Skip to content

Procurement pack

A procurement pack is the set of documents a supplier hands a buyer's legal, security, data protection and purchasing functions so each can complete its review: the processing agreement, sub-processor list, security evidence, records of processing, insurance, terms and a plain description of what is being bought. Its quality decides how long procurement takes.

Every controller and processor must keep a record of its processing, and the pack is where that record meets the buyer's own.

Why it matters when the plan changes

Four reviewers with four checklists will each ask the supplier for documents, and each document they have to request is a week added to the cycle. A pack that anticipates the questions turns a review into a reading exercise rather than a correspondence, and the effort per review falls the same way effort per delivery falls when repeatable work is prepared once rather than assembled on demand. A pack built after the request arrives makes the supplier's responsiveness, not its practice, the thing being evaluated.

The tension is between completeness and honesty. A pack can be made to look complete by describing intentions as though they were capabilities, and security evidence in particular must show measures appropriate to the risk, not measures planned for it. Reviewers sample, and a single overstated document discredits the rest. A shorter pack that states its limits is a better pack than a thicker one that has to be corrected later.

In practice

A buyer's data protection officer, security lead and procurement manager each email the supplier for documents over three weeks. Half the requests overlap. The supplier sends different versions of the sub-processor list to two of them. The review takes a quarter and ends with a request for a reconciled set, which is what a pack would have been.

Evidence

What it cannot tell you

A procurement pack shows what a supplier documents about itself; it does not verify that practice matches the document, or that controls remain in place after the review closes. It says nothing about how the buyer's own processing will interact with the service, and a complete pack is not evidence that the relationship will be well managed once signed.

Questions

The data processing agreement, the sub-processor list with locations, the record of processing required under Article 30 of the General Data Protection Regulation (2016), security evidence such as test reports and audit results with dates, standard terms, insurance certificates, a plain description of the service and its limits, and a named contact for each reviewing function.

Legal reads the terms and the processing agreement. The data protection officer reads the processing record required under Article 30 and the retention terms. Security reads the evidence against the Article 32 standard of appropriate technical and organisational measures. Procurement reads the commercial summary and checks the rest exists.

Plainly, in the document they concern. A security review is dated and scoped; a permission model that is being built is labelled as direction; a certification that does not exist is not implied. Reviewers sample, and a stated limit costs less than a discovered one.

Whenever any document in it changes, and reviewed as a whole at least annually. Version and date every document. A pack containing two versions of the same list, sent to two reviewers, is the most common way a supplier turns a smooth review into a long one.

Substantially. Most procurement time is spent waiting for documents and reconciling inconsistencies between them. A complete, consistent, dated pack removes both, and it signals a supplier that has been through the process before and knows what the reviewers are looking for.