The Procurement Decision you cannot explain is already an Audit Finding
There is a moment every public sector procurement leader knows. An auditor’s letter arrives, a freedom of information request is filed, or a parliamentary committee schedules a hearing. And the question that follows is always the same: can you show us why you made that decision?
In some organisations, the honest answer is no. Their decisions are defensible and well-intentioned. The issue emerges when the justification exists only in someone’s memory, or in an email thread no one can find, or in a document that was never formally logged. The audit exposure was not created at the moment of the finding. It was created at the moment the decision was made without adequate documentation.
£434bn
UK public sector procurement spend 2024/25
House of Commons Library, 2025
£55–81bn
Estimated fraud & error losses to the public purse, 2023/24
NAO, 2024
50%
Of audited public bodies had inadequate audit trails for COI
Govt Internal Audit Agency, 2024
13%
Of GDP that public procurement represents across OECD member countries
OECD, 2026
The Scale of the Problem
The UK’s National Audit Office is unsparing in its assessments. A November 2024 report on conflicts of interest management found that across the Government Internal Audit Agency’s reviews of at least 20 public bodies since 2019, inadequate audit trails limited the assurance it could provide in half of them. Those are not isolated failures. They represent a systemic pattern in which the absence of documentation is the norm rather than the exception.
The financial stakes are significant. The NAO estimates that fraud and error caused losses of between £55 billion and £81 billion to the public purse in 2023/24 alone. Not all of that flows from documentation failures, but weak audit trails make it significantly harder to detect and address. As the OECD’s Anti-Corruption and Integrity Outlook 2026 notes, public procurement remains the government activity most exposed to integrity risk, and digital tools for proactive risk management have considerable potential but remain underused across member countries.
Procurement Audit Readiness — Key Compliance Gaps Identified Across UK Public Bodies
Source: NAO reviews, Government Internal Audit Agency findings, and OECD Integrity Outlook 2026
Why Documentation Fails
The problem is not dishonesty. Most procurement professionals are trying to do the right thing under significant time and resource pressure. The problem is structural. Documentation requirements are treated as administrative burdens to be completed after the fact, rather than as a natural output of good decision-making. Approvals happen over email. Justifications are verbal. Supplier communications are held in personal inboxes. And by the time an auditor asks, the connective tissue of the decision has dissolved.
The EU’s parallel experience reinforces this. The European Commission launched a formal evaluation of all three major EU procurement directives in December 2024, with details of new Public Procurement regulations being trailed publicly. Poor documentation is not a uniquely British problem. It is a structural weakness in public procurement systems globally, particularly where digital tools have not been embedded into the transactional process.
The audit finding is not the problem. It is the symptom. The problem is a procurement process that separates decision-making from documentation — and by the time anyone looks, the two can no longer be reconnected.
— Analysis informed by NAO Commercial Lifecycle guidance, February 2025
What Good Looks Like
Organisations that withstand audit scrutiny well share a common characteristic: they treat documentation as a live process, not a retrospective one. Supplier evaluation scores are recorded as they are assigned. Waiver justifications are captured in the system that approved them. Approval chains are visible in real time. There is no scramble at the end because nothing was left undone at the beginning.
The NAO’s February 2025 guidance on managing the commercial lifecycle, which was updated specifically in response to the Procurement Act 2023 and informed by over 200 reports covering more than 300 commercial arrangements, is explicit on this point.
Auditability is not a back-office capability. It is a core operational requirement, and it must be embedded into the procurement process from the first decision to the final contract management action.
AI & Technology – A Grounded Perspective
What AI can do – and what it cannot do
AI-assisted procurement platforms can help by making documentation the path of least resistance. When a system captures approval decisions, flags expired certifications in real time, or generates automatic records of supplier communications, the audit trail becomes a by-product of the procurement process itself rather than a separate compliance task. The IIA’s December 2025 Global Practice Guide on auditing procurement in the public sector notes that big data analytics and intelligent automation have meaningfully enhanced fraud detection and operational efficiency where they have been properly implemented. The OECD identifies AI-driven anomaly detection, real-time compliance monitoring, and intelligent audit logging as among the highest-value applications of AI in public procurement as they can reduce the gap between what happened and what can be proved to have happened.
The Critical Limit
AI does not fix a broken governance culture. If an organisation routinely bypasses approvals, makes decisions outside the system, or lacks the leadership commitment to enforce documentation requirements, AI will scale and record that dysfunction more efficiently. It will not address or correct behavioural failings. The precondition for AI to add genuine value is a governance framework worth supporting. Technology is infrastructure. It is not leadership, and it cannot substitute for it.
The Procurement Act Changes the Calculus
For UK public sector organisations, the Procurement Act 2023 has materially raised the stakes. Contracting authorities are now required to keep records of material decisions and supplier communications for a minimum of three years. New transparency obligations make procurement decisions more readily scrutinised by suppliers, civil society, and parliamentarians. The Act’s provisions around conflicts of interest place a new burden of proof on contracting authorities to demonstrate that their processes were not only compliant but visibly so.
The OECD found in 2024 that the UK met just 36% of its criteria for best-practice conflicts of interest management, against an OECD average of 76%. On implementation, the UK reached just over 20%, against an OECD average of 40%. The Act provides the legislative impetus for change. What remains is the organisational will to build processes in which accountability is structural rather than aspirational, transferring the question from ‘can we find the justification?’ to ‘was the justification ever in doubt?’.
5 Recommendations for Procurement Leaders
1. Treat the audit trail as a process output, not a compliance add-on.
Every material decision, be it waiver approvals, supplier selections, conflict-of-interest declarations, should be captured at the point it is made, inside the system that made it. If your process requires a separate documentation step after the event, the risk has already been created.
2. Map your current exposure against your existing legislation now.
Record-keeping obligation and transparency duties exist. Identify which procurement activities still rely on email approvals, verbal sign-offs, or manual records. Those are your audit liabilities. Prioritise closing them before a scrutiny event forces the issue.
3. Use AI as audit infrastructure — not as a reporting tool.
The value of AI in this context is not generating compliance reports after the fact. It is embedding documentation into the transactional flow so that the audit trail is a live, continuous by-product of every procurement action. Anomaly detection, real-time certification checking, and automated approval logging all shift the organisation from reactive to defensible. That is the right frame for the technology investment conversation.
4. Address governance culture before deploying technology.
The NAO’s finding that half of audited public bodies had inadequate audit trails is not a technology finding. It is a leadership finding. AI platforms accelerate and scale whatever behaviour exists beneath them. Before investing in procurement technology, be clear that the organisation’s approval disciplines, conflict-of-interest protocols, and documentation expectations are actively enforced versus aspirational.
5. Benchmark against OECD best practice, not just domestic compliance.
The UK meets just 36% of OECD criteria for best-practice conflicts of interest management. Procurement Act compliance is the floor, not the ceiling. Organisations that want to be genuinely audit-ready, being able to demonstrate it credibly to parliamentary scrutiny, suppliers, and the public, should use the OECD framework as the standard they are building towards.
Key Takeaways
- Audit exposure in public sector procurement is almost always a process failure, not a compliance failure. The gap between good decision-making and defensible decision-making is documentation, which is captured in real time, inside the system, at the moment of the decision.
- The UK Procurement Act 2023 materially raised the evidential bar. Three-year record-keeping obligations, transparency requirements, and strengthened conflict-of-interest provisions mean that organisations that have not yet built documentation into their procurement process are accumulating legal exposure with every transaction.
- The NAO’s finding that half of audited public bodies have inadequate audit trails reflects a systemic gap that legislation alone cannot close. The OECD’s data shows the UK lagging significantly behind international peers on conflicts of interest management. Both point to the same conclusion: this requires leadership action, not just policy compliance.
- AI has a genuine and specific role here as audit infrastructure. When procurement platforms capture approvals, flag anomalies, and log communications automatically, the audit trail becomes a continuous by-product of the process rather than a retrospective reconstruction. That is where the technology investment is defensible and durable.
- The right question for any public sector procurement team to ask is not ‘are we compliant?’ but ‘if an auditor asked us to explain every significant decision we made in the last three years, could we do it today, without a search?’ If the answer is no, the work starts now.
Talk to a procurement expert.
Tell us your challenge. We will show you exactly where JAGGAER One fits into your current setup — with specifics, not a generic demo.
- Direct or indirect?
We handle both — on one platform. - Already have an ERP?
JAGGAER Link connects to 1,000+ systems, no rip-and-replace. - Need to show ROI fast?
We define outcomes and KPIs before you sign. - Vertical-specific?
Manufacturing, higher ed, public sector — configured, not customized.



