Procurement is not responsible for deciding whether a hiring platform is the right tool. Its role is to make sure the vendor meets your organisation’s purchasing requirements before a contract is signed. That means checking that the vendor pack is complete, the purchase meets your internal approval thresholds, and the contract clearly explains what happens during the initial term and at renewal.
The vendor pack should contain the same core documents for every supplier. These typically include the vendor’s legal and registration details, insurance certificates, financial information, data-processing terms, subprocessor list, standard contract, proposed contract changes, references, and completed security documentation.
Some of these documents can take much longer to obtain than others. Security questionnaires often need input from several people. Contract changes may need to go through legal teams on both sides. References may also need to find time for a call.
This is why procurement should get involved at shortlist stage rather than waiting until the final decision. Starting the paperwork early allows the team to identify missing information and resolve contract issues while the hiring team is still evaluating its options. It removes delays that have little to do with the actual buying decision.
The data-processing terms also need particular attention. These are not simply a procurement preference. Where the hiring platform processes personal data on your organisation’s behalf, the appropriate data-processing agreement and related privacy terms are part of the legal requirements around that processing.
This is the procurement section of the hiring software approval process, and it is the review that should start first.
In this article
- Who is procurement, and when do they engage?
- What is in the vendor pack?
- What are your own thresholds?
- Where do the days go?
- Why do references and reviews matter?
- What does the contract need to say about renewal?
- Conclusion
- Frequently asked questions
Who is procurement, and when do they engage?
Procurement should be treated as a decision-making partner from the start, not as the team that appears when everyone else has already made their choice.
Forrester's 2026 buyer research identifies procurement professionals as decision makers in 53% of business buying cycles. They engage from the beginning of the process and typically work within decisions involving 13 internal stakeholders and nine external influencers.
This matters because procurement teams are often managing more work with fewer resources. The Hackett Group projects that procurement workloads will increase by 8% in 2026 while headcount and operating budgets decline. AI-enabled technology is also now one of procurement's top three priorities, following a near doubling in deployment year over year.
The volume of software purchases adds another layer of pressure. Zylo's index reports that smaller companies use an average of 152 SaaS applications, while large enterprises use an average of 660. A hiring platform is therefore one procurement request among hundreds of other software purchases, renewals and vendor reviews.
Think of the procurement contact as a colleague with a queue rather than a final checkpoint. They need the information required to assess the purchase before they can move it forward.
The practical response is simple: involve procurement early and give them a complete vendor pack. If they have the required documents at shortlist stage, they can start their review while the hiring team completes its evaluation. That makes it less likely that procurement becomes the reason a decision sits idle after everyone else is ready to proceed.
What is in the vendor pack?
The vendor pack gives procurement the information it needs to assess the supplier and move the purchase through the approval process.
It should include:
| Document | What procurement is checking |
|---|---|
| Legal entity and registration | Who the contracting entity is and whether it is properly registered |
| Insurance certificates | Whether the vendor carries the required insurance |
| Financial standing | Whether there are concerns about the vendor's financial position |
| Data-processing terms | How personal data will be processed and what obligations apply |
| Subprocessor list | Which other companies may process data on the vendor's behalf |
| Standard contract | The vendor's standard legal terms |
| Contract deviations | Which clauses the vendor is willing to negotiate or change |
| References | Contactable customers who can speak about their experience |
| Security questionnaire | Whether the vendor meets your security requirements |
| Audit report | Independent evidence supporting the vendor's security controls |
Some parts of the pack take considerably longer to obtain than others. The security questionnaire may require information from several teams at the vendor. Contract documents may need to be reviewed and countersigned by legal teams. References also depend on customers being available for a call.
These items should therefore be requested before the final purchasing decision, rather than after everyone has agreed to buy.
Data-processing terms
The data-processing terms are a legal requirement, not simply a procurement preference. Under GDPR Article 28, when a processor handles personal data on behalf of a controller, the processing must be governed by a contract. That contract needs to cover areas such as the subject matter and duration of processing, its nature and purpose, the types of personal data involved, and the obligations of the parties.
Subprocessors also need to be addressed. A processor cannot simply appoint another processor without the required authorisation from the controller.
Retention should be covered at the same time. The ICO's audits of AI recruitment providers found that retention was often left to the recruiter, with periods commonly set at one or two years after a requisition closed. Where possible, make the retention period explicit in the contract rather than leaving it as an informal operating practice.
The audit report
An audit report should not simply be added to the procurement folder and marked as complete. Someone needs to read it and understand what it actually demonstrates.
For example, ISO/IEC 27001:2022 sets requirements for an information security management system. The AICPA's Trust Services Criteria provide criteria used in attestation engagements covering areas such as security, availability, processing integrity, confidentiality and privacy.
The organisation that performed the examination matters too. The Journal of Accountancy has reported that many newer SOC tool providers are not CPA firms themselves and therefore cannot perform the attestations that establish whether controls are effective. Some instead work with networks of smaller accounting firms to complete the examinations.
Ask two straightforward questions:
- Who performed the examination;
- And what period did it cover?
The answer helps procurement understand whether the report provides current, relevant evidence about the controls being relied on, rather than simply confirming that an audit report exists.
What are your own thresholds?
Before you start talking to a vendor, find out how your organisation handles purchases at different spend levels.
You need to know the threshold that triggers a competitive process. You also need to know when legal review becomes mandatory and when procurement requires more than one quote. These rules are normally set out in your internal procurement policy.
Public-sector organisations publish their thresholds, which gives a useful example of how these approval levels can work. Under the US Federal Acquisition Regulation, the micro-purchase threshold is $15,000 and the simplified acquisition threshold is $350,000, subject to specific exceptions.
Private companies generally have their own internal thresholds. They may be considerably lower or structured differently. The important point is to find out what applies to your organisation before the vendor conversation begins.
The contract value can also affect how long the purchase takes. Vertice's Q2 2026 data shows that software purchases under $10,000 took an average of 54 days from request to signature. Contracts worth $50,000 to $100,000 took 81 days. Contracts of $100,000 or more took 93 days.
This means the price of the hiring platform can affect the procurement process itself. A higher-value contract may bring more stakeholders into the review and require additional legal, security or executive approval.
Practical threshold checklist
Before the vendor reaches the shortlist, answer these questions:
| Question | What to confirm |
|---|---|
| What is the total contract value? | Include implementation, licences, services, usage fees and expected renewal costs |
| What spend threshold applies? | Identify the internal approval level for this purchase |
| Are multiple quotes required? | Confirm whether procurement needs two or more suppliers to be considered |
| Is a competitive process required? | Check whether the spend requires an RFP, tender or other formal process |
| When does legal review become mandatory? | Confirm the contract value or terms that trigger legal involvement |
| Who must approve the purchase? | Identify procurement, finance, legal, security and executive approvers |
| Does the renewal follow a different threshold? | Check whether renewal or expansion requires another approval |
| What is the expected procurement timeline? | Work backwards from the required go-live date |
| Are there exceptions? | Record any approved exception to the normal purchasing process |
You should also expect a requirement for more than one quote or supplier option. Your procurement policy may require competitive sourcing above a particular spend level.
The HR technology market is large enough that procurement may reasonably expect evidence that alternatives were considered. Sapient Insights' 2025-2026 HR Systems Survey references 1,539 technology products across 22 HR technology segments.
That does not mean you need to evaluate hundreds of products. It means that saying "there was only one candidate" is unlikely to satisfy a competitive procurement requirement on its own.
If your hiring team has already narrowed the market, document why those vendors were considered and why the shortlisted options fit the requirements. That gives procurement something concrete to review instead of asking them to accept a purchasing decision they were not involved in making.
Where do the days go?
A hiring platform can be ready to buy while the purchase is still weeks away from approval. The delay is rarely one big task. It is usually a series of small waits: procurement finishes its review, then security starts, then legal waits for security, then contract negotiation begins.
Most procurement delays happen because these stages run one after another when they could be happening at the same time.
Vertice measures the average intake stage at 10.3 days and customer negotiation at 11.8 days. Its data shows that a new software purchase took 36 days on average in June 2026, while a renewal took 87 days.
Two practical changes can reduce unnecessary waiting.
- Ask for the complete vendor pack when you shortlist the supplier.
Do not wait until the hiring team has made its final decision. Procurement can start checking the documents while the remaining evaluation is happening.
- start security and procurement on the same day.
These reviews often depend on one another later in the process. Legal may be waiting for security's findings before it can complete its review, while contract negotiation may then depend on legal's input. Starting the work together reduces the amount of time spent waiting for another team to finish.
The buyer's own pace also matters. Capterra's survey of more than 3,300 software buyers found that two-thirds experienced implementation disruption, purchase regret, or both. Only around one in three were classified as successful adopters. The survey also found that successful adopters typically made their choice within three months, while longer buying timelines were associated with dissatisfaction. More than half had an implementation plan.
Speed alone does not make a procurement process good. A rushed purchase can create problems later. But a process that simply sits between stages is not necessarily more careful.
The goal is to move each review forward as soon as its inputs are available. Give procurement the information early, run independent reviews in parallel, and identify dependencies before they become blockers.
Why do references and reviews matter?
Reviews and references answer different questions:
- Reviews show you what a broader group of customers say about the product;
- References let you ask specific questions of customers with a similar use case.
You need both because they provide different types of evidence.
TrustRadius's survey of 2,058 technology buyers found that 77% looked at user reviews and 54% spoke directly with a user before buying. Forrester's research also found that more than 60% of business buyers now use a trial as part of the buying process.
Reviews: the wider customer picture
Independent reviews can reveal patterns across many customers. Look for recurring comments about implementation, support, reliability, integrations, usability and pricing.
Reviews are particularly useful early in the process. They help you understand the common customer experience before you spend time arranging vendor calls or references.
Do not treat every review as equally reliable. Check how recent it is, whether the reviewer appears to have a similar use case, and whether the same issue appears across multiple reviews.
References: evidence from similar customers
A reference is different. The vendor connects you with a customer who has agreed to discuss their experience.
This gives you the opportunity to ask questions that a public review cannot answer. You can ask how long implementation took, what went wrong, how the vendor responded, and whether the product delivered what was expected.
Capterra's research found that 89% of buyers who regretted a software purchase had experienced implementation disruptions first. That makes implementation a useful focus for reference calls.
Ask references:
- How long did implementation actually take?
- What caused the biggest delays?
- Did the vendor deliver what was promised during the sales process?
- How responsive was the support team after go-live?
- Were there unexpected costs or additional work?
- What would you want to know before signing the contract?
Use reviews to identify patterns and references to investigate those patterns in context.
A vendor that cannot provide relevant, contactable customers also leaves an important part of the procurement process unanswered. The reference call is a relatively low-cost way to learn what implementation may look like before your organisation commits to the same process.
What does the contract need to say about renewal?
Renewal should not be a surprise conversation that starts a few weeks before the contract expires. The contract should make the renewal process clear from the beginning.
At a minimum, check four things:
| Contract term | What to confirm |
|---|---|
| Renewal date | When the initial contract ends and when renewal takes effect |
| Notice window | How much notice you must give if you do not want to renew |
| Price increase | Whether annual increases are capped and how the new price is calculated |
| Data at termination | What happens to your data when the contract ends, including access, export and deletion |
Renewals can also take longer than new purchases. Vertice's June 2026 data shows an average of 87 days for a renewal compared with 36 days for a new software purchase.
That makes the renewal terms particularly important. If your organisation has to give notice 30, 60 or 90 days before the renewal date, procurement needs enough time to review usage, price and performance before that deadline arrives.
A practical renewal timeline
Do not work backwards from the renewal date alone. Work backwards from the notice deadline in the contract.
| Step | Action | Owner |
|---|---|---|
| First | Confirm the renewal date, notice period and pricing terms | Procurement |
| Then | Review usage, adoption, support history and agreed outcomes | Business owner |
| Then | Ask the vendor for renewal pricing and updated terms | Procurement |
| Then | Review commercial terms, security requirements and any proposed changes | Procurement, legal and security |
| Then | Decide whether to renew, renegotiate or begin an alternative process | Business owner and procurement |
| Before the contractual notice deadline | Send the required renewal or non-renewal notice | Procurement |
| Then | Complete negotiation and approvals | Procurement and legal |
| Before the new term begins | Sign the agreement and confirm billing and access arrangements | Procurement |
The exact dates should follow your organisation's procurement process and the notice period in the contract. A 90-day notice clause means you cannot safely treat the renewal as a 30-day task.
Price is only part of the renewal discussion. Vendr's transaction data shows that annual contract values for both new purchases and renewals declined in 2024 compared with 2023. Its data also points to buyers paying closer attention to software usage and the outcomes they are getting from their purchases.
Those questions should not wait until renewal. At the point of signing, agree on what will be measured, how usage will be reported, and what outcomes the organisation expects from the platform.
For a hiring platform, that might include measures such as adoption, usage by hiring teams, time spent on parts of the hiring process, or completion of required workflows. The specific measures should reflect what the organisation is actually buying the platform to achieve.
Put those measures and the agreed usage reporting into the contract or an accompanying schedule where appropriate. When renewal arrives, both sides can then review the same numbers rather than starting the conversation from scratch.
The aim is simple: make renewal a review of agreed evidence, not a last-minute renegotiation of whether the software is still useful.
Conclusion
A hiring platform does not become approved when everyone agrees that they want it. It becomes approved when the organisation has enough evidence to buy it, the right people have reviewed it, and the contract protects what happens after the purchase.
That process can take weeks because procurement, security, legal and the business are each answering different questions. The problem is not that those questions need to be asked. The problem is asking them one after another.
Start procurement when the vendor reaches the shortlist. Confirm your spend thresholds before the vendor conversation. Request the complete vendor pack early. Run procurement and security in parallel where possible. Use reviews to understand the wider customer experience and references to investigate the issues that matter to your organisation.
Then look beyond the first contract signature. Agree on renewal dates, notice periods, price increases, data handling and outcome measures before you need them. A renewal should be based on information you have been collecting throughout the contract, not a decision made under a deadline.
The practical principle is simple: procurement should remove uncertainty, not create delay. Give every reviewer the information they need, start dependent work as early as possible, and put important expectations into the contract.
Final approval checklist
Before moving the hiring platform to final approval, confirm:
| Check | Complete |
|---|---|
| The correct contracting entity has been verified | ☐ |
| The vendor pack is complete | ☐ |
| Required insurance and financial information has been reviewed | ☐ |
| The security questionnaire has been completed | ☐ |
| The relevant security or audit report has been reviewed | ☐ |
| Data-processing terms have been agreed | ☐ |
| Subprocessors have been identified and reviewed | ☐ |
| Required customer references have been completed | ☐ |
| The organisation's spend threshold has been confirmed | ☐ |
| Required quotes or competitive process requirements have been met | ☐ |
| Legal review is complete | ☐ |
| Pricing and commercial terms are approved | ☐ |
| Renewal date and notice period are recorded | ☐ |
| Any renewal price increase is understood or capped | ☐ |
| Data export and deletion requirements are agreed | ☐ |
| Usage and outcome measures are defined | ☐ |
| Every remaining open item has an owner and deadline | ☐ |
Once the checklist is complete, procurement should not need to restart the evaluation. The remaining step is to record the approvals, sign the contract and hand the agreed requirements to the people responsible for implementation.
Before you ask for final approval, make every open item visible. If something is unresolved, give it an owner and a deadline. If it is resolved, record the evidence. That simple discipline turns procurement from a final hurdle into a controlled transition from buying decision to implementation.
Frequently asked questions
What documents should be in the vendor pack before we shortlist?
The vendor pack should give procurement, security and legal enough information to start their reviews without repeatedly going back to the vendor.
At a minimum, request:
| Document | Purpose |
|---|---|
| Legal entity and registration details | Confirms who you would be contracting with |
| Insurance certificates | Confirms the vendor carries the required insurance |
| Financial information | Supports the assessment of the vendor's financial standing |
| Data Processing Agreement (DPA) | Sets out how personal data will be processed |
| Subprocessor list | Shows which other providers may process your data |
| Security questionnaire | Documents the vendor's security controls and practices |
| Independent audit or assurance report | Provides supporting evidence for the security controls described |
| Standard contract | Shows the vendor's proposed legal and commercial terms |
| Contract deviation or negotiation position | Shows which clauses the vendor will and will not change |
| Customer references | Provides customers who can be contacted about their experience |
You may also need additional documents depending on your organisation's requirements. These could include a business continuity plan, disaster recovery information, privacy documentation, financial accounts or specific regulatory certifications.
Do not treat the audit report as a substitute for the security questionnaire. The questionnaire explains what the vendor says it does. The audit or assurance report provides independent evidence about the controls that were examined.
The same applies to the contract and the data-processing agreement. The DPA should be reviewed alongside the main contract so that data processing, subprocessors, retention, deletion and other privacy obligations are clear.
Does a small contract skip procurement?
A small contract may fall below the threshold for a competitive procurement process, but that does not automatically remove the other reviews.
You may still need to review data-processing terms, security requirements and the contract itself. If a paid pilot uses real candidate data, treat the data processing and security implications seriously from the beginning rather than assuming the pilot avoids the normal controls.
Check your organisation's own procurement policy to see which requirements are triggered at each spend level.
How long should the procurement stage take?
There is no single timeline that applies to every organisation. Vertice measures average intake at 10.3 days and negotiation at 11.8 days. Its data shows that the average time for a new software purchase was 36 days in June 2026.
The biggest opportunity is usually reducing the time spent waiting between stages. A complete vendor pack, early procurement involvement and parallel security and procurement reviews can prevent one team's work from sitting idle while another team finishes.
When should procurement get involved?
Procurement should be involved when a vendor reaches the shortlist, not after the business has already made its final decision.
This gives procurement time to check spend thresholds, request missing documents, begin its review and identify any competitive sourcing requirements. It also gives legal and security teams more time to resolve issues before the intended purchase date.
What should we ask a customer reference?
Use the reference call to investigate the parts of the buying process that a sales demo cannot show you.
Ask how long implementation actually took, what caused delays, how responsive the vendor was after signing, whether there were unexpected costs or additional work, and whether the product delivered what was promised. Choose references with a similar organisation size, use case or implementation environment where possible.
What should we check before renewal?
Start with the contract's renewal date and notice period. Then review actual usage, agreed outcomes, support history, pricing and any proposed changes to the terms.
Do not wait until the renewal deadline to start this work. Give procurement enough time to negotiate or run an alternative process if the organisation decides not to continue. The contract should also make clear what happens to organisational data if the agreement ends.
Sources
- The State of Business Buying, 2026, Forrester
- Stage completion times, procurement cycle time and cycle time by contract value, Vertice, 2026
- Bridging the Trust Gap, TrustRadius, 2025
- 2025-2026 HR Systems Survey, Sapient Insights Group
- 2025 SaaS Management Index, Zylo
- 2026 Software Buying Trends, Capterra
- SaaS Trends Report 2025, Vendr
- 2026 Procurement Key Issues Study, The Hackett Group
- FAR 2.101, acquisition.gov
- Regulation (EU) 2016/679, Official Journal
- Trust Services Criteria, AICPA; ISO/IEC 27001:2022, ISO
- Promises of fast and easy threaten SOC credibility, Journal of Accountancy
- AI tools in recruitment: audit outcomes report, ICO

