Membership software · a vendor-neutral guide
Membership software: how to choose an AMS or CRM
What you need, the questions to ask in every demo, and how to run the procurement — for UK professional bodies, trade associations, membership charities and clubs.
No rankings and no vendor names: a shortlist is only as good as the requirements you judge it against.
One member record, used by membership, finance, events, education, comms
Choosing membership softwarein five steps
- 01Needswhat the system must do, in writingSPECIFY
- 02Marketa long list, then a short oneENGAGE
- 03Demoyour scenarios, scored the same wayTEST
- 04Contractdata terms and a way outPROTECT
- 05Migrateclean data, parallel run, switchMOVE
Judged onone clean member record
01/ which system
AMS, CRM or CMS: which do you need?
Three acronyms, three different jobs. Most membership bodies need two of them, joined up.
An AMS — association management software, also sold as membership management software — runs the membership itself: joining, grades, renewals, payments, events, CPD and the member record behind them.
A membership CRM manages relationships: contacts, organisations, interactions and pipelines. A general CRM can hold members, but renewal cycles, grades and Direct Debit usually have to be built on top. A membership database is the record either one keeps; a spreadsheet stops being one the day two teams edit it.
A CMS runs your website and a member engagement platform adds community, apps or learning. Both should read the AMS record, not keep their own. The CMS and member portal are website decisions; this page covers the system underneath.
Which system fits you? · 0/5 answered
01How do members join and pay?
02Do you run events or CPD for members?
03How many membership grades or categories?
04Where do members update their details?
05Who else uses the member record?
Answer all 5 to see your result.
A way to frame the decision, not a published benchmark.
02/ the jobs
What membership software must do
Six jobs, whatever the product is called. If a system cannot do one, something else has to — and that is where double entry starts.
One record per member
People and organisations, grades, history, consent and preferences.
Joining online
Application, approval where needed, payment and a welcome, in one flow.
Renewals and payments
Card, Direct Debit and invoice; reminders; failed-payment recovery.
Events, CPD and groups
Bookings at member rates, CPD records, committees and communities.
Communications
Email and segments that respect each member’s consent.
Reporting
Retention, lapses, income and engagement, without an export.
The same survey names the three operational challenges its respondents hit most: inadequate integration between the membership system and the website, incorrect or incomplete data, and multiple databases and silos. None of them is a feature gap. All three are decided at selection — which is why the next section starts with what you need, not with what vendors show. Once the record is clean, member engagement and retention reporting become things the system can measure.
03/ requirements
A requirements checklist
Write requirements as outcomes — “a lapsed member can rejoin online without calling us” — not as features copied from a brochure. Mark each one must, should or could, and agree the musts with finance, events and IT before any vendor sees them.
Tick what your specification already covers. Anything unticked is a question a vendor will answer for you, in their favour.
The GOV.UK Technology Code of Practice is written for government, but three of its points travel well: define user needs, make things accessible, and integrate with what you already run.
Your specification · 0/14 in place
Each gap is a question for the demo — and a line in the contract.
Accessibility: GOV.UK’s guide to WCAG 2.2 explains level AA, the standard its own services must meet.
04/ demo questions
Demo questions to ask every vendor
Send your scenarios before the demo and ask every vendor the same questions, in the same order. Copy them from here.
Records and data
Ask them to show it, live, on your scenario.
- Show one member who belongs as an individual and through their employer.
- Where is consent recorded, and what happens when a member withdraws it?
- How do you stop duplicate records at import and at sign-up?
- Which fields can we add ourselves, without paying for development?
- Show the audit trail for a change to a member’s grade.
Joining and renewals
- Join as a new member on a phone, start to finish, including payment.
- Renew a lapsed member without staff involvement.
- Change a grade mid-year: how is the price pro-rated?
- Which renewal reminders can we schedule, and by which channels?
- How does a member cancel an auto-renewing membership?
Payments
- Which payment providers do you support, and who holds the card data?
- Can we see the payment provider’s PCI DSS Attestation of Compliance?
- Do you support Direct Debit through a Bacs bureau or our own Service User Number?
- How are failed payments retried, and how is the member told?
- How do payments reconcile with our accounting system?
Integration
- Is there a documented API, and is it included in the price?
- Which website CMSs do you integrate with, and who maintains it?
- Can members sign in once for the website, portal and learning?
- How do email tools receive segments and return unsubscribes?
- Show a live integration another customer runs today.
Security and hosting
- Where is our data stored and processed, and by which sub-processors?
- Is multi-factor authentication on by default for staff?
- Which independent certifications do you hold: Cyber Essentials, ISO 27001, SOC 2?
- How are we told about a breach, and how fast?
- When were you last penetration-tested, and can we see the summary?
Price, support and exit
- What does year three cost, including every module we saw today?
- What is not included: implementation, migration, training, API calls?
- How are price rises set at renewal?
- How do we get all our data out, in what format, and at what cost?
- At the end of the contract, do you return and delete our data?
Score answers during the demo, not after it. Two of those questions come straight from regulators’ guidance: the NCSC’s lightweight approach to cloud security asks where data is processed and expects two-factor authentication, ideally on by default; the ICO’s list of what a processor contract must include ends with returning or deleting your data.
05/ the tender
Running a membership software tender
If you are a public body, the rules may already be set. The Procurement Act 2023 has applied since 24 February 2025, and it binds “contracting authorities”: under section 2, bodies wholly or mainly publicly funded, or under public oversight, that do not operate on a commercial basis. The government’s announcement describes rules “that all public bodies must follow”. Most membership organisations are not caught — check your own funding and governance before assuming either way.
Everyone else can borrow the shape: a written specification, market engagement, the same questions to every bidder, and a scored decision the board can sign off. It is the same discipline behind RFP software for UK public tenders, a sister site.
Define
Agree the requirements
Musts, shoulds and coulds, signed off by every team that uses the record.
Engage
Talk to the market
A short brief to a long list; drop anyone who cannot meet a must.
Invite
Issue one specification
Scenarios, questions, scoring weights and a deadline, identical for all.
Test
Run scripted demos
Your scenarios, your data, scored live by a panel.
Check
References and due diligence
Customers of your size, security evidence and the contract draft.
Decide
Score, then negotiate
Highest score wins the negotiation, not the contract. Exit terms first.
06/ integration
Integrating with your website and payments
The website is where members join, renew and sign in, so the AMS–CMS join is the one that shows. MemberWise’s UK research found 35% of organisations had not integrated their AMS with their website CMS, citing cost, time and incompatibility — 2021 research, so treat it as direction, not today’s number. How the website side is built is covered on our membership website page.
Payments carry their own rules. Card data belongs with a PCI DSS-compliant provider: PCI SSC’s SAQ A is for merchants whose card handling is “completely outsourced”, and it expects you to have reviewed your provider’s Attestation of Compliance. Direct Debit runs through Bacs — directly, through an approved bureau, or via a facilities-management provider.
Renewal notices are about to matter more. The subscription rules in the Digital Markets, Competition and Consumers Act 2024 are due in January 2027, and No 10 says businesses “will need to provide clearer up-front information, regular reminders and a much easier exit”. Ask how the system will send those reminders and handle cancellations — before you sign, not in 2027.
→ The website reads the record; it never keeps its own.
→ Fully outsourced card handling keeps your PCI scope smallest.
→ The system, not a person, should read the Bacs reports.
Bacs FAQs: the default advance notice, absent another agreement, is at least 10 working days plus postal time; from 1 July 2027 it will not be possible to apply for a non-AUDDIS Service User Number.
07/ migration
Migration and data cleansing
Migration is the moment to fix the data, not copy it. The ICO’s accuracy principle asks you to take reasonable steps to correct or erase data that is incorrect or misleading, and its storage limitation guidance says you must not keep personal data longer than you need it — so records you could not justify keeping should not make the move.
New technology holding members’ personal data is also a trigger to screen for a DPIA; the NCSC notes its own cloud security assessment does not replace one. And the old supplier’s contract should already say what happens next: return or delete, at your choice.
Plan a parallel run through at least one renewal batch. Only switch off the old system when both produce the same members, the same amounts and the same reminders.
01 · Audit
Know what you hold
Every source, every field, who owns it and why you keep it.
02 · Cleanse
Fix before you move
Merge duplicates, correct errors, delete what you cannot justify.
03 · Map
Field to field
Old fields to new, with a rule for every mismatch.
04 · Trial load
Load a copy, then check
Count records, totals and consent flags against the source.
05 · Parallel run
Run both, compare
Same renewal batch through both systems; differences explained.
06 · Switch
Switch, then close
Go live, confirm deletion or return from the old supplier.
08/ total cost
Budget and total cost of ownership
The licence is the number on the quote; it is rarely the biggest. Add implementation, migration, integrations, training, staff time and the cost of leaving — then look at the total over the life of the contract.
Plan for overruns you cannot see yet. In Flyvbjerg and Budzier’s study of 1,471 IT projects, the average cost overrun was 27%, and one in six overran by 200% on average. They suggest a stress test: could you take the hit if a project overran by 200%?
Skills are the other hidden cost. UK professional bodies told PARN and Buzzacott that lack of skill is their biggest barrier to automation and AI — ahead of security and quality concerns.
Security is a cost line too: Cyber Essentials, the minimum standard the government recommends, is priced by organisation size and starts at £320 plus VAT.
Your quotes and effort
Total cost over 5 years
£168,180
One-off work with contingency, plus 5 years of licence, upkeep and staff time.
One-off vs recurring
Cumulative cost, year by year
The licence is the smaller part
On these numbers the licence is 36% of the total. Negotiate the rest as hard as the price per year.
Our arithmetic on your inputs. The starting values are placeholders — replace them with your quotes. The 27% contingency is the average cost overrun across 1,471 IT projects in Flyvbjerg and Budzier’s study for HBR (2011, mostly public-sector and US); the stress test applies the 200% average overrun of the one project in six they call a “black swan”.
Barriers to automation and AI, UK professional bodies
- Lack of skill76%
- Security concerns57%
- Quality concerns48%
- Budget14%
- Staff resistance14%
09/ questions
Membership software — questions
15 minutes · video or phone
Choosing membership software?
Book 15 minutes. Bring your current systems and your renewal process; leave with the requirements that matter most for your members.
- 0115 minutes, video or phone
- 02Your must-have requirements, named
- 03Where your member data leaks today
- 04A plain next step
Pick a day that suits · live availability

Book 15 minutes · no obligation
Choose the system your members will use.
Vendor-neutral: this page ranks no products and names no favourites.
11/ sources
Every claim, and where it came from
Vendor, US and dated sources are labelled as such. rfp.quest is a sister site, linked for navigation, never as evidence.
- iMIS (ASI) — 2026 Membership Performance Benchmark Report (71% invest; 73% cloud; 43% data access)Vendor survey, 400+ respondents, 76% US
- MemberWise — Digital Excellence Report 2021: over a third need to take action (35% not integrated)UK sector network, 2021
- Harvard Business Review — Flyvbjerg and Budzier, Why your IT project may be riskier than you think (2011)Oxford research, 1,471 projects
- PARN with Buzzacott — Financial benchmarking for professional bodies 2026 (barriers to automation)UK sector research
- Information Commissioner’s Office — What needs to be included in the contract? (Article 28)UK regulator guidance
- Information Commissioner’s Office — Principle (d): AccuracyUK regulator guidance
- Information Commissioner’s Office — Principle (e): Storage limitationUK regulator guidance
- Information Commissioner’s Office — When do we need to do a DPIA?UK regulator guidance
- legislation.gov.uk — Procurement Act 2023, section 2: contracting authoritiesUK statute
- legislation.gov.uk — Procurement Act 2023 (Commencement No. 3) Regulations 2024: 24 February 2025UK statutory instrument
- legislation.gov.uk — Digital Markets, Competition and Consumers Act 2024, Part 4 Chapter 2UK statute (not yet in force)
- Cabinet Office — New public procurement rules now in force (25 February 2025)UK government department
- Prime Minister’s Office — Subscription rules to come into force in January 2027 (9 August 2026)UK government press release
- Government Digital Service — The Technology Code of PracticeUK government guidance
- GOV.UK Service Manual — Understanding WCAG 2.2UK government guidance
- National Cyber Security Centre — Choosing a cloud providerUK government security agency
- National Cyber Security Centre — Lightweight approach to cloud securityUK government security agency
- National Cyber Security Centre — Cyber Essentials overview (from £320 + VAT)UK government certification scheme
- PCI Security Standards Council — PCI DSS v4.0 Self-Assessment Questionnaire AIndustry security standard
- Bacs — Getting started with Direct DebitUK payment scheme operator
- Bacs — FAQs: advance notice and AUDDISUK payment scheme operator
- rfp.quest — RFP software for UK public tendersSister site · navigation only