
What Is Procurement Risk and How Do You Manage It?
What Is Procurement Risk and How Do You Manage It?
Wednesday, 26 August 2026
What is procurement risk?
In 2020 and 2021, the Digital Transformation Agency held a contract that was varied ten times over two years, rising from an original value of $121,000 to $4.9 million. The scope moved with it, from advice on a business case to a range of services for four different teams. The Australian National Audit Office found the variations were authorised despite advice from a central procurement area that they weren’t an effective, efficient or ethical use of public resources. Each variation on its own looked small against what had already been committed.
Procurement risk is the chance that a purchase fails to deliver what it was meant to deliver, at the price and on the terms expected. It runs across the whole arc: defining the need, testing the market, evaluating offers, negotiating terms, then managing delivery and eventually exit. Attention concentrates on the tender, which is the visible and deadline-driven part. A good deal of what can go wrong only surfaces years later.
People conflate two things here. Risk of the procurement is the chance the process itself goes wrong, through an unclear specification, a flawed evaluation or a challenge from a losing bidder. Risk in the thing being procured is the chance the goods or services fail, the supplier collapses, the price moves or the technology dates. The treatments differ. One is addressed by running a better process, the other by writing better terms and watching what happens under them.
Where do procurement risks sit?
Four families are familiar enough to need little explanation. Supply risk is a supplier failing, exiting the market or losing the people who made them capable. Financial risk covers price movement, currency exposure, cost escalation and the supplier’s own solvency. Performance risk is work that arrives late, incomplete or below specification, and compliance risk is the conflict of interest or process breach that leaves a decision indefensible.
Four more get less attention until they arrive. Concentration builds when so much depends on one supplier that leaving becomes impractical, which quietly hands them negotiating power. Scope creep accumulates through variations that each seem reasonable at the time. Exit costs are rarely priced at the point of entry. And your supplier’s own subcontractors sit inside your exposure and outside your contract, often without anyone on your side knowing their names.
Should you push risk onto the supplier?
The instinctive answer is yes, and the rules explicitly say otherwise. The Commonwealth Procurement Rules state that as a general principle, risks should be borne by the party best placed to manage them, so entities should generally not accept risk another party is better placed to manage. The same paragraph runs the other way too: when the entity is best placed to manage a particular risk, it shouldn’t seek to inappropriately transfer that risk to the supplier.
Organisations skip that second half, and it costs them. A supplier asked to carry uncertainty about your requirements, your approvals or your own data has three options and all of them are bad for you: price the uncertainty in, decline to bid or accept it and later fail. The rules extend this to insurance, advising entities to limit insurance requirements by reflecting the actual risk suppliers bear in contractual liability caps and not to direct suppliers to take out insurance until a contract is about to be awarded. Requirements that reach past the risk a supplier carries come back as a higher price or a thinner field of bidders.
The proportionality principle sits alongside it. Risk assessment effort should be commensurate with the scale, scope and risk of the procurement. A full risk workshop before buying laptops is waste. The same light touch applied to a ten-year service contract is how organisations end up locked into arrangements nobody examined properly.
Can you outsource a risk along with the work?
Examining how agencies manage cyber security risks in procurement, the Australian National Audit Office (ANAO) stated the principle plainly: when the provision of services is outsourced to external providers, accountability for the good or service and associated delivery outcomes, including managing security risks, remains with the entity. Contracting out moves the work. It leaves the consequences where they were.
The same audit shows how wide the gap can be. Just over half of non-corporate Commonwealth entities reported not fully implementing the protective security policy governing contracted providers. Of three agencies examined in detail, none had a process requiring procurement teams to consult their own cyber security specialists when assessing procurement risk. All three had contract clauses obliging providers to comply with security requirements. Two of them didn’t monitor whether the providers did.
A control that exists only as a clause isn’t a control. Where nobody verifies compliance, what the organisation holds is a documented expectation, and it will hold that comfortably until something goes wrong.
What do the failures have in common?
Australian audit reports come back to two patterns. The first is scope drift through variation, and the Digital Transformation Agency contract is the shape of it: ten variations over two years, none of them individually alarming, a fortyfold rise in value against a scope nobody re-tested.
The second is capability. The ANAO made the point by comparing two agencies running similar high-value maritime surveillance contracts with the same contractor. The Australian Maritime Safety Authority had contract managers with twenty years of experience and low turnover. The Department of Home Affairs had nineteen different people managing the contract between 2006 and 2020, six of whom had relevant experience or formal training and none of whom had been involved in the original tender and negotiation. Nothing in that arrangement broke a rule. It did mean that when questions arose about what had been agreed, nobody involved had been there when it was agreed. The answer had to be reconstructed from files.
How do you manage procurement risk in practice?
The framework isn’t complicated. Australian Commonwealth entities must establish processes to identify, analyse, allocate and treat risk when conducting a procurement and consider risks and their impact when assessing value for money, approving spending and settling contract terms. Those four verbs work as a checklist for any organisation, public or private. The order matters, since allocating a risk you haven’t analysed is guesswork.
Making it work day to day comes down to a few habits. Assess risk before choosing the procurement method, since the method should follow the risk rather than the calendar. Bring in the specialists your organisation already employs, because procurement teams aren’t expected to assess technical, security or clinical risk unaided. Write the risk allocation into the contract deliberately rather than accepting a template. Set a variation threshold that triggers a fresh look rather than another signature. And treat contract handover as a risk event, since knowledge leaving the building is one of the few risks that gets worse with time and never appears on a register.
Holding onto any of it is harder than knowing it, especially when a business unit needs something in three weeks, the specification is still moving and the easiest path is the supplier already sitting on a panel. Saying no, or saying yes with conditions, means knowing which risks matter and being able to explain the reasoning to someone impatient. AcademyGlobal (AG) runs a one-day Procurement Risk Management workshop built around that decision, working through case studies and group exercises rather than a lecture on the framework.
If you want one thing to check on a procurement you’re running now, look for the risk nobody has costed. It tends to be the one both sides assumed the other had covered.
Frequently asked questions
What are the biggest risks in procurement?
Supplier failure, cost escalation, poor performance against specification and probity or compliance breaches that make a decision indefensible. Less obvious but often more damaging are concentration on a single supplier, scope creep through accumulated variations and exit costs that were never priced when the contract was signed.
When should you do a procurement risk assessment?
Before choosing the procurement method, because the method should follow the risk. Reassess when the requirement changes materially, before signing and at each significant variation. A single assessment filed at the start of a multi-year contract records what someone thought once. It isn’t a live control.
Who is responsible for managing procurement risk?
The buying organisation, which can’t transfer accountability by contracting the work out. Within it, responsibility is usually shared between the procurement team, the business area that owns the requirement and specialists in security, legal or technical fields. Named owners for individual risks matter more than which team holds the register.
How much risk should you transfer to the supplier?
Only the risks they’re genuinely better placed to manage. Transferring risks a supplier can’t control doesn’t eliminate them. It prices them into the bid, narrows the field or produces a contract that fails. Liability caps and insurance requirements should reflect the risk the supplier actually bears.
What is supply chain risk in procurement?
The risk arising from your supplier’s own suppliers and subcontractors, who sit inside your exposure while being outside your contract. It covers continuity, quality, security and increasingly modern slavery and sustainability obligations. Managing it usually means contractual visibility of subcontractors plus verification, not assurance alone.
References
Australian Government Department of Finance. Commonwealth Procurement Rules and Commonwealth Procurement Rules: Procurement Risk.
Australian National Audit Office (2022). Management of Cyber Security Supply Chain Risks, Auditor-General Report No. 9 of 2022 to 2023.
Australian National Audit Office (2023). Insights: Audit Lessons, Procurement and Contract Management.