The Modern Software Procurement Process (2026 Guide)


The textbook software procurement process is straightforward. A team identifies a need, evaluates options, negotiates a contract, and rolls out the tool. Yet, there are a few variables at play that require adjustments to that process in 2026 and beyond.
Departments and employees have been purchasing software outside of central procurement for years. In the average organization, IT owns just 13% of the applications in the portfolio. The other 87% are owned by lines of business and individual employees, purchased outside a central IT or procurement flow, according to Zylo's 2026 SaaS Management Index.

What's changed in 2026 is the pressure on the process: shadow AI is spreading at laser speed, consumption-based pricing is variable and harder to predict, and vendors are revising pricing more often than annual planning can absorb.
This guide covers both sides of that reality: the canonical eight-step procurement process, and how to handle the software already moving through your organization without it.
Why Most Software Is Bought Outside the Procurement Process
Most enterprise software gets bought the moment someone needs it, without waiting for Procurement’s approval. When a request can take weeks to work through, employees go around it and buy the tool themselves.
New software enters your business through:
- Credit card subscriptions expensed by individual employees
- Departmental tools bought directly by marketing, sales, or engineering
- AI tools a single team adopts ahead of any policy
- Renewals that auto-execute before anyone reviews them
The scale of shadow IT is easy to underestimate. Expensed software alone accounts for 45% of applications while making up only 4% of total spend, according to Zylo's 2026 SaaS Management Index. These are the low-dollar, high-count purchases that move too fast and are too small for anyone to catch on the way in. Speed and autonomy are winning over governance, one purchase at a time. You can read more on how these decentralized software purchasing channels take shape and how to bring them back under management.
In 2025, the top most-expensed software included ChatGPT, Apple iCloud, Canva, Quickbooks, and OpenAI API.
What Is Software Procurement?
Software procurement is the end-to-end process of identifying, evaluating, purchasing, and managing the software an organization needs. It spans requirements gathering, vendor research, security and financial review, negotiation, contracting, implementation, and renewal. It typically involves IT, procurement, finance, security, and the end users who requested the tool.
The stakeholders haven't changed much, but the ownership has. Software procurement used to be IT-led and centralized. Today it's cross-functional and distributed, with procurement, finance, security, and business owners each holding a piece of the decision, which is why a shared set of IT procurement best practices matters more than it used to. The shift toward procurement and SaaS management as a single discipline keeps distributed buying from turning into uncontrolled sprawl.
The 8 Steps of the Software Procurement Process
The software procurement process runs through eight steps, from first defining the need to managing the tool long after it's live. Each step has a clear owner, a common failure point, and a 2026 wrinkle that older playbooks don't account for.

1. Identify Needs and Document Requirements
Requirements definition is the cross-functional work of specifying what problem the software has to solve before you look at a single vendor. Get this wrong, and every later step inherits the error.
The most common mistake is skipping the requirements document entirely, or letting one team define needs for the whole organization. Teams also conflate what they want with what they need, which inflates scope and cost.
Build a requirements template that captures functional, technical, and compliance needs in one place, so every evaluator scores vendors against the same criteria. In 2026, add one more path: procurement increasingly starts after discovery surfaces a tool a team already bought. When that happens, you're documenting requirements for a purchase that's already live, not a hypothetical one.
2. Research the Market and Identify Vendors
Market research is the step where you build a vendor candidate list from analyst coverage, peer references, and hands-on trials. The goal is a shortlist grounded in how the tool performs in your own environment.
Relying only on Gartner, G2, or Forrester quadrants without operator validation is the usual misstep. Analyst coverage tells you who the established players are, not how a tool behaves in your stack.
Balance analyst sources with peer references and free-trial validation before you commit. This becomes more important every year, because the analyst view is slow to catch new categories. AI tooling and agentic software often move faster than the quadrants, so supplement formal research with practitioner communities and people running the tools now.
3. Run the RFP and Shortlist
An RFP is a structured request that lets you compare vendors against consistent criteria and narrow the field to two or three finalists. Done well, it forces vendors to answer your questions instead of pitching their strengths.
Common mistakes include writing a bloated RFP that buries the decision or scoring responses without a defined rubric. Both let the loudest vendor win instead of the best fit.
Keep the RFP tight and tie every question to a requirement. In 2026, know when to compress or skip it. A full RFP cycle can take longer than an AI tool's useful evaluation window, so for time-sensitive AI purchases, a structured trial with clear exit criteria often beats a formal RFP.
4. Evaluate, Review Security, and Align Stakeholders
After the RFP, the next step of the software procurement process is evaluation, security review, and stakeholder alignment. This cross-functional stage scores a shortlisted vendor, vets it for risk, and confirms alignment with everyone who owns part of the decision.
- Evaluation: scoring each finalist against your functional, technical, and cost requirements.
- Security review: assessing data handling, access controls, compliance posture, and, for AI tools, model and training-data risk.
- Stakeholder alignment: confirming IT, security, finance, and the business owner agree before anyone signs.
One common mistake is bringing security and finance in too late, after the business has committed to a vendor. The review was run without a scorecard, which makes the choice feel subjective and easy to relitigate.
Build a weighted scorecard with category-specific criteria so each stakeholder scores what they own. AI purchases need their own criteria: model security, training-data handling, data residency, and AI governance alignment. Consumption-priced tools add one more, since you have to forecast a variable cost before you sign, so the tradeoffs between usage-based pricing and subscription models belong in the scorecard rather than on next quarter's bill.
5. Negotiate and Contract
Negotiation is where pricing, terms, and protections get locked in, and where accurate usage data becomes leverage for rightsizing licenses. Walk in with utilization numbers and benchmarks, and you negotiate from evidence instead of the vendor's assumptions.
Common mistakes include negotiating without data and accepting the first paper the vendor sends. Both hand the vendor control of the terms.
Anchor the conversation in what you use and what comparable organizations pay. Modern deals bring new levers to watch: hybrid pricing, AI features bundled into existing licenses, and mandatory adoption clauses. Contracting is where those wins get locked in, so get the negotiated pricing, terms, and protections into signed paper before the deal loses momentum. A clear view of what to review in every SaaS contract keeps auto-renewals, true-up terms, and notification windows from becoming next year's problem.
6. Approve and Purchase
Approval routes the negotiated contract through final sign-off and executes the purchase. It exists to add a last checkpoint, not to stall the deal.
The mistake that does the most damage is an approval workflow so slow that stakeholders bypass it. Every bottleneck here directly feeds shadow IT, because a team that waits eight weeks for a yes will find a workaround.
Set a tiered approval workflow based on deal size and risk profile. A $2,000 team tool and a $100,000 enterprise contract shouldn't move through the same gauntlet. Match the scrutiny to the stakes, and people stop routing around you.
7. Implement and Roll Out
The implementation phase covers deployment, integration, testing, user acceptance, and training. When all those pieces are in place, implementation can help drive adoption from the get-go.
Common failures include rolling out a tool with no communication or onboarding plan for the switch, underinvestment in training, and no defined success metric for go-live. Without a target, no one can say whether the rollout worked.
Define adoption metrics in the contract, so the vendor is accountable to the same outcome you are. Name an owner, set a check-in cadence, and treat low early adoption as a signal to intervene rather than a number to explain away later.
8. Manage and Review Renewals
Renewal management is about optimizing costs and ensuring renewals align with your current needs and budget. On average, 87% of SaaS spend goes toward renewals, per Zylo's 2026 SaaS Management Index. Because most of your spend is tied up in existing software, you need to make sure you’re making the most of what you have.
Treat every renewal as a fresh procurement decision, backed by utilization data, a current pricing benchmark, and an understanding of alternative vendors. A phased SaaS renewal process with milestones at 120, 90, 60, and 30 days ahead of renewal gives your team room to prepare instead of reacting.
Procuring AI Software Is Different
AI software procurement differs from traditional software procurement in five ways: pricing is variable, security review expands to cover model and training-data risk, evaluation now includes consumption forecasting, vendors bundle AI into existing licenses, and employees adopt AI tools faster than any review can track. Each one changes how you buy.
Consumption Pricing Makes Cost Variable
Consumption pricing charges per token or per action, so cost moves with usage instead of sitting fixed on a contract. That variability can quietly outrun a budget. Model the range before you sign, and negotiate guardrails like overage alerts and spend caps. The mechanics of consumption-based pricing are worth understanding in full before you commit.
Model and Data Risk Reshape the Security Review
AI tools add risks a standard security review doesn't cover: model security, data residency, agentic behavior, and how the vendor uses your data for training. Assess each against AI governance standards like the NIST AI Risk Management Framework. Regulation is catching up too, with the EU AI Act's enforcement provisions arriving in 2026, so compliance is a present concern rather than a future one.
Consumption Forecasting Becomes Part of Evaluation
With variable pricing, you can't evaluate an AI tool on features alone. You have to forecast what it will cost across realistic usage. Skipping that step is how teams get surprised: 78% of IT leaders hit unexpected charges tied to consumption or AI pricing in the past year, according to Zylo's survey. Build the forecast into the scorecard so cost is part of the decision, not an after-the-fact discovery.
Mandatory AI Bundling
Vendors increasingly fold AI features into existing licenses and raise the price, whether or not you asked for them. Treat bundled AI as a negotiation point: ask what's included, what it costs, and whether you can opt out or defer adoption.
Shadow AI
Shadow AI is the AI-era version of shadow IT, where individual employees and teams adopt AI tools with no review at all. The same discovery that surfaces shadow SaaS is what catches shadow AI before it shows up on the bill or in a compliance gap.
Software Procurement Best Practices
The best software procurement practices in 2026 assume decentralized buying instead of fighting it. They make the sanctioned path faster than the workaround, and treat visibility as the foundation everything else sits on.
Seven practices do the heavy lifting:
- Start with discovery, not requirements
- Build intake faster than the workarounds
- Tier approval workflows by deal size and risk
- Standardize on two to three vendors per category
- Require security and finance sign-off on consumption contracts
- Maintain a procurement-policy-as-code stance
- Treat every renewal as a fresh procurement decision
Start with Discovery, Not Requirements
Discovery comes first because most enterprises already know what software came through the formal procurement process, but not the rest. Before you define new needs, find what's already in flight through financial feeds, SSO logs, and expense data. You'll almost always find redundant tools you can consolidate before spending a dollar on anything new.
Build Intake Faster Than the Workarounds
Slow procurement is the single biggest driver of shadow IT. If your intake form takes eight weeks to produce a yes or no, business units will go around it. Publish a clear intake policy backed by a pre-approved application catalog, so teams can self-serve approved tools and only route genuine exceptions to you.
Tier Approval Workflows by Deal Size and Risk
One process for every purchase guarantees friction where it isn't needed. Tier the workflow so low-dollar, low-risk tools clear quickly while large or sensitive contracts get full review. The point is to reserve your scrutiny for the deals that warrant it.
Standardize on Two to Three Vendors per Category
One part of Procurement's job is to prevent redundant purchases. Standardizing the tools. Define two or three preferred vendors per category and consolidate toward them. When Adobe rationalized its portfolio with Zylo, it started with more than 2,600 discovered titles to roughly 400 standardized applications. The team unlocked about $60M in savings and cost avoidance, per Zylo's case study.
Require Security and Finance Sign-Off on Consumption Contracts
Variable-cost contracts need modeling before signature. Require finance to forecast the spend and security to review model risk on any consumption-based or AI purchase. Doing so prevents budget surprises that consumption pricing is notorious for.
Maintain a Procurement-Policy-as-Code Stance
Codify your exception rules, dollar thresholds, and approval routing so business units understand the rules without asking Procurement every time. When the policy is explicit and self-service, compliance improves, and your team stops asking your help desk for routine questions.
Treat Every Renewal as a Fresh Procurement Decision
Run a defined review cadence with milestones at 120, 90, 60, and 30 days before the renewal date. Each stage carries its own focus: confirm the application owner and stakeholders, review utilization and license data, assess business value and overlap, then benchmark pricing and negotiate. Organizations that prepare this early consistently negotiate better terms than those scrambling in the final weeks. You can dig deeper into these procurement management practices and how they hold up as your portfolio grows.
Common Challenges in Software Procurement (And How to Overcome Them)
The hardest software procurement challenges in 2026 come from decentralized purchasing, variable pricing, and AI sprawl. They share a root cause: limited visibility into what you own and what it costs. Solve for visibility first, and most of these become manageable.
- Shadow IT and credit-card SaaS. Expensed software is a high-count, low-dollar problem that's easy to ignore and expensive to leave alone. Catch it with automated discovery, then consolidate expensed instances into managed contracts.
- Decentralized buying authority. When every department thinks it owns procurement, redundancy multiplies. A shared system of record and clear category ownership put everyone on the same map.
- AI tool sprawl and shadow AI. Individual teams adopt AI tools faster than any review can keep up. Fold AI purchases into the same discovery and intake process you use for SaaS.
- Consumption-pricing budget surprises. Variable costs are hard to forecast and can obliterate your original budget, sometimes overnight. Model the range and negotiate overage alerts before signing.
- Cross-functional coordination. IT, Procurement, Finance, Security, and business owners each hold part of the decision. Aligned KPIs and shared visibility keep them from working at cross purposes.
- Renewal-cliff visibility. Not knowing what renews when, and at what cost, forces reactive decisions. A renewal calendar with early milestones turns surprises into planned negotiations.
- Velocity mismatch. Procurement often moves slower than the SaaS and AI market it's trying to govern. Tiered workflows and self-service catalogs close the gap without giving up control.
What to Look for in Software Procurement Tools
The right software procurement tool earns its place by surfacing software you don't know about and giving IT, procurement, and finance one shared view. Evaluate any platform against six criteria:
- Discovery breadth: does it surface unknown software through financial feeds, SSO, expense reports, and browser signals, or only track what you already entered?
- SaaS-specific functionality: license tracking, renewal calendars, and real utilization data, not just a vendor list.
- Consumption and AI cost visibility: can it track token-based and usage-based spend alongside fixed subscriptions?
- Integration depth: does it connect to your ERP, expense management, SSO, and contract repository?
- Workflow automation: intake, approval routing, and renewal alerts that run without manual chasing.
- Stakeholder fit: is it built for procurement, IT, or finance, or does it serve all three from one system of record?
No single platform wins every category, so match the tool to the gap that's costing you most. Here are a few examples:
- Coupa: broad enterprise spend and procure-to-pay
- Ramp: corporate cards and expense
- Zylo: SaaS-specific procurement and renewal management, plus consumption and AI cost visibility
Modernize Your Software Procurement Process
A software procurement framework gives you a repeatable process for buying and managing software, but the process only works if you can see what's flowing through it. In 2026, that means pairing the eight steps with visibility into shadow purchases and modern spend models. You can run every step perfectly and still lose control of your portfolio when most of your software never enters the process in the first place.
Zylo gives you the visibility needed to modernize your procurement process, manage SaaS spend, and forecast AI consumption costs. To learn how, set up time with our team.
Frequently Asked Questions About the Software Procurement Process
A software procurement process is the structured set of steps an organization follows to identify, evaluate, buy, and manage software. It typically spans requirements, vendor research, evaluation and security review, negotiation, approval, implementation, and renewal, and it involves IT, procurement, finance, security, and end users.
Software procurement has eight core steps: identify needs and document requirements, research the market and identify vendors, run the RFP and shortlist, evaluate and review security, negotiate and contract, approve and purchase, implement and roll out, and manage and review renewals. The last step repeats at every renewal.
Software procurement timelines vary widely with deal size, risk, and the number of stakeholders involved. A low-cost, low-risk team tool can clear a tiered workflow in days. A large enterprise contract that triggers security, legal, and finance review takes much longer, because each added reviewer adds calendar time. The more approvals a purchase requires, the longer it runs, so slow processes push buyers toward workarounds.
Traditional procurement handles discrete, planned purchases like a new ERP system, a hardware refresh, or a perpetual software license. All routed through a centralized flow by Procurement. In contrast, SaaS procurement is specifically focused on the procurement of cloud software and AI tools. Teams and individuals across the organization do the buying, while Procurement takes a strategic role to support decision making and prevent unnecessary purchases.
Software procurement is a shared responsibility. IT owns application strategy, access, and security. Procurement owns contracts, vendor relationships, and negotiation. Finance owns spend visibility and forecasting. Ownership should be distributed but coordinated, with shared visibility and aligned KPIs, since no single function sees the full picture.
AI software procurement adds evaluation criteria that traditional procurement doesn't cover: model security, training-data handling, data residency, and consumption-pricing forecasts. Because many AI tools charge per token or per action, cost is variable and harder to budget, which is why so many teams hit unexpected AI charges.
To procure software that's already in use, start with discovery instead of requirements. Use financial data, SSO logs, and expense reports to surface every active tool, then bring each one under management retroactively by assigning an owner, reviewing security and utilization, and consolidating it into a managed contract.
Common software procurement mistakes include skipping the requirements document, bringing security and finance in too late, running one heavy process for every deal size, letting approval bottlenecks fuel shadow IT, and starting renewal prep too late to negotiate. Each one either slows the process or pushes buyers around it.










