Procurement
Strengthening Procurement Compliance
Building a risk-aware, compliant procurement process.

The challenge
An automotive components business had grown by acquisition and inherited several purchasing processes along the way. Policies existed on paper, but buying happened through a mix of approved routes, local workarounds and retrospective purchase orders raised after goods had already arrived.
The approach
Procurement began by mapping how purchases were really being made, not how policy said they should be. That exercise showed that most non-compliance came from a process that was slow or unclear for ordinary requests, rather than from deliberate avoidance.
The team simplified the policy into risk-based tiers, so that low-value, low-risk purchases moved quickly through catalogues and pre-approved suppliers, while higher-risk spend received proper due diligence, contract review and segregation of duties. Controls were built into the purchasing system itself instead of relying on people remembering the rules.
What changed
Retrospective orders became the exception rather than the habit, and audit conversations became more straightforward because approvals could be traced. Budget holders reported that the compliant route was now also the easier one, which did more for adoption than any reminder email had.
Lessons for practitioners
Treat non-compliance as a symptom before treating it as misconduct. Proportionate controls, placed where the risk actually sits, earn more cooperation than uniform rules applied to every purchase.