Procurement Governance
In the CGEIT framework, Procurement Governance falls under the IT Resources domain. It is the set of policies, structures, decision rights, and oversight mechanisms that ensure the enterprise acquires IT products, services, and capabilities in a way that supports business objectives, optimizes valu… In the CGEIT framework, Procurement Governance falls under the IT Resources domain. It is the set of policies, structures, decision rights, and oversight mechanisms that ensure the enterprise acquires IT products, services, and capabilities in a way that supports business objectives, optimizes value, and manages risk. Its purpose is not to run individual purchases. Instead, it sets the direction and controls that make sourcing decisions consistent, transparent, and accountable. The first element is strategic alignment. IT acquisitions should follow from the enterprise strategy and the IT strategy. A sourcing strategy defines when to build, buy, outsource, or use cloud services. Governance bodies such as the board, IT steering committee, or investment committee approve major acquisitions based on business cases that show expected benefits, costs, and risks. The second element is policy and decision rights. The organization sets clear procurement policies, authorization limits, and segregation of duties. These cover vendor selection criteria, competitive bidding requirements, and approval thresholds. A RACI model clarifies who requests, evaluates, approves, and oversees each acquisition. This helps prevent conflicts of interest, fraud, and unauthorized spending. The third element is risk management. Procurement governance requires due diligence on vendors, covering financial stability, security posture, regulatory compliance, and concentration or lock-in risk. Contracts should include service level agreements, right-to-audit clauses, data protection terms, exit strategies, and escrow arrangements where appropriate. The fourth element is vendor and contract lifecycle management. Governance extends past signing the contract. It includes ongoing performance monitoring, relationship management, periodic reviews, renewals, and orderly termination. The fifth element is value and performance measurement. Metrics such as total cost of ownership, SLA compliance, benefits realized, and vendor scorecards help confirm that acquisitions deliver their promised value. These measures connect procurement to Benefits Realization. Frameworks such as COBIT support procurement governance, especially its objectives for managed vendors, agreements, and portfolio. Together, these elements give stakeholders assurance that IT resources are acquired efficiently, ethically, and in line with the organization's risk appetite.
Procurement Governance in CGEIT: IT Resources Domain – Complete Guide
Introduction
Procurement Governance is a key topic within the IT Resources domain of the ISACA Certified in the Governance of Enterprise IT (CGEIT) certification. It covers the policies, structures, roles, processes and controls that make sure the enterprise acquires IT products, services and capabilities in a way that supports its strategy, delivers value, manages risk and uses resources well. CGEIT looks at procurement from a governance perspective (direction, oversight and accountability), not from an operational purchasing perspective. Keep that distinction in mind throughout your preparation.
Why Procurement Governance Is Important
Enterprises now depend heavily on external suppliers for cloud services, software, hardware, managed services, outsourcing and specialist skills. A large share of IT spending flows to third parties, so procurement decisions directly shape the enterprise's ability to deliver value. Without good governance, enterprises face these problems:
• Strategic misalignment: purchases that do not support business objectives or the enterprise architecture.
• Value leakage: overpaying, duplicate contracts, shelfware (licences bought but never used) and missed economies of scale.
• Increased risk exposure: vendor lock-in, supplier failure, security and privacy breaches, regulatory non-compliance and concentration risk.
• Shadow IT: business units buying technology outside approved channels, which leads to fragmented architectures and unmanaged risk.
• Fraud and conflicts of interest: weak segregation of duties and opaque vendor selection.
• Poor accountability: nobody clearly owns the outcome of a sourcing decision.
Procurement governance gives the board and executive management assurance that sourcing decisions are made transparently, consistently and in the best interest of the enterprise. It links directly to the three governance objectives emphasised in COBIT: benefits realisation, risk optimisation and resource optimisation.
What Procurement Governance Is
Procurement governance is the framework the governing body uses to evaluate, direct and monitor how IT-related goods and services are sourced. Its main components are:
• Sourcing strategy: an enterprise-level view of what to build, buy, outsource or rent (for example, as-a-service). It is aligned with the IT strategy and business strategy.
• Procurement policies and standards: rules on approval thresholds, competitive bidding, preferred suppliers, ethics, conflicts of interest, security requirements and contract standards.
• Roles and responsibilities: clear accountability, often documented in a RACI chart. Typical roles include the board, the IT steering committee, the CIO, the procurement function, legal, risk/compliance, business owners and vendor managers.
• Decision rights: who can approve which level of spend or risk, and when escalation is needed.
• Vendor (supplier) management: classifying suppliers (strategic, tactical, commodity), monitoring performance, managing relationships and managing supplier risk.
• Contract management: SLAs, right-to-audit clauses, exit and transition clauses, data ownership, confidentiality, liability, escrow and renewal management.
• Performance and compliance monitoring: KPIs, KRIs, audits and reporting to governance bodies.
Relevant frameworks and references include:
• COBIT 2019, especially APO10 (Managed Vendors), APO06 (Managed Budget and Costs), APO07 (Managed Human Resources), BAI03 (Managed Solutions Identification and Build), EDM02 (Ensured Benefits Delivery), EDM03 (Ensured Risk Optimization) and EDM04 (Ensured Resource Optimization).
• ISO/IEC 38500 principles, in particular Acquisition: IT acquisitions are made for valid reasons, on the basis of appropriate and ongoing analysis, with clear and transparent decision-making.
• ISO 20400 (sustainable procurement) and ISO 27036 (information security for supplier relationships) as supporting guidance.
How Procurement Governance Works
Think of procurement governance as a lifecycle with governance checkpoints at each stage.
1. Strategy and Direction (Evaluate and Direct)
• The board and executive leadership set the sourcing strategy and risk appetite.
• The IT strategy committee makes sure sourcing aligns with enterprise objectives and the target architecture.
• Policies set out principles such as cloud-first, preferred vendors, ethical sourcing, data residency and security baselines.
2. Needs Identification and Business Case
• Business requirements are defined and validated by business owners.
• A business case justifies the acquisition. It covers costs (total cost of ownership, TCO), benefits, risks, alternatives (build, buy, outsource) and alignment with the investment portfolio.
• Portfolio management prioritises the request against other investments.
3. Sourcing and Vendor Selection
• An RFI/RFP/RFQ process is used where appropriate.
• Evaluation criteria are defined in advance and weighted. Typical criteria are functionality, cost, financial stability, security posture, compliance, references, support and strategic fit.
• Due diligence covers financial health, certifications (for example, ISO 27001 and SOC reports), subcontractors and geographic risk.
• Segregation of duties is maintained: the requester, the evaluator and the approver should be different parties.
4. Contracting
• Contracts are reviewed by legal, risk and security.
• Key clauses include SLAs and penalties, right to audit, data protection, intellectual property, termination and exit, transition assistance, business continuity, liability caps and escrow for critical software.
• Approval follows the delegated authority matrix.
5. Implementation and Transition
• Onboarding, integration, knowledge transfer and change management.
• Benefits tracking begins.
6. Ongoing Vendor Management and Monitoring
• Performance is measured against SLAs and KPIs.
• Supplier risk is reassessed regularly.
• Relationship reviews and scorecards are reported to governance bodies.
• Contract compliance and licence management are tracked.
7. Renewal, Renegotiation or Exit
• Ahead of contract expiry, the enterprise decides whether to renew, renegotiate, re-tender or exit.
• Exit plans are executed to avoid disruption and to keep control of data and assets.
Key Metrics Used in Procurement Governance
• Percentage of IT spend under managed contracts.
• Percentage of suppliers meeting SLAs.
• Number of procurements bypassing approved processes (an indicator of shadow IT).
• Cost savings or cost avoidance achieved.
• Supplier risk ratings and the number of critical suppliers without exit plans.
• Benefits realised versus the business case.
Common Governance Structures
• IT Steering Committee / Investment Committee: approves significant acquisitions.
• Vendor Management Office (VMO): centralises supplier oversight.
• Architecture Review Board: confirms technical fit and compliance with standards.
• Risk Committee: reviews significant third-party risk.
Exam Tips: Answering Questions on Procurement Governance
1. Think like a governance professional, not a buyer. CGEIT questions reward answers that set direction, define accountability, align with strategy and support monitoring. If one option is operational (for example, negotiating a lower price) and another is governance-oriented (for example, setting a sourcing policy aligned with strategy), the governance option is usually correct.
2. Strategic alignment comes first. When asked what should be done FIRST or what is MOST important, look for answers about aligning the acquisition with business objectives, the IT strategy or the enterprise architecture. Selecting a vendor before confirming the business need is a classic wrong answer.
3. The business case is central. Many questions test whether an acquisition was justified. A well-defined business case covering TCO, benefits, risks and alternatives is often the best answer to questions about approving or prioritising purchases.
4. Watch for keywords. FIRST, BEST, MOST, PRIMARY and GREATEST concern change the answer. For example:
• PRIMARY purpose of procurement governance: ensuring acquisitions deliver value aligned with enterprise objectives at acceptable risk.
• GREATEST risk of decentralised purchasing: misalignment, duplicated spend and unmanaged risk (shadow IT).
• BEST way to reduce vendor lock-in: exit strategy, standards-based architecture and appropriate contract terms.
5. Accountability and decision rights matter. Questions often ask who should approve or be accountable. The business owner is generally accountable for the value of an investment. Executive management or a steering committee approves major investments. The board sets direction and risk appetite. Procurement executes the process. Avoid answers that give strategic decisions to operational staff.
6. Recognise key contract controls. Know why right-to-audit, SLAs, exit clauses, data ownership and escrow clauses exist. If a question describes a problem after signing (for example, the inability to verify vendor security), the root cause is often a missing contract clause, and the best preventive answer is to include it in contract standards.
7. Prefer preventive and systemic solutions. When choosing between fixing one incident and putting in place a policy, framework or process that prevents recurrence, CGEIT usually favours the systemic governance fix.
8. Include risk management. Third-party risk assessment, due diligence and ongoing monitoring are frequently tested. Remember that accountability for risk cannot be outsourced. The enterprise stays accountable even when a vendor performs the service.
9. Link to benefits realisation. After an acquisition, governance requires tracking whether the promised benefits were achieved. Post-implementation reviews and benefit tracking against the business case are strong answers.
10. Know the relevant COBIT objectives. APO10 (Managed Vendors) and the EDM objectives are useful anchors. Questions may describe a situation and expect you to identify the governance practice that addresses it.
11. Eliminate extreme or narrow answers. Options that rely only on cost, only on technology, or that bypass stakeholders are usually wrong. The correct option typically balances value, risk and resources.
12. Stakeholder involvement is good governance. Answers that bring in business, IT, legal, risk and security perspectives are generally stronger than those relying on one function.
Sample Question Walkthrough
Question: A business unit has independently contracted several cloud services without IT involvement. What should the governance body do FIRST?
A. Terminate all unapproved contracts.
B. Establish and communicate an enterprise sourcing policy with clear decision rights.
C. Ask procurement to renegotiate pricing.
D. Conduct a technical security scan of the services.
Answer: B. The root cause is the lack of governance (policy and decision rights). Option A is reactive and disruptive. Option C is operational. Option D addresses a symptom. Establishing the policy and decision rights is the systemic governance response.
Summary
Procurement governance makes sure IT acquisitions are strategically aligned, justified by a business case, transparently selected, properly contracted, actively monitored and exited in a controlled way. It is built on clear policies, defined accountability, risk management and performance measurement. For the CGEIT exam, approach every procurement question from the board's and executive management's viewpoint: alignment, value, risk, resource optimisation and accountability. Choose systemic, preventive, strategy-driven answers over tactical fixes.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!