Standardise governance: how it works and what to require
Most manufacturers have adequate procurement policy and inconsistent application. Proconomy makes the policy executable: value, category, entity and risk rules decide the route, thresholds decide what reaches a person, exceptions escalate to named approvers and the evidence is retained without anyone assembling it.
Policy rarely fails on paper. It fails at execution.
Not at the point of writing. At the request, the supplier, the approval and the audit.
At the request
- Route chosen by whoever received the email
- Threshold applied from memory
- Category assigned inconsistently
- Entity rules applied by habit
- Urgency used to bypass the process
- No record of which rule applied
At the supplier
- Purchase from an unqualified source
- Approval scope crossed between entities
- Expired documents not detected
- Onboarding skipped under time pressure
- Sanctions screening done once
- Sub-tier changes never assessed
At the approval
- Delegated authority exceeded
- Approval given without full context
- Segregation of duties breached
- Absent approver bypassed
- Retrospective approval after commitment
- Overrides not distinguishable from approvals
At the audit
- Evidence reconstructed from mailboxes
- Justifications written after the fact
- Policy adherence measured by sampling
- Exceptions counted only when material
- No record of who decided what
- Findings that arrive with a remediation programme
A document people remember. Or rules that execute.
Six mechanisms, and the difference is whether the rule can be bypassed.
| Mechanism | What it has to do |
|---|---|
| Rules applied as part of the work | Value, category, entity and risk select the route automatically, and the rule that fired is stored against the transaction. |
| Qualification enforced at purchase | Approval scope is checked when the order is raised, so an unqualified source cannot be used by habit. |
| Non-bypassable checkpoints | Decisions your policy reserves for people cannot be routed around by any configuration. |
| Escalation instead of bypass | An absent approver escalates to the next authorised person, which removes the most common reason for a workaround. |
| Overrides recorded as overrides | A departure from policy is distinguishable from a routine approval, with its author and reason. |
| Variance measured continuously | Policy adherence becomes a measurement across every transaction rather than a sample taken annually. |
A description of what the practice requires, not a feature list.
One evidence standard. Different question by sector.
What you will be asked to produce, by industry.
Automotive
Can you evidence the change that caused a recall exposure, who assessed it and on what basis?
Aerospace and defence
Can you defend every departure from the approved supplier list, with the authority that permitted it?
Medical devices
Can you produce the supplier qualification file today rather than in three weeks?
Multi-entity groups
Can you show the same policy being applied consistently across every entity?
Five questions. Run on your own workflow.
Each takes minutes and none can be prepared for.
- Ask them to run one of your workflows in the session, on your policy and your thresholds.
- Ask what happens when reality varies from the happy path — that is where most of your work lives.
- Ask which decisions return to a person, and confirm those checkpoints cannot be configured away.
- Ask what the system did without a person overnight, and see the record.
- Ask what they would advise you not to do first.
Definitions. Asked and answered.
No. Group rules define what must be common — competitive sourcing standards, supplier qualification, segregation of duties, audit retention. Thresholds, approvers and local routes remain configurable, which is what makes standardisation survive contact with operations.
By designing them. Each class of exception has a named approver and a required justification, and the decision is retained. Informal exceptions are what create audit findings; designed ones do not.
Yes. Policy, threshold and permission changes are themselves controlled, approved actions and are recorded, so the governance model is as auditable as the transactions it governs.
The rule that applied to each transaction, the approvals given, the exceptions raised and any override, retrievable per transaction rather than reconstructed from several systems.
They create a control requirement, which is why agent permissioning, thresholds and non-bypassable checkpoints exist. An agent operating inside an explicit permission set is generally more reviewable than a person applying policy from memory.
Procurement governance is the framework of policies, authorities, thresholds and controls that determines how purchasing decisions are made and evidenced. It becomes effective when encoded as executable rules applied during the work, rather than as a document consulted afterwards.
A delegation of authority matrix defines who may approve what, at what value, in which entity or cost centre. It fails in practice when it is applied from memory, and it works when it is enforced at the moment an approval is requested.
By retaining, per transaction, the rule that applied, the actions taken, who approved, what was overridden and on what basis — assembled as the work happens rather than reconstructed when an auditor asks.