IT Procurement for Finance, Insurance & Regulated Industries

Two industry areas of focus where regulatory requirements and commercial IT procurement are closely linked.

Financial Services & Insurance

Experience with DORA-relevant requirements (Digital Operational Resilience Act) in IT procurement

IT procurement in financial institutions is part of operational resilience. For critical ICT services, commercial goals must be reconciled with regulatory requirements for third-party governance.

Typical Challenges

  • Regulatory requirements meet commercial cost targets
  • Critical ICT providers require robust exit and control rights
  • Contract design must satisfy third-party risk requirements

Relevant Procurement Topics

  • DORA
  • ICT Third-Party Risk
  • Exit
  • Contractual Controls
  • Vendor Governance
  • Procurement Processes

How I Support

  • Integrate DORA-relevant requirements into RFX and contracts early
  • Contract gap analysis and remediation
  • Coordination with Legal, Risk, Security and the business

Pharma & Regulated Industries

Experience with GMP-relevant requirements (Good Manufacturing Practice) in IT procurement

In GMP and quality-critical environments, a commercially attractive IT solution can only be procured if validation and documentation requirements are considered from the start.

Typical Challenges

  • Validation and documentation requirements on every supplier change
  • Change control must not slow down commercial flexibility
  • Quality and risk functions need to be involved early

Relevant Procurement Topics

  • GMP
  • Change Control
  • Validation Requirements
  • Supplier Governance
  • Quality & Compliance

How I Support

  • Align sourcing processes with procurement, IT, quality and legal
  • Anchor evidence and accountability requirements in tender and contract
  • Preserve competition despite compliance requirements