Blog
Industry Experts

Procurement is a risk function

・ 8

min read

Josh Reynolds

Senior Product Manager

Ask a procurement team where onboarding time goes, and you get the same answer. Not sourcing. Not negotiation. Risk.

That is rarely because anyone is slow. It is because the risk process usually lives somewhere else: a separate tool, a separate queue, a separate owner, and often a separate spreadsheet of chased email replies.

Procurement waits on an answer it cannot influence. Risk chases evidence about a purchase it did not scope. The supplier re-answers a questionnaire it has already filled in for someone else. Three parties frustrated, none doing anything wrong.


01 — The split

You can't govern a decision you have already made

Every purchase brings a third party into the business. When you sign a vendor, you are not just agreeing on a price, you are granting access: to data, to systems, to customers, sometimes to your regulatory perimeter. The buying decision and the risk decision are the same decision, assessed by different people against different criteria.

Run them in one place and that is obvious. Run them in two and the risk verdict arrives after the commitment: supplier chosen, budget approved, contract already with legal. By then, the assessment's realistic outcome is a note on a file, not a change of course.

A risk process that sits outside the decision can produce evidence. It cannot produce control. That is the difference between a report and a brake. It is the whole argument for moving risk inside the buying process.


02 — Why now

Three forces are closing the gap. Regulation is only one.

  1. The volume changed first.Every team now buys software that touches data, and AI has multiplied it. What used to be a quick expense claim now comes with a subprocessor list and a retention policy. Purchases with genuine third-party risk exposure are outpacing every risk team, and a manual review line cannot absorb them. Either something assesses proportionally in the flow, or coverage collapses.

  2. Then exposure became commercial.Your customers now audit how you manage your vendors. Sell into financial services or healthcare and you will be asked to account for your subprocessors and monitoring before a deal closes. Third-party risk is no longer a compliance cost. It shows up in the sales cycle, which changes who cares internally.

  3. Regulation came third, on the same demand.In the US, a vendor's incident materially affecting your business can become your own disclosure obligation. In Europe, DORA goes further: name the service, map it to a critical function, identify the subcontractors, and say where the data sits. The laws read differently, but each one wants information generated during the buying process, and risk registers built after the fact are always partly fiction.

With an increased demand on risk, standardising it within the procurement process brings consistency and efficiency.


03 — The real shift

Context is the moat in the AI era

A couple of years ago, getting value from AI here meant going deep into one narrow task. A model tuned to read a SOC 2 report. A classifier trained to catch a sanctions hit. Each is useful, but locked to a single task.

That advantage is eroding. Frontier models read and extract well enough that depth is no defence. If everyone can read the document, the edge is knowing what it means for this purchase. That is context, not capability.

What an agent needs to assess a vendor properly

Consider what an agent actually needs to assess a vendor properly: what is being bought and for what,  who will use it, what data it will touch, and under which classification. Whether you already own something that does the same job. What your policy says about this category, and what your team decided the last forty times a similar request came in. What the previous assessment of this supplier found, and whether anything has changed since.

Almost none of that exists inside a risk tool. All of it is generated during the buying process by the person raising the request.

This is where the two architectures separate for good. A system that sees real decisions and their outcomes gets better at making them. One fed records after the fact does not, because it never sees the reasoning: which supplier was rejected, which exception was granted, and what the approver overrode.

An integration between two systems can move fields. It cannot move judgement. So, embedding risk is not about tidiness. One system is how each process reaches the context that decides how well AI performs inside it. Run them apart and both are stuck with whatever their own tool holds.


04 — Both directions

Risk gets the deal context. Procurement gets the risk context.

Risk ← the deal: Risk gains the business context of the purchase.

An assessment that runs inside the buying flow already knows the category, value, data, integrations, users and criticality. So it can be proportionate. A design tool for four people should not be treated like a payment processor, and pretending otherwise is why people route around the process.

It can also be scored where it matters. One vendor may sell you a product that touches customer data and one that does not. At supplier level, they collapse into one verdict that is wrong about both. At agreement level, each is judged on its own facts.

Procurement ← risk: Procurement gains the risk context of the vendor.

An expired SOC 2, a recent sanctions listing, slipping financials, and a subprocessor added quietly last quarter. In two systems, each becomes a report that someone reads later. In one, they arrive while the decision is still open, which changes what you can do.

A control gap found before signature is a negotiating position. Found afterwards, it is a remediation project, and your only levers are asking nicely or paying to leave. Finance notices that difference, because a CFO's real fear is not risk but exposure they cannot see or act on. Risk intelligence next to spend usually pays for itself in a negotiation long before it prevents an incident.

And it keeps moving: And both directions keep moving.

The vendors you buy are increasingly AI companies, so their subprocessor lists are longer, newer and change faster than this category was built to track. The provider behind a tool you approved in January may not be the one behind it in June. An annual review cannot see that. Continuous monitoring can, but only when it looks at a record that knows what you bought and how you use it.


05 — In practice

What this looks like in the aOS

Trigger: The assessment starts itself.

Every new supplier request automatically triggers an assessment, scoped by category, value, and data access. Procurement and risk work from one record, one workflow.

Proportionality: Depth matches exposure.

The intake adjusts to spend, data access, integrations, location and the documents already on hand. Simple requests stay simple. Agents find the supplier's trust centre, read the security artefacts against your playbook and fill the vendor form from them.

Monitoring: Monitoring never stops.

Continuous screening with Dow Jones covers sanctions, adverse media, PEPs and financial health. It also watches what quietly becomes outdated: a SOC 2 that expires, an ISO cert that lapses, a pen test now eighteen months old, a subprocessor added months after you approved the vendor. When any of it changes, an agent triages the alert with full context and routes it to the owning team, instead of adding a row to a dashboard nobody opens.

Auditability: The audit trail assembles itself.

Request, approval, assessment, rationale and contract all connect to one supplier record, at agreement level. Every AI action shows its sources and can be switched off per workflow, which is what gets risk agents past an AI governance committee.

Compounding: And it gets better at it.

Every assessment, escalation, exception and approval feeds back in. The system learns which categories generate findings, which questions produce answers and which produce noise, and how your team handled this request before. The assessment you run in month two is not the one you ran on day one, and the difference comes from your own decisions, not a vendor's roadmap.


06 — Proof

Regulated teams moved first

The pattern is clearest where the stakes are highest. Teams in payments, financial services, and regulated infrastructure are the ones folding standalone risk tools into the buying process rather than running the two side by side.

"Before Omnea, risk lived in its own silo—detached from procurement and difficult to contextualize. Now, everything is in one place. We can see the cyber, legal, and financial risk associated with a supplier in a single view, giving the business real clarity."

Stephen Murphy, TISO, Reach plc


Summary

Risk is procurement's strongest argument, not its heaviest burden.

Procurement's reputation problem is that it is seen as the thing slowing the business down. Risk takes the blame, and the blame is misplaced. What slows a purchase down is the handoff between two systems that do not share context.

This makes risk the best case procurement has. The board already cares about it, regulators ask about it by name, and it is where the function protects the company rather than polices it. Teams that bring risk inside the buying decision do not just onboard faster.

They walk into the CFO conversation holding what no other function can: a complete, current picture of every third party the business depends on, and the ability to act before the money moves.

Interested in learning more? Book a demo to see Omnea in action.

Stay in the loop.

Subscribe to our newsletter.

Stay in the loop.

Subscribe to our newsletter.

Stay in the loop.

Subscribe to our newsletter.