Skip to content
Sections
All notes

All notes · Enabling

Procurement That Keeps Up

A six-month assessment cycle in a field that moves monthly guarantees shadow use. What to change.

Enabling · Analysis

The approval process is the mechanism that converts a useful tool into an approved one. In most organisations it is slower than the field it is assessing.

A practical review based on “Procurement That Keeps Up” includes the time required for assessment, contracting, rollout and later reassessment. Teams can use this useful page to make that operational effort visible across owners and deadlines, while keeping the legal, security and model-risk decision in the documented approval process.

For an independent benchmark, compare the local approach with NIST AI Resource Center; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.

The mismatch

Standard software procurement assumes a tool that will be in place for years.

AI tools change materially in months, and the one assessed in January may be superseded by June.

A process calibrated for the first case applied to the second produces decisions about a tool that no longer exists.

What a faster path looks like

A tiered assessment: light for low-risk categories, full for anything touching confidential or regulated data.

The light path: terms check against the seven clauses, classification scope, named owner, time-bounded approval.

Days rather than months, done by one person with a checklist.

Reserve the full process for the cases that warrant it, which is a minority.

The reusable assessment

Most of the work is the same for every tool: the same seven clauses, the same questions.

Build a template once and the per-tool effort drops to an hour.

And keep the completed assessments, because providers reappear and terms change rather than being new each time.

Time-bounded approvals

Approve for six or twelve months rather than indefinitely.

The review is then scheduled rather than triggered by somebody noticing.

And a tool that has been superseded falls off naturally, which keeps the approved list short.

The subprocessor question at procurement

Ask which model providers sit behind the service, and get the answer in the contract.

This is the question most likely to be deflected and most likely to matter, because the AI layer in many products is somebody else's.

Working with legal

The bottleneck is usually legal review capacity rather than the assessment itself.

A pre-agreed position on the standard clauses — what is acceptable, what needs escalation — removes most of the queue.

That is a half-day conversation once, and it is the single change that most speeds this up.

The honest constraint

Some assessments genuinely take time: regulated sectors, large contracts, novel risk.

Say which category a request is in at the start, with an expected date.

People accept a stated timescale and route around an unknown one.

What to check

How long does a low-risk AI tool take to approve here?

Is there a tiered path, or one process for everything?

Do you have a pre-agreed legal position on the standard clauses?

And are approvals time-bounded?

The point

A six-month assessment cycle in a field that moves monthly guarantees shadow use.

Tier the assessment and reserve the full process for what warrants it.

Underlying all of this

Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.

The recurring pattern

The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.