The hiring software approval process: who signs, and what they ask

James Hitch

James Hitch

The hiring software approval process: who signs, and what they ask

A hiring OS is rarely rejected simply because of its price. More often, the purchase stalls because several people need to approve it, and each person is looking at the decision from a different perspective. Finance wants to understand which existing costs will decrease or disappear.

Procurement needs the right documents and commercial details. Security wants to know whether the platform meets the company’s security requirements. Legal needs to understand what obligations the company is taking on. Hiring managers want to make sure they can still use the parts of the hiring process they already trust.

If the approval case only answers one of these questions, the process can stop even when the software itself is a good fit. The buyer has to build a case that addresses the concerns of everyone involved in the decision.

A hiring OS in this context means a platform that manages the hiring process from requisition through to offer, rather than software that handles just one stage. Because it touches several parts of the hiring workflow, it also affects more teams inside the company. That broader scope is why a hiring OS usually needs more approvals than a point solution.

In this article

  • Why agreement in principle is not approval
  • What finance asks, and the answer that fails
  • What procurement needs, and how early to start
  • What security reviews, and which documents take longest
  • What hiring managers are actually defending
  • Who signs, in what order, and where the weeks go
  • Conclusion
  • Frequently Asked Questions

Why does a hiring OS stall after everyone agrees it is a good idea?

Because agreeing that something is a good idea and formally approving the purchase are two different events. Most internal business cases are built to achieve the first. They explain the problem, show why it matters and make a case for change. That can be enough to get people interested, but it does not necessarily give every stakeholder what they need to approve the purchase.

Once the proposal moves into the approval process, the questions change. Finance wants to know whether the claimed savings or return will actually appear in the company’s accounts. Procurement wants to know whether the required documentation and commercial information are in place. Security needs to assess whether the vendor can be trusted with candidate data. Legal needs to understand the obligations created by the contract. Hiring managers want to know whether the new system will preserve the parts of the hiring process where they rely on their own judgement.

These reviewers are not necessarily opposed to the purchase. They are simply evaluating it against different requirements. That is why a strong case for the hiring problem is not enough on its own. The proposal also needs to answer the questions that arise during procurement, security, legal and operational review.

There are usually more people involved than the core group. Forrester's 2026 buyer research found that a typical B2B purchase involves 13 internal stakeholders and nine external influencers, with larger groups for more complex or strategic purchases. A hiring OS can therefore involve considerably more people than the original buying conversation suggests.

The problem is often not that one of these stakeholders says no. It is that one of them has an unanswered question, so the purchase cannot move to the next stage. The proposal then sits in a queue while other work that is already complete moves ahead of it.

The time involved can add up quickly. Vertice's 2026 procurement data found that the average software purchase took 72 days from request to signature in Q1 2026. In June, new software purchases averaged 36 days, while renewals averaged 87 days. Vertice's stage-level data also shows that intake averaged 10.3 days and legal approval 9.6 days.

That means approval work should start before the vendor has been chosen. If finance, security, procurement and legal only become involved once the preferred platform is selected, their reviews are pushed to the end of the process. By preparing the information they will need earlier, the buying team can reduce the amount of waiting between stages.

The practical lesson is simple: do not build the business case for the person who wants the software. Build it for everyone who has to approve it. The faster each stakeholder can answer their own question, the less likely the purchase is to stall after everyone has already agreed that the problem needs solving.

What does finance actually ask?

Finance is not only asking what the software costs. The more important question is: which existing line item gets smaller, by how much, and when will that change appear in the budget?

This is where many internal cases for hiring software fall short. Saving recruiters' time is not automatically the same as saving money. The time only becomes a financial saving if something changes on the cost side. For example, the company might avoid hiring another recruiter, stop extending a contractor, reduce agency fees or cancel an existing software licence. If none of those things happen, the saved hours may still be valuable because the team can handle more work, but they do not create a direct reduction in costs.

Software spend is another area finance will examine closely. Forrester forecast software spending to grow by 10.5% in 2025 and account for 60% of global technology spending growth by 2029. That makes software consolidation and licence costs relevant parts of the business case. The important thing is to identify the specific costs the hiring OS will affect rather than presenting a general claim about efficiency.

Agency spend is usually the easiest cost to demonstrate. It is a real invoice, and it can decrease when the internal team becomes better at sourcing and filling roles. Contractor or interim recruiting capacity can be treated in a similar way if the company can show that the additional capacity will no longer be required.

Tool consolidation is another concrete saving, although it may be smaller than expected. Zylo's 2025 SaaS Management Index reported an average of $21 million in wasted SaaS licences among the organisations it analysed, a 14.2% increase year over year. The same research reported an average of 152 applications at smaller companies and 660 at large enterprises. If a hiring OS replaces several existing tools, finance can measure the licences that will actually be cancelled.

Recruiter headcount requires more care. It may be tempting to claim that better software means the company can avoid hiring another recruiter. Unless that hiring decision has already been made, however, the saving is hypothetical. It is safer to separate a confirmed saving from capacity that the team can use to handle more hiring without increasing headcount.

The cost of an open vacancy can also be important, but it needs to be calculated carefully. SHRM's 2026 benchmarking, based on more than 4,600 organisations, puts the median time to fill a nonexecutive position at 39 calendar days. The Bureau of Labor Statistics reported 7.3 million US job openings and 5.1 million hires in July 2026. These figures show that vacancies and hiring delays are measurable. They do not, by themselves, tell you what a particular vacancy costs the business.

That cost is where finance will challenge the assumptions. Vendor calculators can produce large numbers, but a figure created by your own finance team is more useful in an approval meeting. Work with finance to calculate the cost of a vacancy using the company's own revenue, workload, overtime, contractor and operational data. A smaller number that finance has built and accepts is more useful than a larger number that finance does not trust.

The direct cost of filling a role is easier to establish, but it should not carry the entire business case. CIPD's 2024 research put the median UK cost of recruiting a senior manager at £2,000, down from £3,000 two years earlier. That type of figure can help estimate the sourcing and recruitment cost, but the case for a hiring OS should also show what happens to the broader costs around hiring.

Finance ultimately wants to see payback, not just a total list of benefits. Put twelve months of platform costs against the specific savings and avoided costs the business can support. Then show the month in which those savings cover the investment.

If the investment does not pay back within the company's budget horizon, do not force the numbers. State that clearly and make the case around other measurable outcomes, such as reduced agency dependence, greater hiring capacity or lower operational risk. A payback calculation that does not survive scrutiny can weaken an otherwise strong business case. What a CFO asks before approving hiring software is the shape finance will want it in.

Finance is also not necessarily the slowest part of the approval process. Vertice's procurement data puts average commercial approval at 8.3 days, with 45% of approvals completed within one day. Contract value has a larger effect on the overall timeline. In Q2 2026, Vertice recorded an average of 54 days from request to signature for contracts below $10,000, compared with 81 days for contracts between $50,000 and $100,000. Contracts above $100,000 took 93 days.

The practical lesson is to give finance a case it can put into the budget. Name the line item, show the expected change, state when it should happen, and make clear which numbers are confirmed and which are assumptions. That gives finance something it can validate rather than a collection of efficiency claims it has to translate into financial terms.

What does procurement need, and how early?

Procurement needs to start earlier than most buying teams expect. The documents are usually predictable, but collecting and reviewing them can take time. Vertice measures the average intake stage at 10.3 days and legal approval at 9.6 days. Forrester's 2026 research also found that procurement is involved in 53% of business buying cycles, which means it can be part of the decision from much earlier in the process than the final purchasing stage.

Procurement is not primarily deciding whether the hiring platform is good. Its job is to make sure the vendor meets the company's purchasing requirements and that the necessary documentation is in place. This normally includes the vendor's legal entity and registration details, insurance certificates, financial information, data-processing terms, subprocessor list, standard contract and information about which contractual terms can be negotiated. Procurement may also request customer references and a completed security questionnaire.

Most of these documents should be straightforward for an established vendor to provide. The potential delays tend to come from documents or people that require additional work. A detailed security questionnaire may need several teams to complete. Contract changes may need to be reviewed and approved by both sides. Customer references also depend on other people's availability, particularly when procurement wants to speak to a reference directly.

References can be an important part of the process. TrustRadius's survey of 2,058 technology buyers found that 77% looked at user reviews before making a purchase, while 54% spoke directly with another user. That means procurement or other stakeholders may reasonably expect a vendor to provide customers who are willing to discuss their experience. A vendor that cannot provide contactable references may have an additional question to answer during the approval process.

The resulting delay is measurable. Vertice reports that legal approval takes 9.6 days on average and 14 days at the 80th percentile, with only 42% of legal reviews completed within one day. The intake stage alone averages 10.3 days. Across the software contracts Vertice processed in Q1 2026, the average time from request to signature was 72 days. In June 2026, new software purchases averaged 36 days, while renewals averaged 87 days.

Two habits can reduce unnecessary waiting. First, ask the shortlisted vendor for the complete procurement pack before the final decision is made. This gives procurement, legal and security time to review the material while the buying team is still evaluating the platform.

Second, understand your company's purchasing thresholds before you start. Find out which spend level triggers a competitive process, when legal review becomes mandatory and when the company requires multiple quotes. These requirements can change the buying process significantly. The procurement checklist for a hiring OS is the pack to assemble meanwhile.

A competitive process is also something to plan for rather than assume you can avoid. Sapient's HR Systems Survey references 1,539 technology products across 22 segments. Procurement therefore has a reasonable basis for asking why a particular vendor was selected and what alternatives were considered. Saying that there was only one possible supplier is unlikely to be enough without evidence.

The security review should run alongside procurement rather than after it. Both processes depend on information from the vendor, so starting them together can prevent one completed review from simply waiting for the other.

What do IT and security review?

IT and security want to know four basic things:

  • where candidate data is stored;
  • who can access it;
  • what the vendor does with it;
  • and whether the platform makes or influences decisions automatically.

The first part is a standard vendor security review. It usually covers hosting and data residency, encryption in transit and at rest, access controls and single sign-on, audit logs, backups and retention, incident response and the vendor's list of subprocessors.

Security certifications can make this process easier. A current SOC 2 Type II report or ISO 27001 certification does not prove that a product is completely safe. It does, however, give the security team documented evidence that it can review instead of starting every assessment from scratch. That matters when the vendor already has the relevant documentation available.

Vertice's procurement data puts IT and security approval at an average of 7.1 days, with 55% of approvals completed within one day. A vendor that can provide its security documentation as a complete pack gives the internal security team a much easier review to work through.

That matters because security teams are already dealing with substantial compliance workloads. Vanta's survey of 2,500 IT and business leaders found that compliance work had increased to 11 working weeks per year. Only 24% rated their visibility into vendor risk as very strong. A complete vendor security pack can therefore remove unnecessary back-and-forth from a process that is already demanding.

The AI question

The second part of the review is newer. It becomes particularly important when the hiring platform uses AI to score, rank, filter or recommend candidates.

AI is already common in business software. Ramp's data from more than 70,000 businesses found that almost half of small businesses pay for AI tools. But AI used in hiring can create additional legal requirements because some jurisdictions regulate automated employment decision-making specifically.

The exact requirements depend on where the employer operates and what the system actually does. Three sets of rules are particularly relevant here. The status below is as of 15 September 2026.

New York City: Local Law 144

Local Law 144 has been enforced by the Department of Consumer and Worker Protection since 5 July 2023.

For covered automated employment decision tools:

  • The tool must have undergone a bias audit within one year before it is used
  • Candidates must receive notice at least 10 business days before the tool is used.

European Union: AI Act

The EU AI Act, Regulation 2024/1689, was amended by Regulation 2026/1744 on 8 July 2026.

Under Annex III, AI systems intended for recruitment or selection are classified as high risk when they are used for activities such as filtering applications or evaluating candidates. The same applies to certain systems used for decisions about promotion, termination, task allocation and performance monitoring.

The timeline matters for procurement. The high-risk obligations for these systems were moved from 2 August 2026 to 2 December 2027 by the 2026 amendment. Certain AI systems embedded in regulated products have a later date of 2 August 2028.

Once the relevant obligations apply, organisations deploying these systems will have requirements that include assigning appropriate human oversight. They will also need to retain system logs for at least six months and inform workers' representatives and affected workers before using covered systems in the workplace.

Colorado: SB 26-189

Colorado's SB 26-189 was signed on 14 May 2026 and replaces SB 24-205. It takes effect on 1 January 2027.

The new law replaces the previous law's reasonable-care and impact-assessment requirements with a disclosure-focused regime for automated decision-making technology used in consequential decisions, including employment.

Developers must provide deployers with technical documentation. Deployers must provide clear notice at the point of interaction, and consumers can request human review after an adverse decision.

None of these laws simply bans hiring software that uses AI. The important question is what the system actually does and how people remain involved in the decision.

What do hiring managers resist?

Hiring managers usually do not resist the tool itself. They resist the part of the hiring process where they currently use their own judgement and believe the new system may take that judgement away.

This is also the approval that can fail quietly. A manager may agree with the proposal in the meeting but continue interviewing candidates in the way they always have. The new platform then becomes a system of record rather than the system actually running the hiring process. The organisation has bought the software, but the behaviour has not changed.

What the manager is protecting is usually specific. A manager who has experienced a bad hire may have developed a screening question they always ask, a take-home exercise they trust or a particular reference check they consider important. When a new platform standardises screening, the manager may see that as replacing their judgement with someone else's process. Unless the organisation can show why the new approach works, that concern is understandable.

The problem is that organisations often struggle to measure whether either approach is actually producing better hires. LinkedIn's Future of Recruiting survey of 1,271 recruiting professionals, conducted in September 2024, found that 89% expected measuring quality of hire to become increasingly important, while only 25% were highly confident in their organisation's ability to measure it. Among organisations that did measure quality of hire, 66% used job performance ratings, 60% used new-hire retention and 44% used hiring manager satisfaction.

That creates a difficult conversation. The manager is defending a process that may not have a reliable measure of success, while the new process is also being asked to prove that it is better.

The solution is to be precise about what the platform is actually standardising. Scheduling, interview coordination, record keeping, candidate communication and the structure of a scorecard are process activities. They can be standardised without removing the manager's responsibility for deciding whether a candidate is right for the role.

If the platform scores or ranks candidates, be equally clear about that. Show managers what the system is assessing and where they can review or override its recommendations. Do not describe an automated recommendation as though it were simply administrative automation. How to get hiring managers to back a new hiring process covers the override question from the manager's side.

This distinction also matters for compliance. Under the EU AI Act, relevant high-risk AI systems used for recruitment and selection will be subject to requirements around human oversight from 2 December 2027. An organisation buying a platform in 2026 may therefore still be using it when those requirements apply. Human oversight needs to be designed into the process rather than added later as a checkbox.

The easiest way to build trust is to give managers an immediate benefit. Remove one piece of coordination work from their desk as soon as the new process begins. That might mean taking over interview scheduling, booking the panel or handling follow-up between stages.

The message should be simple: the platform is taking administrative work away from the manager, not taking the hiring decision away from them. That makes the change easier to understand and gives managers a reason to use the process rather than quietly working around it.

Who signs, in what order, and where do the weeks go?

The approval process should not be treated as one long sequence. Security and procurement should start as soon as a vendor is shortlisted and run in parallel. Legal can then work from the security information it receives. Finance can work alongside these reviews because its calculations are based on the company's own costs. Hiring managers should be involved throughout because their approval is behavioural rather than contractual. There is no signature that proves they have approved the process.

Approver The question they are really asking What they need from you Measured stage time (Vertice, 2026)
Finance Which line item shrinks, by how much, and when? A payback model based on named cost lines, with vacancy costs calculated with finance rather than taken from a vendor estimate. 8.3 days on average; 11 days at the 80th percentile
Procurement Does the vendor pack exist, and does the purchase meet our thresholds? Entity and insurance documents, data-processing terms, subprocessor list, contract redlines and contactable references. Intake: 10.3 days; negotiation: 11.8 days
IT and security Where does candidate data live, and who can access it? SOC 2 or ISO 27001 documentation, SSO support, retention and deletion terms, and incident-response commitments. 7.1 days on average; 8 days at the 80th percentile
Legal Are we taking on an obligation we cannot meet? Information about automated decision-making, audit documentation, candidate-notice requirements and the jurisdictions involved. 9.6 days on average; 14 days at the 80th percentile
Hiring managers Does my judgement survive this process? A clear boundary between administrative coordination and hiring decisions, plus one practical improvement they can experience quickly. Not measured; approval continues after signature

If these stages were run entirely in sequence, Vertice's measured averages would add up to 47.1 days: 10.3 days for intake, 8.3 for commercial approval, 7.1 for IT and security, 9.6 for legal and 11.8 for negotiation. Yet the average software contract still took 72 days from request to signature in Q1 2026.

The difference matters. Those additional days are not necessarily another formal review. They can represent time spent waiting for the next person or team to become available. Running the reviews in parallel reduces some of that queueing. When stages genuinely can run at the same time, the longest stage becomes more important than the sum of every stage.

Hiring-manager approval is particularly easy to leave out because there is no signature to track. A manager can agree with the business case and still continue using the old process. The real evidence of approval is whether managers actually use the new workflow.

That means hiring managers need to be involved while the other reviews are happening, rather than brought in after the contract is signed. They should help define where the platform handles coordination and where their judgement remains essential. They should also see a practical benefit early, such as less scheduling or follow-up work.

The goal is not simply to collect five approvals. It is to have five groups ready to approve the purchase and use the process when the contract is signed.

Conclusion

A hiring OS does not need five separate business cases. It needs one case that answers five different questions.

Finance needs to see which costs change and when. Procurement needs the vendor documentation and purchasing requirements. IT and security need evidence about data, access and risk. Legal needs to understand the obligations created by the platform. Hiring managers need to know where the technology supports their work and where their judgement remains in control.

The easiest way to prevent the purchase from stalling is to start these conversations before the vendor is selected. Collect the procurement and security documentation early. Build the financial case around costs the company can actually measure. Involve legal before the contract becomes urgent. Give hiring managers a clear role in designing the process rather than asking them to adopt it after the fact.

The approval process is therefore part of the buying decision, not the step that comes after it. When each stakeholder has the information they need and the reviews that can run in parallel actually do so, fewer days are spent waiting for the next approval.

For a hiring leader, that is the real objective: not simply getting the software signed off, but getting the organisation ready to use it when the signature is on the contract.

Frequently asked questions

How long does the hiring software approval process take?

There is no single timeline. Vertice measured an average of 36 days for a new software purchase in June 2026, while contracts worth $100,000 or more took an average of 93 days in Q2 2026. The difference can come from contract value, how many reviews are required and whether those reviews run in parallel. Legal review alone takes 9.6 days on average and 14 days at the 80th percentile. Security can also take longer when the vendor has to complete a bespoke questionnaire rather than providing an existing security pack.

Do we need a business case if the budget is already approved?

Yes, although the purpose changes. An approved budget addresses the financial availability of the money. It does not automatically clear procurement, security or legal. On Vertice's data, those stages average 27 days combined: 10.3 days for intake, 7.1 days for IT and security, and 9.6 days for legal. Queueing between stages can add more time.

A business case also gives you something to return to when the contract comes up for renewal. If you have documented which costs were expected to change and what outcomes the platform was supposed to deliver, you have a much clearer basis for deciding whether the investment should continue.

Who should own the approval process?

The person responsible for the hiring outcome should usually coordinate the process. In many organisations, that will be the talent leader or another senior hiring owner. The approval process involves questions about hiring costs, workflow, candidate data and manager adoption, so the person coordinating it needs enough context to connect those pieces.

That does not mean the talent team should complete every review. Finance, procurement, security and legal should own their respective assessments. The talent leader's role is to make sure the right information reaches each team and that no stage is left waiting unnecessarily.

What if security comes back with findings?

Expect some findings. The important thing is to understand what they mean and what needs to happen next.

Ask security to document each finding and give it a severity or priority. Then identify who owns the response and whether the issue needs to be fixed before the platform can be approved. A documented list of issues, owners and actions is much easier for legal and procurement to work with than an informal statement that the vendor has "some security concerns."

This can also help distinguish between a blocking risk and an issue that can be addressed through a contract commitment, configuration change or later remediation.

Does a pilot skip any of this?

Usually, no. A pilot can reduce the size of the commercial commitment, but it does not automatically remove the security, privacy or legal review. Forrester's 2026 research found that more than 60% of business buyers use trials, showing how common pilots have become.

If the pilot uses real candidate data, the organisation still needs to understand where that data goes, who can access it, how long it is retained and what the vendor does with it. The fact that the arrangement is temporary does not make the data less sensitive.

The same principle applies to AI-related requirements. Where applicable, regulatory obligations can depend on how a system is used rather than whether the organisation has signed a long-term contract. A pilot can therefore be useful for testing the product and reducing commercial commitment, but it should not be treated as a way around the approval process.

Sources

Where Hivemind fits

Hivemind runs these steps for you, in one platform.

JH

Written by

James Hitch

COO

James Hitch is COO of HiveMind, the hiring OS for modern staffing firms. He leads the company’s day-to-day operations, aligning teams across product, growth, customer success, recruiting, and internal systems to turn strategic priorities into consistent execution. His writing translates those operational conversations into clear, practical guidance for staffing teams: how to unlock value from an existing candidate database, reduce time to first submittal, build meaningful desk-level metrics, and apply AI where it materially improves speed, judgment, and recruiter capacity.

Share this article

Help others discover this content