HomeLearnIT Procurement Process
Planning guide · Updated August 2026

IT Procurement Process and Best Practices

A sound IT procurement process defines the business need, sets measurable requirements, checks security and vendor risk, compares full lifecycle cost, tests the preferred option, records approval, and plans renewal or exit before a contract is signed.

Why a process matters

The cheapest quote can become the most expensive system

Technology purchases affect more than the budget. A new application may receive customer information, connect to Microsoft 365, create administrator access, require staff training, duplicate an existing tool, or become essential to daily operations. A laptop or firewall may need compatible warranties, management, security, and replacement planning.

Procurement gives those decisions a consistent path. It reduces shadow IT, duplicate subscriptions, unsafe vendors, contract surprises, unsupported hardware, and systems that cannot export their data. The process should be proportional: a keyboard needs little review, while a cloud platform holding sensitive records needs much more.

Eight stages

A practical IT procurement workflow

1. Intake

Describe the business problem

Name the sponsor, affected users, current pain, desired outcome, timeline, sensitivity, budget range, and what happens if nothing changes. Do not start with a preferred brand.

2. Current state

Check what you already own

Review existing licences, hardware, contracts, integrations, support capacity, and renewal dates. The best procurement may be consolidating or configuring an existing platform.

3. Requirements

Separate must-have from nice-to-have

Write measurable functional, technical, security, privacy, accessibility, support, migration, reporting, and exit requirements. Rank them before demonstrations begin.

4. Market scan

Create a defensible shortlist

Compare credible options, compatibility, vendor stability, implementation partners, references, support coverage, and roadmap fit. Record why candidates were included or rejected.

5. Due diligence

Assess vendor and supply-chain risk

Identify data access, sub-processors, remote connections, hosting location, security controls, vulnerability handling, incident notice, recovery, certifications, ownership, and concentration risk.

6. Cost and contract

Calculate lifecycle cost

Include purchase or subscription, implementation, migration, support, add-ons, storage growth, training, administration, renewal, taxes, currency, warranty, disposal, and exit.

7. Pilot and approval

Test with real work

Use representative users, files, devices, integrations, security controls, and failure scenarios. Score the results against the requirements and record who accepts residual risk.

8. Deploy and govern

Own the full lifecycle

Document configuration, assets, licences, owners, support, backups, renewal notice, access reviews, vendor reviews, replacement timing, data export, and secure disposal.

Evaluation matrix

Score value, risk, and fit together

Set weights before vendors present. Adjust them to the actual business case rather than copying this example unchanged.

CategoryExample weightEvidence to review
Functional fit25%Requirements test and user pilot
Security and privacy20%Controls, architecture, reports, contract, data flow
Total lifecycle cost20%Three-year or five-year model with assumptions
Integration and operations15%Technical proof, admin effort, monitoring, support
Vendor and service resilience10%Ownership, continuity, recovery, incident history, references
Exit and portability10%Export test, deletion terms, transition support, lock-in

A weighted score supports judgment; it does not replace it. A vendor that fails a mandatory security, legal, compatibility, or continuity requirement should not win because it scores well elsewhere.

Total cost

Build the cost model before comparing prices

Total lifecycle cost = acquisition + implementation + migration + integration + training + operations + support + growth + renewal + exit - credible savings.

  • Model every required licence, minimum seat count, add-on, and premium support tier.
  • Include internal staff time and external professional services.
  • State currency, tax, term, expected growth, renewal assumptions, and inflation assumptions.
  • Price backup, security, identity, device management, storage, logging, and compliance needs separately when they are not included.
  • Estimate the cost of downtime, failed migration, manual workarounds, and delayed adoption.
  • Include data export, contract termination, replacement, and secure disposal.

For Microsoft and Google licensing examples, compare our Google Workspace pricing guide and Office 2021 versus Microsoft 365 guide. They show why the sticker price alone is not the buying decision.

Supplier security

Questions every critical technology vendor should answer

  • What data and systems can the vendor, its staff, and its sub-processors access?
  • Where is data stored, processed, backed up, and supported from?
  • How are data and administrative connections encrypted and authenticated?
  • Does the service support multi-factor authentication, single sign-on, least privilege, and useful audit logs?
  • How are vulnerabilities received, prioritized, patched, disclosed, and communicated?
  • What incident notification timeline and cooperation obligations are written into the contract?
  • How are continuity, disaster recovery, backups, and restoration tested?
  • Can the business export all required data in a usable format, and how is remaining data deleted?
  • What happens if the vendor is acquired, changes hosting, removes a feature, raises prices, or ends the service?

The Canadian Centre for Cyber Security recommends knowing which vendors access data and support critical functions, maintaining a third-party inventory, classifying vendors by criticality, setting minimum security requirements, and re-evaluating suppliers regularly.

Hardware and software

Use the same governance, then change the evidence

Hardware procurement

Standardize the fleet

Check warranty, lifecycle, repairability, approved sellers, delivery, spares, device management, security features, compatibility, disposal, and the operational cost of supporting too many models.

See North Star's hardware procurement and setup service.

Software procurement

Map data and contract risk

Check licences, data flow, identity, integrations, backup, retention, privacy, accessibility, support, service levels, renewal, price protection, portability, deletion, and the effort to administer the platform.

See North Star's vendor management service.

Primary sources

Check the current vendor guidance

These sources provide risk-management guidance, not legal advice or a universal procurement policy. Adapt the process to your organization, contracts, data, and regulatory obligations.

FAQ

Questions Canadian teams ask

What is an IT procurement process?

An IT procurement process is the repeatable path used to define a need, evaluate options, assess security and vendor risk, compare full lifecycle cost, approve a purchase, deploy it, and manage renewal or retirement. It applies to hardware, software, cloud services, and outsourced technology.

Who should approve an IT purchase?

The business owner should approve the need and budget, IT should approve architecture, support, and security, privacy or legal reviewers should assess data and contract obligations when needed, and procurement or finance should confirm commercial terms. Higher-risk systems need more review than ordinary accessories.

How should a business compare software vendors?

Use weighted criteria tied to requirements. Score functional fit, security, identity integration, data location, privacy, implementation, support, resilience, exit options, contract terms, and total cost. A pilot with real users is more reliable than a sales demonstration.

What costs are often missed in IT procurement?

Common omissions include implementation, migration, training, integrations, premium support, backup, storage growth, identity add-ons, contract minimums, currency, taxes, renewal increases, device management, staff administration, and the cost to export or replace the system later.

What security questions should be in software procurement?

Ask how data is encrypted, where it is stored, which sub-processors receive it, whether MFA and single sign-on are supported, what logs are available, how vulnerabilities are handled, how quickly incidents are reported, how data is exported and deleted, and how service continuity is tested.

How often should vendors be reviewed?

Review critical vendors at least on a defined recurring schedule and whenever the service, ownership, data use, contract, integration, security posture, or business criticality changes. Renewal should be a decision point, not an automatic payment event.

Making a high-impact technology purchase?

North Star can translate the business need into requirements, compare vendors, model lifecycle cost, assess technical risk, and support implementation.

Review the PurchaseTalk to North Star