CYBORIUM article header reading Procurement risk starts before the contract, over a connected node graphic.

Procurement risk is the risk that the buying process itself produces the wrong outcome: the wrong provider, the wrong scope, or a contract that cannot be defended later. It is distinct from delivery risk. A project can be run well and still fail because the decision that started it was made on incomplete information.

What is procurement risk in IT and cybersecurity?

In technology buying, procurement risk shows up in four places: requirements that do not describe the actual need, a shortlist that never included the best-fit provider, evaluation evidence that cannot be reconstructed afterwards, and commercial terms that leave no way out. Each is created before implementation starts, and each is expensive to unwind after signature.

The scale of the decisions makes this material. Gartner forecasts Australian IT spending to reach A$172.3 billion in 2026, up 8.9 per cent on the previous year, with software the largest single category. Cybersecurity buying carries an additional dimension: the Australian Signals Directorate received more than 84,700 cybercrime reports in FY2024-25, an average of one every six minutes, and the average self-reported cost per report for businesses rose 50 per cent to $80,850 (ASD Annual Cyber Threat Report 2024-25). A security control that does not work as described becomes a security problem as well as a procurement one.

Why procurement risk is routinely underestimated

The most reliable evidence that buying processes fail is that decision owners say so. Gartner found that 60 per cent of technology decision owners involved in renewal and expansion decisions regret nearly every purchase they make, a six point increase on 2020. An earlier Gartner survey found 56 per cent of organisations reported a high degree of regret about their largest technology purchase in the preceding two years.

What matters is the stated cause. In both cases the regret is attributed less to the products than to the buying process: unclear requirements, no consensus among stakeholders, and decisions made without comparable evidence. That is a procurement failure, and it is addressable.

Three assumptions do most of the damage. That a known brand is a proxy for fit. That one detailed proposal is enough to judge value. That price can be compared without normalising what each price actually includes.

The most common sources of procurement risk

Incomplete or misaligned requirements

Vague requirements produce proposals that cannot be compared, because each provider has answered a slightly different question. The usual failure is a requirements list where almost everything is marked mandatory. The DSDM framework that defines MoSCoW prioritisation sets an explicit ceiling here: no more than 60 per cent Must Have effort, with around 20 per cent held as Could Have contingency, and it states that levels above 60 per cent introduce a risk of failure. A list where everything is mandatory has stopped being a prioritisation.

Vendor bias and conflicts of interest

Bias is usually structural rather than deliberate. Where the party running the evaluation also earns margin on the outcome, the incentive is to steer toward what they resell. Reseller relationships, referral incentives and advisors carrying vendor quotas all introduce it. The question worth asking any advisor is direct: who pays you, how much, and does it change depending on which provider is selected.

Inadequate market coverage

Most shortlists are assembled from familiarity: the incumbent, the provider a peer mentioned, and whoever the advisor already works with. Providers who do not participate in analyst processes or spend heavily on marketing are absent from that list regardless of fit. A shortlist built on recall is not a market scan.

Weak commercial and contractual governance

Undefined service levels, uncapped uplifts at renewal, and no exit provisions all convert a good selection into a poor engagement. For regulated entities this is explicit rather than optional: APRA CPS 230 requires the identification of material service providers and the ability to keep critical operations running within tolerance when one fails, and APRA CPS 234 requires assessment of the information security capability of any third party managing the entity’s information assets.

How a structured process reduces the risk

Structure is what makes a decision explainable months later, which is the test that actually gets applied. Reviewing Commonwealth procurement, the Australian National Audit Office has found that where request documentation did not clearly articulate the evaluation criteria, or where records did not adequately explain how assessment outcomes informed the final decision, entities could not demonstrate how they reached a value for money conclusion (ANAO procurement insights). Value for money is the core principle of the Commonwealth Procurement Rules, and boards and audit committees apply the same standard in the private sector.

In practice that means criteria agreed and weighted before the market is approached, mandatory requirements used as pass or fail gates rather than scored items, evidence recorded against each criterion, and commercials normalised so the comparison is real rather than nominal.

How to assess procurement risk before committing to a provider

Set the evaluation criteria before approaching the market

Capability, commercial, risk and delivery-fit criteria agreed with stakeholders in advance remove most of the argument later. Criteria written after proposals arrive tend to describe the leading proposal.

Compare providers side by side, on the same evidence

Comparative evaluation surfaces the trade-offs that a single proposal hides. Gating comes first and removes providers that cannot meet a non-negotiable. Scoring then differentiates between those that remain. Mixing the two lets a provider compensate for a genuine deal-breaker by scoring well elsewhere.

Test claims against something other than the provider’s own material

Capability claims should be verifiable. In cybersecurity that often means asking which maturity level a control has been independently assessed at, and by whom, against the ASD Essential Eight Maturity Model rather than accepting a general statement of alignment.

What makes cybersecurity procurement different

Three things. The regulatory layer is specific and enforceable, covering APRA CPS 234 and CPS 230 for regulated entities and the SOCI Act and enhanced CIRMP Rules for critical infrastructure. Integration complexity is higher, because a security control that does not fit the existing estate produces gaps rather than partial benefit. And a poor selection has security and regulatory consequences as well as commercial ones.

Due diligence on a security provider should therefore cover financial stability, roadmap transparency, independent certification scope rather than certificate status alone, and the evidence behind any maturity claim. Certification scope is the detail most often skipped: a certificate covering a subsidiary or a single product line is not a statement about the service being bought.

Where independent procurement support fits

An independent partner reduces procurement risk when the independence is structural rather than asserted. CYBORIUM does not sell, deliver or invoice technology, and every contract is between the client and the provider the client selects. The procuring organisation pays CYBORIUM nothing. CYBORIUM is paid by the selected provider under a capped, success-based arrangement. The cap limits the incentive to steer a client toward a larger contract or a better-paying provider. It does not remove it, which is why the applicable rate is disclosed on request. The rate varies by provider, and because it is a percentage it grows with the size of the contract. The honest claim is that the arrangement is capped and that providers do not all pay the same rate.

Building a risk-aware procurement capability

Treating procurement governance as a repeatable capability rather than an administrative step is what makes the improvement durable. That means standard evaluation templates, documented decision rationale kept with the contract, and finance, legal, security and operations involved early rather than at signature. The organisations that do this well are not the ones that run a heavier process. They are the ones that can explain, a year later, exactly why they chose what they chose.

Frequently asked questions

What is procurement risk in IT projects?

It is the risk that the buying process produces the wrong outcome: requirements that do not reflect the need, a shortlist that omitted better-fit providers, evaluation evidence that cannot be reconstructed, or commercial terms with no exit. It is created before delivery begins and is expensive to correct after contract signature.

How can organisations reduce vendor selection bias in technology procurement?

Agree and weight the evaluation criteria before approaching the market, separate pass or fail gating from scoring, normalise commercials so prices are genuinely comparable, and check how any advisor involved is paid and whether that payment changes depending on which provider is selected.

Sources

Where to read more

See structured vendor comparison methods, what is vendor due diligence, third-party risk management, MoSCoW prioritisation in purchasing, and guided vendor evaluations.

Also relevant: cybersecurity procurement services and asking vendors for an SBOM, and how these risks played out in practice, and telecommunications infrastructure procurement priorities, and operational risk in sourcing decisions for COOs, and the energy technology procurement report, and AI-specific procurement guardrails.

Share this analysis