Governance & audit

Not just “the system has controls” — proof that they fire.

Auditors do not ask whether a control can work. They ask whether anyone tried to get round it, and what happened. Every refusal is recorded with who, what and when, beside the declarations and the activity trail.

Controls, with evidence

Every refusal is a record, not just a red message.

Self-approval. Acting above authority. Scoring without a declaration. Awarding to a supplier with lapsed documents. Each refusal is logged against the person and the record they tried it on.

  • BlockedWhat was refused, who attempted it, when, and against which record
  • PatternsEvaluator scoring outliers surfaced before award, not after a challenge — a flag is a prompt to ask, not an accusation
  • DeclaredEvery committee member on a live competition, and whether they have declared; Pending means they have not opened their scoring page
  • SegregatedThe controls are structural — a milestone cannot be certified by whoever achieved it, an award cannot be approved by its own owner
.../governance
Governance — Blocked attempts, scoring patterns and declarations, live.
GovernanceBlocked attempts, scoring patterns and declarations, live.
For the buyer

The controls are on your side in an argument.

A buyer under pressure to move quickly is the person a control protects. “The system will not let me” is a complete answer.

  • GateTwo evaluators minimum, each declared, before anything can be scored
  • GateA public buyer cannot propose an award before the consensus meeting is recorded
  • GateA non-competitive purchase needs a written justification, and it cannot be approved by whoever wrote it
  • ResultThe pressure to bend the process meets a system that does not bend, and the attempt is on the record
.../evaluations
Evaluation controls — Declaration first, then scoring — the gate is the screen itself.
Evaluation controlsDeclaration first, then scoring — the gate is the screen itself.
For an auditor

The trail is complete, chronological and already there.

Nothing here is assembled for an audit. It is the same record the organisation ran on, read in date order.

  • SimpleRead the activity log: who did what, to which record, and when
  • ThenFollow any purchase order back to the requisition that authorised it
  • ThenRead the evidence binder for an awarded competition, generated from what happened
  • ComplexTest a control by trying it — the refusal, and your attempt, are added to the same log
.../logs
Activity log — Who did what, to which record, and when.
Activity logWho did what, to which record, and when.
For the administrator

The policy document cannot drift from the system.

Every organisation has a procurement policy that stopped matching the system some time ago. This one is generated from the live configuration, so it cannot.

  • GeneratedProcurement Rules are produced from this workspace's own thresholds, routes and approval bands
  • CurrentChange a threshold and the document changes — there is no second copy to update
  • ExportableAvailable in the system and as a Word document for a policy pack
  • HonestIt states plainly which figures are enforced and which surrounding content is general practice for the organisation to adapt
.../rules
Procurement rules — The policy document, generated from live configuration.
Procurement rulesThe policy document, generated from live configuration.
For a CPO

The question you do not want to be asked twice.

“Can you show me that this was run properly?” has one good answer, and it is not a promise to look into it.

  • SeesWhether anyone has tried to bypass a control, and who
  • SeesDeclarations outstanding on competitions that are live right now
  • DoesActs on a scoring pattern before the award rather than after the challenge
  • ProofThe evidence exists whether or not anyone thought to collect it, because collecting it is not a separate task
.../governance
Governance — The three panels a review actually asks about.
GovernanceThe three panels a review actually asks about.