| name | design-a-purchase-approval-process |
| category | money |
| description | Create proportionate purchasing controls from request through payment, with clear authority and audit evidence. Use when spend is inconsistent, slow, risky, or weakly documented. |
design-a-purchase-approval-process
Control material risks without making every purchase equally burdensome. Separate requesting, approving, receiving, and paying where practical.
When to use
- Use for company purchasing, purchase orders, vendor onboarding, budget controls, and exception handling.
- Bring in finance, legal, security, privacy, tax, or procurement reviewers according to risk.
Procedure
- Map the current request-to-payment flow, roles, systems, common delays, losses, and regulatory or contractual constraints.
- Segment purchases by amount, category, data access, security, commitment term, geography, and reversibility.
- Define required request fields: purpose, owner, budget, vendor, quote, total commitment, alternatives, renewal, data, and delivery.
- Set an approval matrix by risk and delegated authority, including conflicts and self-approval prohibitions.
- Define when competitive quotes, contract review, security review, purchase orders, or executive approval are required.
- Separate vendor creation, request, approval, receipt confirmation, invoice entry, and payment as proportionately as staffing allows.
- Match contract, purchase order, receipt, invoice, and payment; document permitted tolerances.
- Design urgent and exceptional paths with reason, temporary authority, expiry, and retrospective review.
- Create service targets, status visibility, evidence retention, periodic access review, and exception metrics.
- Pilot on real purchase types and fix bottlenecks before broad rollout.
Failure plan
- Do not split purchases to evade thresholds or use emergency paths for ordinary delay.
- If full segregation is impossible, add independent review and visible compensating controls.
- Do not approve from a quote alone when commitment, renewal, data, or exit terms are unknown.
- Preserve rejected and overridden decisions with reasons.
Done
- Roles, thresholds, required evidence, reviews, exceptions, and retention are explicit
- No participant can silently request, approve, receive, and pay the same material purchase
- The process is tested for both control effectiveness and cycle time