What a Procurement Probity Audit Should Test
A procurement probity audit is often commissioned after a concern has been raised: an unsuccessful tenderer seeks a debrief, a delegate questions the recommendation, or a project team cannot explain why a procurement rule was bypassed. By that point, the organisation is not simply checking process. It is testing whether a significant expenditure decision can withstand scrutiny from executives, auditors, regulators, funding bodies, bidders and, potentially, a court or tribunal. At Contract Control International (CCI), procurement probity audits sit alongside our tenders and probity consulting work, because the same discipline that protects a tender process also protects the audit that follows it.
For construction, infrastructure, engineering and major services procurements, probity is not a ceremonial layer placed over commercial decision-making. It is a practical control over how the market is approached, how information is handled, how tenders are evaluated and how the final decision is recorded. A sound audit identifies weaknesses early enough to correct them. A late audit may instead need to determine the consequences of a flawed process and the least damaging path forward.
What probity means in a procurement setting
Probity requires the procurement process to be fair, impartial, transparent and defensible. Those principles must be visible in the procurement records, not merely asserted after the event. The project team needs to show that suppliers had materially equivalent access to relevant information, evaluators applied the published criteria, conflicts were identified and managed, and the preferred tenderer was selected under the approved decision-making framework.
This does not mean every procurement must follow the same lengthy tender process. A low-value supply purchase, an emergency works package and a complex design and construct procurement call for different controls. The issue is whether the process chosen was proportionate to the value, risk, market conditions and applicable policy requirements, and whether departures were authorised and documented.
Commercial judgement remains necessary. A tender assessment panel can prefer a higher-priced bid where that bidder offers lower delivery risk, stronger methodology or a better whole-of-life outcome, provided those matters were within the stated evaluation approach and the reasoning is recorded. Probity does not prevent good commercial decisions. It makes them capable of being explained.
What a procurement probity audit should examine
An effective procurement probity audit follows the transaction from front-end preparation through to award. It should not be confined to checking whether forms are present in a file. The key question is whether the documents, communications and approvals tell a consistent and credible story.
Procurement strategy and authority
The audit should first establish why the procurement was undertaken in the chosen manner. This includes the approved procurement plan, sourcing strategy, budget authority, market approach, tender timetable and delegated authorities. If a limited tender, direct negotiation or extension of an existing contract was used, the business rationale and approval route require particular attention.
A recurring weakness is the mismatch between the approved strategy and the process actually followed. For example, the plan may nominate weighted non-price criteria and a two-stage evaluation, while the team later conducts informal clarification meetings that materially alter the basis of comparison. Changes may be justified, but they need formal consideration, authority and communication to affected tenderers where appropriate.
Tender documentation and market communications
The request for tender, conditions of tendering, scope, pricing schedules and evaluation criteria should work together. Ambiguous scopes and incomplete pricing schedules create more than an estimating problem. They create an environment in which tenderers make different assumptions and evaluators later compensate for those differences through subjective judgement.
The audit should review how questions, addenda, site briefings, tenderer interviews and clarifications were controlled. Information that could affect price, scope, risk allocation or the prospect of success should not be selectively provided to one bidder unless the process clearly permits it and equivalent treatment is managed. A complete tender communication register is usually far more persuasive than recollection months later.
Conflicts, confidentiality and evaluator conduct
Conflicts of interest are not limited to direct financial interests. Previous employment, personal relationships, current project dealings, prior advice on the requirement and access to commercially sensitive information can all create actual, potential or perceived conflicts. The appropriate response depends on the circumstances. It may involve disclosure, a management plan, restriction from parts of the evaluation, replacement of an evaluator or, in serious cases, exclusion from the process.
Confidentiality controls matter equally. Bid information must be restricted to people with a genuine role in the procurement. Evaluation papers should be stored securely, version-controlled and retained in accordance with organisational requirements. Casual forwarding of tender submissions, undocumented conversations with bidders and unprotected working spreadsheets are common sources of avoidable risk.
Evaluation evidence and moderation
The audit should test whether each evaluator’s assessment can be traced to the tender response and the published criteria. Scoring sheets should contain reasons, not only numbers. A score of two rather than four is of limited value if no one can identify the evidence relied on or the deficiency found.
Moderation is often where a process becomes vulnerable. Panel discussion is necessary, particularly for complex construction and services tenders, but it must not turn into a retrospective rewriting of criteria. The moderator should be able to explain how individual assessments were considered, why agreed scores changed and whether evaluators had access to the same information.
The following records are commonly central to an audit finding:
- approved procurement and evaluation plans;
- conflict and confidentiality declarations, including management actions;
- tender issue records, addenda, question-and-answer registers and briefing notes;
- individual scoring sheets, moderation records and clarification correspondence;
- financial evaluations, reference checks, risk assessments and due diligence material; and
- the recommendation report, approval records, notices and contract award documentation.
A complete file does not automatically prove a fair process. Conversely, an incomplete file does not always mean the decision was wrong. However, poor records make it difficult to demonstrate that the decision was properly made, particularly once personnel have moved on or a challenge has emerged.
Timing changes the value of the audit
A pre-release probity review is usually the most cost-effective point of intervention. It can test whether criteria are measurable, tender conditions are fit for purpose, evaluation roles are clear and anticipated conflicts have been addressed. It is particularly valuable where the procurement involves high value, contested markets, government funding, complex interfaces or a long-term commercial relationship.
An audit during the tender process has a different purpose. It may focus on live risks such as inconsistent tenderer communications, late changes to scope, evaluator availability, undeclared conflicts or an emerging need to alter the procurement approach. The reviewer must preserve independence while giving the team practical guidance that does not become involvement in the decision itself.
A post-evaluation review is often appropriate before a recommendation proceeds to approval. At this stage, the audit tests whether the recommendation is supported by the evidence, whether any departures have been dealt with and whether the report accurately presents the commercial, technical and probity basis for award. This is not an opportunity to manufacture a better paper trail. It is an opportunity to identify genuine gaps and decide whether they can be properly remedied.
Where a complaint, audit query or dispute has already arisen, the work becomes more forensic. The reviewer should preserve relevant records, map the chronology, distinguish facts from assumptions and avoid informal attempts to reconstruct events. Legal advice may also be required, especially where litigation, statutory review obligations, fraud concerns or a threatened injunction are in prospect.
Independence must be practical, not performative
An internal audit team may be well placed to understand organisational policy and systems. An external probity adviser may bring greater independence, specialist procurement experience and credibility where the project is politically sensitive or likely to be challenged. Neither option is automatically superior.
The critical issue is the reviewer’s mandate and separation from the procurement decision. A person who drafted the tender documents, coached evaluators on preferred outcomes or participated in negotiations should not later provide an independent assurance opinion on those same actions. The scope should clearly state what is being reviewed, the applicable standards, the evidence required, the reporting line and how findings will be managed.
For major projects, a useful model is to establish probity controls at the start, conduct targeted reviews at critical gates and retain a clear record of advice, management responses and decisions. This is more effective than commissioning a broad review after contract award, when remedial options are usually narrower and more expensive.
Turning findings into stronger procurement controls
Audit findings should lead to specific operational improvements rather than generic reminders to "follow policy". If evaluators provided weak reasons for scores, the response may be better evaluation templates, chair training and earlier moderation protocols. If scope changes were poorly communicated, the organisation may need a formal variation-to-tender process with approval thresholds and bidder notification rules.
Training is particularly valuable when it is built around the organisation’s own tender conditions, delegation instruments, scoring tools and recent procurement issues. Procurement personnel, technical evaluators and project leaders need a shared understanding of their respective roles. The commercial team may understand tender conditions well, while subject matter experts may need support in recording evidence and avoiding undisclosed bidder contact. Both perspectives are necessary for a defensible outcome.
CCI's practical contract and procurement capability development work can assist your team to connect front-end preparation with the downstream realities of administration, claims and dispute risk. The best procurement controls are designed by people who understand what ambiguous scopes, weak records and poorly allocated risks can cost once work is underway.
A procurement file should allow an informed person, with no prior involvement, to understand what was bought, why the chosen process was used, how bidders were treated and why the selected supplier represented the approved outcome. If the file cannot do that, the audit has identified work worth doing before the next decision is tested under pressure.
Need a probity review before, during or after a procurement? Talk to CCI about a tenders and probity audit, or build this capability in-house through our training courses.
Comments