Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

How to reduce the risks and costs of projects: Top 10 IT procurement mistakes

IT Advocate: Use these legal guidelines when arranging IT purchasing deals to help your organization reduce the risks and costs of projects.

IT procurement does not always get the management and legal attention it deserves. Unlike other transactions, such as buying property or selling a business, IT procurement is often seen as an informal process -- notwithstanding that the spend is often significant and the IT being procured is also critical.

These are the IT procurement mistakes that I see frequently:

1. Signing the supplier’s contract

If you simply sign the supplier’s contract then you are likely to be accepting an “all care and no responsibility” style arrangement. It is likely that the deliverables and associated timeframes are unclear at best, and your ability to sue the supplier will be limited or nonexistent if the solution does not work, or if you get sued for infringing a third party’s intellectual property rights.

It is preferable to include your own terms and conditions in your RFP or, if this is not possible, negotiate the supplier’s contract to reflect an acceptable position.

2. Downselecting

It is important not to let a supplier know they have been selected until the terms under which they are to supply the solution have been agreed. Once a supplier knows they have the job they do not tend to be very willing negotiators.

One way to maintain the competitive tension is to start with three or more candidates, select two and negotiate two binding agreements before making a decision. At each stage of the process you should emphasise to the suppliers that the position they take with respect to the terms may determine whether or not they are going to progress to the next round of negotiations.

3. Specifying what is being provided

Most supplier contracts are deliberately vague about what is to be delivered. Ideally, if software is provided then the functionality of that software should be clearly set out in a schedule. Similarly, services being provided should also be clearly described as failure to do so would invariably result in everything being an “additional service” for additional fees! In the case of ongoing services, specific service levels should be included with respect to aspects of the services that are both important and measurable.

You may wish to consider including a service credit or rebate concept both to drive supplier behaviour and have relatively easy access to compensation if the services are not provided in accordance with the agreement.

4. Timeframes

Ideally your agreement would include a clear project plan with milestones which the supplier would be required to meet. Suppliers are usually reluctant to do this and the excuse most often proffered is that timeframes are dependent on the customer doing its part. It may then be appropriate to have a schedule devoted to the tasks to be performed by the customer, and excuse the supplier for delays if it notifies the customer of a failure to perform a particular customer task and the consequences of doing so.

5. Right to walk away

At a minimum you should try and obtain a right to perform acceptance testing of the solution and a refund if the solution does not work. Suppliers tend to get distressed when you request this, but it provides a practical remedy in circumstances in which a solution may not otherwise be available.

The alternative is to be stuck with a solution that does not work with the option of suing for damages if you have managed to negotiate appropriate warranties and obligations.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: procurement, legal, IT advocate
Latest Blog Posts
Whitepapers
  • Is your data center ready for virtualisation? Important power considerations for virtualised IT environments
    Virtualisation brings the potential to deliver dramatic savings in terms of server count, footprint, power consumption and cooling requirements for data centers. For all its advantages though, virtualisation also brings some unique challenges. The power and cooling infrastructure—which may have been quite sufficient for pre-virtualization needs—could easily become inadequate when data center performance patterns are radically altered. The good news is that there are practical and affordable ways to address these challenges and improve data center efficiency in the process. This paper looks at some of the power-related challenges and the readily available technologies to address them.
    Learn more »
  • FTP Replacement: Where MFT Makes Sense and Why You Should Care
    This research provides advice on when to replace FTP with managed file transfer (MFT) solutions, and which features to consider. This Gartner report includes MFT software and MFT as a service. Also highlighted is where MFT fits into the technology landscape and some of the key benefits. Key Findings include: - Technical differences between FTP and MFT including security, administration and scalability - Implementation concerns that organisations should be aware of (when migrating) - List of vendors and how they are expanding their MFT porfolios (including IBM)
    Learn more »
  • Lost USB keys have 66% chance of malware
    Sophos studied 50 USB keys bought at RailCorp's 2011 Lost Property auction in Sydney. The study revealed that two-thirds were infected by malware, and quickly uncovered information about many of the former owners of the devices, their family, friends and colleagues. Disturbingly, none of the owners had used any sort of encryption to secure their files against unauthorised snoopers.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.

HP and IDG news, product videos and resources