and extraction from structured, semi-structured and unstructured documents, confidence scoring, human validation stations, model training on the buyer's document types, and passing extracted data into bots. Excludes general LLM and agent orchestration (AGT).
AI & Agentic Automation (10)
Calling LLM and GenAI services from automations, designing AI agents that work alongside deterministic bots, passing work and context between agents and bots, and the in-product guardrails and logging that apply to those steps. Excludes vendor-wide model governance, AI safety and cost accounting (ai-model-governance, ai-safety and ai-cost-finops modules).
API-First Automation & Connectors (10)
Pre-built application connectors, native API and database actions inside automations, custom connector creation, open agent-protocol interoperability, and the path for converting an existing UI-driven step to an API call. Excludes the platform's own public APIs and identity integration (integration module).
Process & Task Discovery (8)
Process mining from system event logs, task mining from desktop activity, candidate scoring on volume, stability and API availability, and handing a discovered process into the build tooling. Excludes monitoring of processes that are already automated (MON).
Operational Monitoring & Automation Analytics (11)
Live visibility of bot runs and queue health, alerting on failures and service-level breaches, per-automation run history and logs, business-outcome and ROI reporting, and tracking maintenance effort per bot. Excludes the vendor's own platform uptime reporting (support-operations module).
Questions about this package
How many Robotic Process Automation (RPA) RFP questions are there?
123 solution questions in 12 capability areas: 27 for the RFI, 62 for the RFP and 34 deep-dive questions for the finalists. The workbook adds 100 due-diligence questions on security, integration, implementation and exit.
What comes with each question?
Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.
Can I edit the questions?
Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.
Which license do I need?
The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.