Digitplus
Procurement

Procurement Integrity: Building an Audit-Ready IT Buying Process for Government

For public-sector IT, the right outcome reached by an undocumented route is still a finding. Here is how to build a buying process that holds up under audit, by design, not by scramble.

Digitplus Editorial Team5 min read
Tall stacks of paper files and folders with coloured index tabs in an office

In public-sector IT, getting the right equipment is necessary but not sufficient. An auditor does not score you on the laptops that arrived; they score you on whether the path to those laptops was justified, competitive, and documented. The right outcome reached by an undocumented route is still a finding.

This is the core discipline of procurement integrity: the process must be defensible before anyone asks, not reconstructed after they do. A buying process built for audit-readiness is not slower or more bureaucratic than a sloppy one, it is usually faster, because the questions that derail undocumented purchases never get the chance to land.

Audit-readiness is built in, not bolted on

The failure mode in government IT procurement is rarely fraud. Far more often it is the absence of a trail: a specification that nobody can explain, a sole supplier with no recorded justification, a delivery accepted without a record of what was actually received. None of it is malicious. All of it is a finding.

The auditor's question is never "did you buy good equipment?" It is "can you show me why this, from them, at that price, and prove it arrived?"

Build the process so that the answer to that question already exists as a by-product of doing the work. Below is the shape of a buying process that produces its own evidence.

1. Establish and document the need

Every procurement starts with a stated need tied to an operational or policy objective, approved by someone with the authority to do so. "The department needs new computers" is not a need; "forty workstations to replace end-of-life devices supporting the licensing office, per the approved IT plan" is. The first invites questions. The second answers them.

This step costs almost nothing and prevents the most common audit query, why was this bought at all?, from ever being asked.

2. Write specifications that are open, not engineered

Specifications are where integrity is most often quietly lost. A specification written around one vendor's exact model number, a particular chassis, a unique connector, a feature only one product happens to have, is an audit flag even when no one intended favouritism.

Write to function and standard, not to a brand:

  • State the capability required and the standard it must meet.
  • Allow equivalents, and define how equivalence is judged.
  • Justify any genuinely restrictive requirement in writing, on the record.

A specification that any qualified supplier could legitimately bid against is the single strongest defence against a procurement-integrity challenge.

3. Run a competitive, recorded selection

Whatever method the threshold requires, quotations, restricted tender, open tender, the principle is constant: more than one option, evaluated against criteria set before the responses arrive, with the scoring recorded.

The decisive habit is sequencing. Evaluation criteria and their weights are fixed and documented before bids are opened. Criteria invented after the responses are in are the textbook audit finding, regardless of how reasonable the eventual choice was. The same disciplined sourcing applies to ordinary IT procurement work: a documented basis for the award, every time.

4. Use the LPO as a control, not a formality

In Nigerian public-sector buying, the Local Purchase Order is a control point, not paperwork to be rushed. A properly raised LPO ties the approved need, the selected supplier, the agreed specification, and the authorised budget into one referenceable record. It is the document an auditor will reach for first, which is exactly why it should be raised carefully, against the right authorities, and matched to everything upstream and downstream of it.

This is foundational to working with the government sector at all: LPO discipline and the documented trail around it are what make the rest of the process auditable.

5. Verify delivery against the order

A purchase is not complete when goods arrive; it is complete when delivery is verified against the order and that verification is recorded. Quantity, specification, serial numbers, and condition, checked, signed, dated, retained.

This is the step most often skipped under time pressure, and it is the one that turns a clean procurement into a query. "We received the order" is not evidence. A signed goods-received note matching the LPO line by line is.

Retain the trail as a single, ordered record

The artefacts above are only useful if they can be produced together: the documented need, the open specification, the recorded evaluation, the LPO, the contract or purchase agreement, and the verified delivery. Keep them as one ordered file per procurement. An audit response that takes an afternoon to assemble is the product of a process that filed as it went.

The payoff: speed and trust, not just compliance

It is tempting to read all of this as overhead, process for the sake of process. The opposite is true. A government department known to procure cleanly attracts better suppliers, negotiates from a position of credibility, and moves faster precisely because nobody has to stop and reconstruct a justification under pressure.

Procurement integrity is not a constraint on good public-sector IT. It is what makes good public-sector IT defensible, and being defensible, in the end, is the job. Build the trail as you go, and the audit stops being an event to survive and becomes a record you can simply hand over.

  • government
  • public sector
  • audit
  • compliance
  • procurement integrity
Share

Related to this: IT Procurement.

Have a project that needs this thinking?

Tell us what you’re planning. We’ll come back with practical next steps and a clear, line-itemised proposal, no obligation.