Skip to content

Procurement Non-Compliance: Why Stakeholders Bypass Procurement Processes

Learn why stakeholders bypass procurement processes, how to distinguish different causes of non-compliance, and how procurement managers should diagnose deviations

Procurement non compliance

A stakeholder contacts a supplier directly and asks them to begin work before a contract or purchase order is in place.

From procurement’s perspective, the problem appears simple: the stakeholder did not follow the process.

But the reason may be less obvious.

The stakeholder may not know which process applies. The purchasing system may be difficult to use. The requirement may be urgent. Procurement may have been involved too late. The stakeholder may believe that the approved supplier cannot meet the business need. In more serious cases, the deviation may involve personal preference, a conflict of interest, or deliberate avoidance of controls.

Procurement non-compliance is therefore not only a control problem. It is also a diagnostic problem.

Before management decides how to respond, it must understand why the deviation occurred.

This article explains what procurement non-compliance looks like, why stakeholders bypass procurement processes, and how procurement professionals can distinguish between knowledge gaps, process weaknesses, business pressure, and intentional misconduct.

LHTS classification

Primary role: Management
Supporting role: Tactical
Process: Stakeholder management and governance across Source-to-Contract, contract management, supplier management, and Procure-to-Pay
Learning level: Basic
Related course: Introduction to Procurement Management

Quick answer: Why do stakeholders bypass procurement?

Stakeholders bypass procurement processes for different reasons. Common causes include unclear policies, difficult procedures, urgent business needs, insufficient planning, poor understanding of procurement’s value, weak systems, conflicting objectives, personal supplier preferences, and limited accountability.

Not every deviation is deliberate misconduct. Some are caused by a lack of knowledge or an impractical process. Procurement management should therefore identify the root cause before deciding whether the correct response is training, process improvement, better service, stronger controls, or formal escalation.

What is procurement non-compliance?

Procurement non-compliance occurs when an employee, buyer, manager, or other stakeholder does not follow an applicable procurement policy, approval rule, sourcing process, contract, ethical requirement, or purchasing control.

Examples include:

  • Engaging a supplier before approval.
  • Purchasing from a non-approved supplier.
  • Buying outside an existing contract.
  • Dividing a purchase to avoid an approval threshold.
  • Modifying a supplier’s scope without authorisation.
  • Selecting a supplier without an appropriate evaluation.
  • Creating a purchase order after work has started.
  • Approving an invoice without confirming delivery.
  • Failing to document a sourcing or supplier decision.
  • Ignoring supplier performance problems.
  • Not declaring a conflict of interest.

These behaviours may look similar in a compliance report, but their causes can be very different.

That difference matters because the same corrective action will not work in every case.

Non-compliance is a symptom, not a root cause

A retrospective purchase order is evidence that the process was not followed. It does not explain why.

The cause could be:

  • The stakeholder did not understand that a purchase order was required before commitment.
  • The approval workflow took too long.
  • The supplier was asked to respond to a genuine emergency.
  • The stakeholder did not plan the purchase early enough.
  • The purchasing system was unavailable or difficult to use.
  • Procurement did not provide a practical route for the purchase.
  • The stakeholder deliberately wanted to avoid procurement involvement.

Management should therefore separate the visible behaviour from the underlying cause.

Without that distinction, the organization may repeatedly treat symptoms while the real problem remains.

Three broad types of procurement non-compliance

A useful first step is to distinguish between accidental, situational, and intentional non-compliance.

Accidental non-compliance

Accidental non-compliance occurs when a stakeholder does not understand the requirement or makes an unintentional mistake.

Examples include:

  • Using an outdated process description.
  • Selecting the wrong purchase-order type.
  • Misunderstanding an approval limit.
  • Forgetting to attach sourcing documentation.
  • Believing that a contract owner may approve a contract change.

This type of non-compliance normally points to a need for clearer communication, training, role descriptions, or system guidance.

Situational non-compliance

Situational non-compliance occurs when business circumstances make the established process difficult to follow.

Examples include:

  • An urgent operational failure.
  • An unexpected customer requirement.
  • A supplier suddenly becoming unavailable.
  • A process lead time that does not match business needs.
  • A purchasing system that cannot handle the required transaction.
  • Procurement capacity that is insufficient for the demand.

The stakeholder may understand the rule but believe that following it would prevent the organization from achieving an immediate business objective.

This does not automatically make the deviation acceptable. It does, however, mean that management should examine both the stakeholder’s decision and the practicality of the process.

Intentional non-compliance

Intentional non-compliance occurs when someone knows the requirement but deliberately chooses to avoid it.

Examples include:

  • Splitting a purchase to remain below an approval threshold.
  • Selecting a preferred supplier before the evaluation begins.
  • Hiding a personal relationship with a supplier.
  • Asking a supplier to start work before approval to create a commitment that is difficult to reverse.
  • Bypassing procurement because a competitive process may challenge the stakeholder’s preferred outcome.
  • Repeatedly buying outside an agreement despite previous correction.

Intentional non-compliance requires a stronger response. Depending on the circumstances, this may include management escalation, increased control, audit review, investigation, or disciplinary action.

Five root causes of procurement non-compliance

Although individual cases vary, many deviations can be connected to five recurring causes.

1. Unclear policies, roles, or responsibilities

Employees cannot follow a process they do not understand.

Procurement policies are often written from the perspective of the procurement, finance, or legal function. Stakeholders may see a collection of rules without understanding:

  • When procurement must be involved.
  • Which purchasing route applies.
  • Who owns the requirement.
  • Who may negotiate with a supplier.
  • Who may approve or sign.
  • What documentation must be retained.
  • How an exception should be handled.
  • Where to get help.

A policy may technically contain this information but still be difficult for the intended user to understand.

Example

A project manager agrees to additional supplier work because they believe responsibility for the project includes authority to change the commercial scope.

The problem may not be resistance to compliance. It may be an unclear distinction between project responsibility, contract ownership, commercial authority, and signing authority.

Diagnostic questions

  • Was the requirement clearly communicated?
  • Could the stakeholder reasonably understand which process applied?
  • Were roles and decision rights visible?
  • Had the stakeholder received relevant training?
  • Was help available when the question arose?

When several stakeholders make the same mistake, management should examine the clarity of the process before treating each case as an isolated failure.

2. Process complexity and system friction

A procurement process may be correct in principle but difficult to use in practice.

Stakeholders may experience:

  • Too many approval steps.
  • Long or unpredictable lead times.
  • Complex forms.
  • Repeated requests for the same information.
  • Difficult purchasing systems.
  • Unclear supplier catalogues.
  • Too many purchasing channels.
  • Processes that do not distinguish between low-risk and high-risk purchases.
  • Limited visibility of request status.
  • No practical route for unusual requirements.

Every control has a purpose, but every control also creates effort.

When the effort appears disproportionate to the value or risk of the purchase, stakeholders may create workarounds.

Example

The same sourcing process is required for both a low-value standard service and a complex, strategically important agreement.

Stakeholders responsible for small purchases may consider the process disproportionate and begin making direct supplier commitments.

Diagnostic questions

  • Is the process proportionate to purchase value, complexity, and risk?
  • Which steps create the longest delay?
  • Is the same information entered more than once?
  • Can stakeholders see what happens after submitting a request?
  • Does the approved process cover common business situations?
  • Are exceptions easier to obtain than following the standard process?

A strong compliance framework should make the correct route easier than the workaround wherever possible.

3. Time pressure, poor planning, and genuine urgency

Urgency is one of the most common explanations for bypassing procurement.

Sometimes the urgency is genuine. A production line may have stopped. A critical system may have failed. A customer commitment may be at risk.

In other situations, urgency is the result of late planning.

The requirement may have been known for weeks, but procurement is contacted only when the supplier is expected to begin. The process is then described as too slow, even though insufficient preparation caused the time pressure.

Procurement management should distinguish between:

  • Unforeseeable urgency.
  • Urgency caused by weak demand planning.
  • Urgency caused by delayed stakeholder decisions.
  • Urgency caused by insufficient procurement capacity.
  • Urgency deliberately created to avoid competition or approval.

Example

A department asks procurement to approve a supplier immediately because a project starts the following day.

The requirement itself may be valid. The diagnostic question is when the need first became known and why procurement was not engaged earlier.

Diagnostic questions

  • When was the requirement identified?
  • When was procurement informed?
  • Could the need reasonably have been planned earlier?
  • Does the organization have an emergency procurement process?
  • Was the urgency caused by the stakeholder, procurement, the supplier, or an external event?
  • Is the same department repeatedly responsible for urgent exceptions?

Repeated urgency is usually not an exception. It is a process or planning pattern.

4. Weak trust in procurement or unclear procurement value

Stakeholders are more likely to involve procurement when they believe procurement will help them achieve a better business outcome.

They are less likely to involve procurement when they expect:

  • Delays without clear benefit.
  • A focus on price rather than business requirements.
  • Limited knowledge of the category or supplier market.
  • Standard procedures that ignore operational realities.
  • Poor communication.
  • Procurement taking control without involving the business owner.
  • A supplier being rejected without a practical alternative.
  • Savings being prioritised over quality, delivery, innovation, or risk.

This does not justify bypassing procurement. It does, however, show that compliance depends partly on procurement’s credibility as an internal business partner.

Example

An engineering stakeholder uses a familiar supplier because they believe procurement will select the lowest-priced bidder without understanding the technical risk.

The immediate compliance concern is the unapproved supplier choice. The underlying issue may be a lack of trust in the evaluation process.

Diagnostic questions

  • Was procurement involved early enough to understand the need?
  • Did procurement explain the purpose of the process?
  • Were stakeholder requirements reflected in the supplier evaluation?
  • Did procurement provide useful market or commercial insight?
  • Does the stakeholder see procurement as support, control, or obstruction?
  • Has procurement delivered reliable results in similar situations?

Stakeholder trust does not replace control. It makes the control easier to apply.

5. Personal preference, conflicting incentives, and weak accountability

Some non-compliance is connected to the way individuals are motivated or held accountable.

A stakeholder may be measured on:

  • Project speed.
  • Production output.
  • Sales performance.
  • Budget delivery.
  • Customer response time.
  • Technical results.

Procurement compliance may not be part of the stakeholder’s goals, even though procurement deviations create risk for the wider organization.

This can produce conflicting incentives. The stakeholder receives recognition for delivering quickly, while the commercial, contractual, or compliance consequences are managed by another function.

Personal supplier relationships can create an additional risk. A familiar supplier may feel easier or safer than an unknown alternative. Previous positive experience can influence judgment, even when no improper intention exists.

More serious situations may involve favouritism, undisclosed conflicts of interest, gifts, personal benefit, or deliberate manipulation of the process.

Example

A manager repeatedly selects the same supplier because they have worked together for many years. The manager views the relationship as low risk, while procurement sees insufficient competition and dependence on one supplier.

The correct response depends on whether the preference is supported by objective performance data, whether an exception has been approved, and whether any personal interest exists.

Diagnostic questions

  • What objective is the stakeholder trying to achieve?
  • Do performance incentives conflict with procurement requirements?
  • Has the same behaviour occurred before?
  • Were previous deviations challenged?
  • Does the stakeholder gain personal or professional benefit from the decision?
  • Has a supplier relationship or conflict of interest been disclosed?
  • Are consequences applied consistently across functions and seniority levels?

When known deviations have no consequences, non-compliance can gradually become normal behaviour.

Five common forms of stakeholder non-compliance

The root causes become easier to understand when connected to practical procurement situations.

1. Bypassing procurement procedures

A department engages a supplier directly instead of raising a request or involving procurement.

Possible causes include:

  • Genuine urgency.
  • Poor planning.
  • Unclear thresholds.
  • A belief that procurement will delay the project.
  • An impractical intake process.
  • Deliberate avoidance of competition.

The visible action is the same, but the appropriate response depends on the cause.

2. Making unauthorised contract changes

A project manager agrees to a change in scope, delivery, price, or timing without involving procurement, legal, or the authorised contract owner.

Possible causes include:

  • Unclear authority.
  • A belief that the change is minor.
  • Pressure to maintain project progress.
  • Weak change-control procedures.
  • Limited understanding of contractual risk.
  • A deliberate attempt to avoid additional approval.

Even a seemingly small operational change can affect price, liability, delivery obligations, intellectual property, service levels, or the organization’s ability to enforce the contract.

3. Engaging non-approved suppliers

A stakeholder selects a supplier that has not completed the required sourcing, qualification, or onboarding process.

Possible causes include:

  • Previous positive experience.
  • Lack of awareness of approved alternatives.
  • Incomplete supplier catalogues.
  • A specialist requirement not covered by existing suppliers.
  • Slow supplier onboarding.
  • Personal preference or relationship.
  • Deliberate avoidance of supplier review.

Procurement should assess both the supplier decision and whether the approved supply base actually meets business needs.

4. Ignoring supplier performance information

A stakeholder continues using a supplier despite recurring quality, delivery, service, or contractual problems.

Possible causes include:

  • Switching costs.
  • Operational dependency.
  • Lack of a qualified alternative.
  • A comfortable personal relationship.
  • Disagreement about the performance data.
  • Fear that changing supplier will disrupt the business.
  • Lack of accountability for supplier results.

Performance measurement does not create value unless it affects decisions.

5. Inadequate documentation

A department fails to retain quotations, approvals, evaluation records, purchase orders, receipts, or contract-change documentation.

Possible causes include:

  • Unclear requirements.
  • Systems that are difficult to use.
  • Documentation being treated as an administrative afterthought.
  • Time pressure.
  • Fragmented storage locations.
  • Lack of ownership.
  • An intention to prevent review of the decision.

Missing documentation can indicate a simple process weakness or a more serious control risk. The context must be assessed.

A practical method for diagnosing a deviation

When procurement identifies non-compliance, management can use a five-step diagnostic approach.

Step 1: Establish what happened

Begin with facts rather than assumptions.

Determine:

  • What was purchased?
  • Which supplier was involved?
  • Who made the commitment?
  • Which rule or process was not followed?
  • What approvals or records are missing?
  • What commercial or operational exposure exists?

The immediate priority may be to secure the company’s position, clarify supplier expectations, or prevent additional commitments.

Step 2: Understand the timeline

Identify when the business need became known and when key decisions were made.

A timeline often reveals whether the deviation resulted from genuine urgency, late planning, unclear responsibility, or deliberate avoidance.

Step 3: Ask why the approved process was not used

The question should be asked without immediately accusing the stakeholder.

Useful questions include:

  • What prevented you from using the normal process?
  • Which part of the process was unclear?
  • When did you first become aware of the need?
  • Which business consequence were you trying to avoid?
  • Did you ask procurement for support?
  • Have you faced the same problem before?

The objective is to understand the decision, not to excuse it.

Step 4: Classify the root cause

Consider whether the main cause relates to:

  • Knowledge and communication.
  • Process or system design.
  • Planning and capacity.
  • Procurement service and stakeholder trust.
  • Incentives and accountability.
  • Personal preference or ethical risk.

Several causes may apply to the same event.

Step 5: Select a proportionate response

The response should match both the cause and the seriousness of the risk.

Examples include:

  • Clarifying a policy.
  • Providing targeted training.
  • Simplifying a workflow.
  • Improving system guidance.
  • Introducing a low-value purchasing channel.
  • Creating an emergency exception process.
  • Engaging procurement earlier in business planning.
  • Adjusting authority or approval controls.
  • Monitoring repeat deviations.
  • Escalating an ethical or intentional breach.

A generic reminder to “follow the procurement process” rarely resolves a structural cause.

How this connects to the procurement management role

Understanding non-compliance is primarily a procurement management responsibility.

Procurement management designs the operating environment, including:

  • Policies.
  • Roles and responsibilities.
  • Approval limits.
  • Procurement processes.
  • Methods and templates.
  • Systems and workflows.
  • Stakeholder interfaces.
  • Competence requirements.
  • Compliance indicators.
  • Escalation procedures.

When non-compliance occurs repeatedly, management must ask whether the procurement operating model is functioning as intended.

The question should not only be:

“Why did the stakeholder fail to follow the process?”

Management should also ask:

“Why did our procurement model allow, encourage, or fail to prevent this behaviour?”

This does not remove individual responsibility. It ensures that both behaviour and system design are examined.

How tactical procurement supports compliance

Tactical buyers often work closest to stakeholders during need definition, sourcing preparation, supplier evaluation, negotiation, and contracting.

They can reduce non-compliance by:

  • Involving stakeholders early.
  • Explaining process requirements.
  • Agreeing realistic sourcing timelines.
  • Defining roles before the sourcing event begins.
  • Translating business needs into evaluation criteria.
  • Documenting decisions and deviations.
  • Identifying stakeholder concerns before they become resistance.
  • Escalating conflicts of interest or attempts to manipulate the process.

The tactical buyer is therefore both a sourcing specialist and an important interface between procurement governance and business reality.

Where non-compliance appears in the procurement process

Non-compliance can occur throughout the procurement lifecycle.

Need definition

A preferred supplier is chosen before the requirement is objectively defined.

Sourcing preparation

Procurement is involved too late to plan an appropriate process.

Supplier selection

Suppliers are evaluated using inconsistent or undocumented criteria.

Negotiation

A stakeholder makes commitments directly to a supplier without authority.

Contracting

Work begins before the contract or change order is approved.

Supplier implementation

The supplier is used before qualification, onboarding, or system setup is complete.

Procure-to-Pay

Purchase orders are created retrospectively, receipts are not recorded, or invoices are approved without verification.

Contract and supplier management

Poor performance is ignored, commercial conditions are not applied, or contract changes are not controlled.

A mature compliance approach therefore needs visibility across Source-to-Contract, Procure-to-Pay, and supplier management.

Common mistakes when addressing procurement non-compliance

Mistake 1: Assuming every deviation is deliberate

This can create defensiveness and damage stakeholder relationships. Some deviations result from unclear rules, unsuitable processes, or system limitations.

Mistake 2: Excusing every deviation as urgency

Urgency can be genuine, but repeated urgent purchasing often indicates poor planning or a process weakness.

Mistake 3: Responding only with more training

Training helps when the problem is knowledge. It will not repair a slow approval workflow, an unusable system, or conflicting incentives.

Mistake 4: Adding controls without understanding the cause

Additional approvals may make the process slower and encourage more workarounds.

Controls should address a defined risk.

Mistake 5: Blaming stakeholders while ignoring procurement performance

Procurement must examine whether its own service, competence, capacity, communication, and lead times contribute to non-compliance.

Mistake 6: Improving the process but ignoring intentional misconduct

Process improvement is not an appropriate substitute for accountability when someone knowingly manipulates or bypasses controls.

Mistake 7: Applying consequences inconsistently

When senior stakeholders are allowed to bypass procurement while others are corrected, the organization signals that compliance is optional.

Procurement non-compliance as management information

A deviation is not only a problem to close. It is also information about the procurement operating model.

Patterns of non-compliance can reveal:

  • Policies that are not understood.
  • Procurement processes that do not match business needs.
  • System limitations.
  • Weak demand planning.
  • Insufficient procurement capacity.
  • Categories without suitable agreements.
  • Poor stakeholder relationships.
  • Conflicting objectives.
  • Weak management accountability.
  • Ethical or fraud risks.

Management should therefore analyse trends rather than only counting individual deviations.

Useful indicators may include:

  • Retrospective purchase orders.
  • Spend outside approved contracts.
  • Use of non-approved suppliers.
  • Unauthorised contract commitments.
  • Repeated emergency purchases.
  • Missing sourcing documentation.
  • Unapproved supplier master-data changes.
  • Deviations by department, category, location, or process stage.
  • Repeat deviations after corrective action.

The purpose is not to create a list of offenders. It is to understand where the procurement framework is failing or being challenged.

Learn more about procurement management

Procurement non-compliance is closely connected to how the procurement function is organized and managed.

The Learn How to Source course Introduction to Procurement Management explains how procurement strategy is translated into organization, roles, processes, methods, and tools.

This provides a useful foundation for understanding why non-compliance cannot be solved through policy alone. The full procurement operating model must support the behaviour the organization expects.

For readers working directly with sourcing events, Sourcing Process 1 provides additional learning about the sourcing process and stakeholder management.

Continue the procurement compliance series

This is the second article in a three-part series:

  1. Procurement Compliance: Five Pillars That Protect the Procurement Process
  2. Procurement Non-Compliance: Why Stakeholders Bypass Procurement Processes
  3. Building a Compliance-Driven Procurement Culture

The first article explains the framework that should be followed.

This article explains why deviations occur and how to diagnose their root causes.

The third article explains how procurement leadership can combine clear expectations, practical processes, stakeholder value, monitoring, and accountability to create lasting compliance.

Frequently asked questions

What is procurement non-compliance?

Procurement non-compliance occurs when purchasing or sourcing activity does not follow an applicable procurement policy, approval requirement, contract, ethical standard, or process control.

Why do stakeholders bypass procurement?

Common reasons include unclear requirements, complex processes, urgent business needs, poor planning, difficult systems, limited trust in procurement, personal supplier preferences, conflicting objectives, and weak accountability.

Is all procurement non-compliance intentional?

No. Non-compliance may be accidental, situational, or intentional. Management should understand the cause before selecting a corrective action.

What is maverick buying?

Maverick buying generally refers to purchases made outside approved procurement contracts, suppliers, processes, or purchasing channels.

How should procurement respond to an urgent exception?

The organization should assess the business urgency and risk, involve the correct authority, document the exception, control the commercial commitment, and review why the urgent situation occurred.

Can a difficult procurement process cause non-compliance?

Yes. If a process is unnecessarily complex, slow, or poorly matched to the value and risk of the purchase, stakeholders may look for workarounds. This does not remove their responsibility, but it means the process should also be reviewed.

When should non-compliance be escalated?

Escalation may be necessary when the deviation creates significant financial, legal, ethical, operational, or reputational risk; when it appears intentional; or when the same behaviour continues after previous correction.

Who owns procurement compliance?

Procurement management owns the framework, but compliance depends on buyers, stakeholders, budget owners, contract owners, finance, legal, and business management carrying out their respective responsibilities.

Conclusion

Procurement non-compliance should not be treated as one uniform problem.

The same visible deviation may be caused by a lack of knowledge, an unsuitable process, genuine urgency, weak planning, poor stakeholder trust, conflicting incentives, personal preference, or deliberate misconduct.

Effective procurement management begins by identifying which cause applies.

The correct response may involve training, clearer roles, process improvement, better systems, earlier procurement involvement, stronger stakeholder service, additional controls, or formal accountability.

The objective is not simply to force stakeholders through a process. It is to create a procurement model in which the correct process is understood, practical, proportionate, and supported by clear responsibility.

Once the root causes are understood, procurement leadership can begin building an environment where compliant behaviour becomes the normal and preferred way of working.

That is the subject of the third article: Building a Compliance-Driven Procurement Culture.

Procurement non compliance
Procurement non compliance

Leave a Reply