Pillar guide

The procurement process, end to end

Eight stages, from someone noticing a need to deciding whether to renew. For each one: what happens, the control that makes it trustworthy, who owns it, and the metric that tells you it is working.

Aaron Grainger · 24 min read · Updated August 2026

In short

The procurement process has eight stages: identify the need, specify it, source suppliers, approve the requisition, issue a purchase order, receive the goods or services, match the invoice against the order and receipt, and review the supplier before renewal. Control is strongest at approval, because that is the last point where spend can be stopped at no cost.

Most companies already perform all eight stages. What varies is whether each stage is deliberate, owned, and recorded — or whether it happens implicitly in someone's inbox. The difference shows up as cycle time, budget surprises, and the amount of forensic work finance does at close.

Use this guide in one of two ways. If you are building a process, treat each stage as a design question and start with the earliest point where evidence is missing. If you are auditing an existing process, trace ten purchases end to end and identify the first stage where the official record diverges from what people actually did. Fixing that first weak handoff usually improves several downstream measures at once.

01

Need identification

Someone establishes that a purchase is required and describes what problem it solves, not just what product they want.

Control
A request form that asks for the outcome and the budget line, so alternatives can still be considered.
Owner
Requester
Metric
Share of requests with a stated business justification

Inputs

An available budget line, prior spend for the category, current contracts, and enough context to distinguish a new need from an extension of something already bought. The requester does not need a finished specification, but they must describe the business outcome, timing, likely users, and consequence of doing nothing.

Output

A structured request record with an outcome statement, estimated value band, budget code, urgency, and named requester. It should be useful even if procurement recommends a different product or supplier. A pasted supplier quote is supporting evidence, not the definition of need.

Owner decision

The requester and budget owner decide whether the need is real, timely, and worth investigating. They are not yet choosing a supplier. Keeping that separation matters: once a preferred product is framed as the need, alternatives become politically harder to consider even when no commitment exists.

Handoff failure

A vague request such as ‘need a laptop’ or ‘renew analytics’ reaches sourcing after somebody has already selected a vendor. Procurement receives a done deal, specification becomes reverse engineering, and approval measures compliance with paperwork rather than control over commitment.

Worked example

Adding ten seats to an existing email platform should trigger a check against the current agreement, renewal date, and unused licences. A warehouse-racking project is genuinely new: it needs site constraints, load requirements, and a safety owner before anyone asks suppliers for prices.

Metric caveat

A 100% business-justification completion rate proves only that a required field contains text. Sample ten requests each month and ask whether another approver could understand the outcome and challenge the purchase without opening an email thread.

Go deeper: Writing a one-page procurement policy

02

Specification

The need becomes a specification precise enough that two suppliers would quote comparably.

Control
Category templates for recurring purchases; technical review for anything unusual.
Owner
Requester with category owner
Metric
Quote variance within a category

Inputs

The approved need statement, a category template where one exists, expected volume, delivery constraints, and any technical, safety, privacy, or regulatory requirement. Existing standards should be visible here so requesters do not specify an incompatible item by accident.

Output

A specification precise enough that two unrelated suppliers would price the same obligation. For goods, that means dimensions, quantities, delivery location, and acceptance criteria. For services, it means deliverables, milestones, assumptions, responsibilities, and a definition of done.

Owner decision

The category or technical owner decides whether the requirement is standard enough for a catalogue or preferred supplier, or unusual enough to require design review. This decision determines downstream effort; treating every monitor like a project wastes time, while treating a data migration like a commodity hides risk.

Handoff failure

Suppliers quote against different assumptions. The lowest response excludes implementation, one includes support, and another prices a different service level. Approval then compares totals that look commensurate but are not, and the missing scope returns later as change orders or invoice variance.

Worked example

A broken standard monitor can use a template with an approved model and delivery address. A bespoke office fit-out needs drawings, access windows, materials, safety requirements, milestones, and acceptance sign-off before a credible competitive quote can exist.

Metric caveat

Low quote variance does not necessarily indicate a clear specification. It may mean only one supplier responded or all bidders copied the incumbent price. Read variance beside supplier count, clarification volume, and the number of commercial assumptions in each response.

03

Sourcing

Identify suppliers and gather quotes or proposals proportionate to the value and risk.

Control
Competitive quote thresholds defined in policy; preferred suppliers surfaced first.
Owner
Procurement
Metric
Spend under contract

Inputs

A comparable specification, the policy threshold that determines the form of competition, a list of qualified suppliers, evaluation criteria, switching constraints, and a realistic timetable. If the requirement is still changing materially, sourcing has started too early.

Output

Comparable offers, clarification records, a short evaluation note, and an awarded commercial position that future requesters can find. The result is not merely a selected supplier; it is reusable pricing, scope, and decision evidence tied to a contract or preferred channel.

Owner decision

Procurement decides whether the incumbent's continuity outweighs a challenger's price or capability. That is a judgement about transition cost, operational risk, and future leverage—not a mechanical choice of the lowest cell in a spreadsheet.

Handoff failure

Negotiated terms remain in a buyer's inbox. The next requester cannot discover the agreement, buys elsewhere, and creates apparent non-compliance. The company then reports low spend under contract despite having completed the commercial work required to create a contract.

Worked example

Office supplies under a current framework need a catalogue lookup, not a new competition. Entering a new logistics region may require an RFP, lane data, site validation, references, and several weeks of implementation planning before award.

Metric caveat

Spend under contract is easy to inflate by counting every invoice from a contracted supplier. Count only spend for which the relevant scope and pricing terms apply. A legal agreement with the supplier does not mean every purchase from it used negotiated terms.

Go deeper: RFI vs RFQ vs RFP: which to send

04

Approval

The requisition routes to the people who can genuinely assess it, with budget position visible.

Control
Thresholds by amount, category, and department; parallel routing; standing delegates.
Owner
Budget owner, finance
Metric
Median requisition-to-approval time

Inputs

A complete requisition, expected total commitment, identified budget owner, current budget position, category and entity rules, and any specialist review triggered by the purchase. The approver needs decision evidence, not a notification that asks them to reconstruct context.

Output

An approved, rejected, or returned request with a named decision-maker, timestamp, comments where needed, and preserved version of the evidence reviewed. Approval should unlock the next action; it should not require somebody to re-enter the same facts elsewhere.

Owner decision

The budget owner judges need and priority; finance confirms affordability and coding where required; specialists judge a bounded risk. These are different decisions. Combining them into a generic approval step obscures accountability and encourages reviewers to assume somebody else checked the difficult part.

Handoff failure

A manager approves verbally or in chat before the request exists. The supplier starts work, and the formal workflow becomes retrospective documentation. Rejection is no longer credible, so a fast approval time can actually indicate that the control was bypassed upstream.

Worked example

A recurring subscription inside an agreed budget may need one budget-owner confirmation. A capital purchase spanning departments can route finance and department approvals in parallel, followed by executive authority only when the combined commitment crosses the delegation threshold.

Metric caveat

Median approval time hides stuck requests and can reward informal pre-approval. Publish the 90th percentile, rejection and return rates, and the share of requests where supplier commitment predates approval. Speed is useful only while the decision remains real.

Go deeper: Designing an approval workflow people use

05

Purchase order

The approved request converts into a purchase order and is issued to the supplier.

Control
PO generated from approved data, not retyped; terms attached automatically.
Owner
Procurement or the system
Metric
PO coverage rate

Inputs

The approved request, verified supplier master record, accepted quotation or contract, delivery details, tax treatment, and line structure appropriate for receipt and invoicing. The PO should inherit these facts rather than invite another round of typing.

Output

An issued purchase order with a unique number, clear lines, terms, delivery instructions, and supplier acknowledgement where material. Its structure must survive into receipt and invoice matching; a round-number PO for a milestone contract is not operationally complete.

Owner decision

The process owner decides which POs can be generated automatically and which need commercial review. Manual intervention should correspond to a genuine ambiguity or high-consequence term, not to an administrative habit inherited from a previous accounting system.

Handoff failure

The requisition is approved as one total while the PO, receipt, and invoice use different units or milestones. Matching fails even though the commercial event is legitimate. Accounts payable then repairs a data-structure problem created before the order was issued.

Worked example

Routine stock replenishment can produce a PO with no human touch once quantity rules are met. A consulting engagement may need milestone lines aligned to acceptance points, with expenses and change control separated so later invoices can be evaluated cleanly.

Metric caveat

PO coverage can be manufactured by creating orders after invoices arrive. Measure whether the PO was issued before the invoice—and preferably before supplier commitment. Coverage without sequence is a record-keeping statistic, not evidence of pre-purchase control.

Go deeper: Requisition vs purchase order

06

Receipt

Goods or services are received and recorded, including partial deliveries and shortfalls.

Control
One-tap receipting by the requester, prompted on the expected delivery date.
Owner
Requester or site receiver
Metric
On-time, in-full delivery rate

Inputs

An open PO, expected delivery date and quantity, a designated receiver, acceptance criteria, and a way to record partial, substituted, damaged, or rejected delivery. For services, define who can confirm a milestone and what evidence supports acceptance.

Output

A timestamped receipt tied to the correct PO line, recording quantity and condition close to the actual event. Where the delivery is partial, the remaining balance stays visible. Where acceptance is disputed, the record should explain why rather than pretending nothing arrived.

Owner decision

The receiver decides whether delivery satisfies the order. That can be a count at a loading dock or a judgement that a service milestone is complete. The role should sit with the person able to observe performance, not automatically with procurement or accounts payable.

Handoff failure

Goods arrive and are used, but nobody records receipt. The invoice enters an exception queue and finance chases a requester weeks later. Payment ultimately proceeds on trust, eliminating the control and damaging supplier relationships through avoidable delay.

Worked example

A warehouse can scan a pallet against the PO in seconds and record a shortage immediately. A consulting deliverable may require the project owner to approve a milestone after reviewing work; calling that action a goods receipt does not make it objective.

Metric caveat

On-time, in-full performance is meaningful only when receipts are timely and accurate. Late internal recording can make a reliable supplier look late, while routinely accepting short deliveries as complete can make performance look perfect. Audit receipt discipline before publishing a scorecard.

Go deeper: What to fix before buying AP automation

07

Matching and payment

The invoice is matched against the purchase order and the receipt, then scheduled for payment.

Control
Two- or three-way matching with category tolerances; exceptions to the budget owner.
Owner
Accounts payable
Metric
Touchless invoice rate and exception rate

Inputs

The supplier invoice, PO, receipt or service acceptance, category-specific tolerance rules, tax treatment, and a clear owner for each exception type. Invoice capture must preserve enough line detail to compare what matters rather than only the grand total.

Output

Either a validated invoice scheduled under agreed payment terms or a specific exception routed to someone able to resolve it. The output should state whether price, quantity, tax, duplication, supplier identity, or receipt failed—‘needs review’ is not a useful queue reason.

Owner decision

Finance and procurement decide which variances can clear automatically. Tolerance is risk appetite expressed as a rule: too tight and harmless freight differences consume the team; too loose and repeated overbilling becomes invisible.

Handoff failure

Every mismatch lands in a generic AP queue. Staff can see the problem but cannot confirm delivery or renegotiate price, so they forward messages until the payment deadline passes. A control designed to prevent error becomes a source of late fees and supplier escalation.

Worked example

A utility invoice may use two-way validation against contract and account data because no receipt exists. Capital equipment may require PO, physical receipt, and commissioning acceptance before the invoice can clear. The matching design should follow the evidence available.

Metric caveat

A blended touchless rate rewards simple recurring categories and hides difficult project spend. Segment by invoice population and disclose exclusions. Matching also proves consistency among records, not that the original purchase was sensible or free from collusion.

Go deeper: Three-way matching explained

08

Review and renewal

Performance is assessed and the decision to renew, renegotiate, replace, or exit is made before the notice deadline.

Control
Renewal register with calculated notice deadlines and a named owner per agreement.
Owner
Supplier owner
Metric
Contract renewal lead time

Inputs

The executed contract and amendments, notice clause, usage and performance evidence, current pricing, business owner, switching requirements, and sufficient lead time to test alternatives. The operative date is usually the notice deadline, not the renewal anniversary.

Output

A documented decision to renew, resize, renegotiate, replace, or exit before leverage disappears. The outcome updates pricing, ownership, notice dates, and next review triggers so the following cycle does not begin by rediscovering the same documents.

Owner decision

The supplier owner judges value and switching cost; procurement tests commercial position; legal confirms notice where necessary. Underperformance does not automatically justify replacement, because migration cost and operational disruption may exceed the recoverable value.

Handoff failure

The notice deadline sits inside a filed PDF, passes without action, and the agreement renews automatically. The next need-identification cycle starts with an unwanted commitment already in force, leaving budget owners to rationalise a decision the calendar made for them.

Worked example

A software renewal with a sixty-day notice clause should open review months before that deadline, using active seats and roadmap need. A facilities contract may require a full re-tender and transition plan, so review must start much earlier than a simple negotiation.

Metric caveat

Renewal lead time measures discipline, not decision quality. A file opened 120 days early but left untouched until the deadline is not healthy. Track when usage was reviewed, alternatives considered, and an accountable decision actually made.

Go deeper: Contract renewal management

Where most processes break

Three failures account for the majority of what goes wrong, and all three sit between stages rather than inside them.

  1. 1Approval happens after commitment, so the approval becomes a formality.
  2. 2Sourcing decisions never reach the requester, so negotiated contracts go unused.
  3. 3Receiving is skipped, so matching fails and accounts payable absorbs the cost.

Commitment arrives before control

A requester emails a supplier, accepts a proposal, or asks work to begin. Only then does somebody create the requisition. Stage 04 still records an approval and stage 05 still produces a purchase order, so the records appear complete. But the approver has no credible option to reject without cancelling work or damaging a relationship. The first stale metric is approval time: it may improve because the real decision happened elsewhere. Test the control by comparing supplier-commitment evidence with approval timestamps, not by checking whether an approval record exists.

Sourcing knowledge never reaches demand

Procurement negotiates a preferred agreement in stage 03, stores it in a contract folder, and considers the project complete. The next requester cannot discover the supplier or price while identifying a need, so they search the market again. The resulting invoice is labelled maverick even though the operating failure is poor distribution of sourcing knowledge. Spend-under-contract deteriorates first, then supplier count and price variance follow. Put the negotiated route in the requester's path and test whether an unfamiliar employee can find it without asking procurement.

Receipt becomes an accounts-payable problem

Delivery happens at stage 06 but the record does not. When the invoice arrives, matching fails and accounts payable asks whether goods or services were received. By then the requester may not remember quantities, the original receiver may be on leave, and the supplier is already counting payment days. Exception age rises before the touchless rate falls because invoices sit unresolved. The fix is not more AP capacity; it is a prompt and accountable receiver close to the delivery event.

A 90-day sequence for fixing it

This sequence assumes an executive sponsor will enforce one pilot department's rules and that the team can obtain at least six months of invoice and purchase-order data. Without those conditions, spend the first month securing ownership and access rather than pretending configuration has started.

WeeksFocusOutcome
1–2Map current spend and approval realityAn honest baseline for cycle time and PO coverage
3–4Redesign thresholds from the spend distributionA one-page policy people can follow
5–8Roll out requisitions and POs in one departmentProof the compliant path is the fast path
9–12Extend to remaining departments and enable matchingTouchless invoices and a visible maverick rate

Weeks 1–2: produce an honest baseline. Build a transaction-level file showing whether each addressable invoice had a request, approval, PO, and receipt, and when each appeared. Trace outliers with the people involved. Leadership's required decision is which population and department will form the pilot.

Weeks 3–4: turn evidence into operating rules. Draft a one-page threshold policy and a routing matrix tied to budget ownership and risk triggers. Test both against recent purchases, including emergencies. Leadership must approve the exceptions explicitly; unresolved exceptions become private workarounds after launch.

Weeks 5–8: run real purchases through the pilot. Configure only the common path and consequential variants, train requesters using their own examples, and review every exception daily. Metrics may worsen because previously invisible off-process work is now recorded. Explain that visibility change before a CFO mistakes it for regression.

Weeks 9–12: stabilise before expanding. Reconcile approved orders to accounting, remove duplicate suppliers, tune tolerances, and publish cycle-time distributions with exception reasons. Expansion should be conditional on clean handoffs, not on the calendar. A second department inherits the corrected process, not the pilot's unresolved backlog.

What ninety days will not fix

Three things routinely run past the quarter, and pretending otherwise is how these programmes lose credibility with a CFO. Supplier data cleanup is slower than anyone estimates, because merging duplicate records means calling suppliers to confirm which legal entity you actually contract with. Accounting integration stalls whenever the chart of accounts is mid-revision. And a department whose budget owner has not agreed their thresholds will simply not go live — that is a management conversation, not a configuration task.

Baselines for weeks 1–2 come from a spend analysis, and the numbers worth tracking from week 12 onward are in procurement KPIs.

Ninety days also does not reset supplier relationships. New notice periods, payment habits, ordering channels, and data expectations take longer to become normal. Expect early reporting to expose more uncontrolled activity than the baseline suggested. That is useful discovery, provided the team keeps definitions stable and explains why a temporarily worse number can represent a healthier control environment.

Supporting articles

Each stage in more depth.

See Procura Flow on your own purchase orders

A 30-minute walkthrough using your categories, approval thresholds, and supplier list.

Book a demo