Procurement Policy: How to Create Rules That Are Actually Followed

Most organisations have a procurement policy. Few actually follow it. It's not because employees are disloyal or lazy — it's because the policy is written in a way that makes it impossible to follow. Long documents in legal jargon, contradictory rules, and no clear enforcement. The result is maverick buying, frustration, and a procurement team that spends its days cleaning up deviations.
In this article you'll learn how to create a procurement policy employees actually follow — and how to enforce it without making life miserable for anyone. With concrete examples and a template you can adapt to your organisation.
Key takeaways
- • A good procurement policy is simple, concrete and built into the system — not a PDF document
- • The most important elements: approval limits, contract use, supplier selection, documentation
- • Enforcement happens best automatically via the procurement system, not through after-the-fact checks
- • Goal: 80% adoption in 12 months, not 100% on day one
Why most procurement policies fail
The classic procurement policy is a 30-page PDF written by the legal department. It covers everything from "definitions" to "sanctions", with detailed rules for every imaginable situation. It's stored on the intranet and never read after the onboarding click-through.
The result is predictable. When Lars in marketing needs new laptops for a campaign, he goes directly to a supplier he knows — because he doesn't know where the contract is, what approval he needs, or whether the laptop is even within budget. He buys "the usual way" and the policy is just a set of rules that were broken.
Three reasons this happens:
- Too long and complex: People don't read 30 pages to order a chair
- Not built into the workflow: The policy lives in one system, ordering happens in another
- No real enforcement: Breaches are discovered — if at all — after the fact through audits
Principles behind a policy that actually works
1. Plain language
Write as if the reader is a new employee in their first week. "Purchases over €1,000 must be approved by your manager" beats "Procurement of value exceeding EUR 1,000 requires prior authorisation by the reporting manager or their deputy".
2. Concrete, not generic
"Use contracted suppliers" means nothing. "For office supplies: Staples. For PCs and IT: Dustin. For PPE: SafeProAS." means something.
3. Built into the system
A policy that requires employees to remember the rules has already lost. A policy built into the ordering system — so the system automatically suggests the right supplier and blocks orders without approval — works without anyone needing to remember anything.
4. Consequence without fear
People should know what happens on breach — but the focus should be prevention, not punishment. A policy that opens with threats ends with people hiding deviations instead of reporting them.
The 6 key elements of a modern procurement policy
1. Approval limits
Who can approve what? Define clearly in amounts and roles.
2. Contract use
List specific contracted suppliers per category. Define when off-contract is allowed (typically: product not on contract, or urgent need). Requirement: always justified in writing and logged.
3. Supplier selection
For new suppliers: minimum three quotes above a given amount. Requirements for supplier status (D&B, certifications, VAT-registered). Use a standardised supplier approval process.
4. Documentation
What must be documented? Order, approval, receipt, invoice. Everything traceable in one system. Invoices: always with order number.
5. Sustainability and ethics
What requirements apply to suppliers? Environmental certification, transparency act, anti-corruption. Concretise with industry-specific requirements.
6. Consequences of breach
What happens on deviation? First time: dialogue and follow-up. Repeat breaches: formal feedback to manager. Wilful breaches: HR case. Be clear, but start gently.
How to enforce the policy through the procurement system
The biggest change in modern procurement is that the policy no longer lives in a document — it lives in the system. With a good procurement system like Vieri you can:
- Automatic approval rules: Orders routed to the right approver by amount, category and department
- Contract compliance built in: Contracted suppliers suggested first, alternatives require justification
- Real-time budget control: Orders checked against available budget before approval
- Traceability on everything: Every order logged with approver, reason, timestamp and status
- Automatic deviation reports: When someone goes off-contract, procurement is alerted — no manual hunting
💡 Did you know?
Organisations that move the procurement policy from document to system make compliance something the system enforces rather than something people must remember. Not because employees suddenly read the policy — but because the system makes it easier to follow the rule than break it.
Implementation: How to get there
- Start with current practice. What do people actually do today? Map it before writing rules.
- Involve the users. Get employees on board early — they know where the friction is.
- Deliver on one page. If you can't get the policy on one page, you have too many exceptions.
- Build into the system. Configure approval flow and contract use in the procurement system.
- Communicate short and clearly. A 3-minute video beats 30 pages of PDF.
- Follow up monthly. Send monthly deviation report to leadership. Visibility creates change.
- Adjust based on data. If 30% of orders go off-contract, something is wrong with the contract — not the employees.
Bonus: For more on how uncontrolled spending costs you, read our article on maverick buying. To understand how automation enforces policies, see the guide to 3-way matching.
Build the procurement policy into the system
Vieri lets you configure approval flow, budget control and contract use so the policy is enforced automatically. Book a demo and see how your rules can become workflow.
Book demo →

