Technology Procurement for Government: A Buyer's Guide
Across five UK digital programmes, supplier arrangements contributed to at least 29 years of delay and £3 billion in cost increases. The auditors were clear about why — and the fix is in how the contract is written, not who signs it.

This guide is written for the buyer, not the seller.
We build technology for public institutions, so we have an obvious interest in how government buys it. We have written this anyway, and written it straight, because the single biggest risk in public sector technology is not vendor dishonesty. It is that buyers and suppliers agree a contract that was never capable of producing the outcome either of them wanted.
The auditors have documented this exhaustively. Almost nobody reads them.
What the auditors actually found
The UK National Audit Office examined five large government digital change programmes — the Emergency Services Network, Electronic Monitoring, Universal Credit, the National Law Enforcement Data Service, and Digital Services at the Border. It found that commercial approaches to working with suppliers contributed to delays totalling at least 29 years and more than £3 billion in cost increases, at least 26% above original forecast. The NAO notes these figures come in varying formats and price bases and may not reflect final cost. (NAO, January 2025)
Its diagnosis of the mechanism is the most useful passage in public sector technology. The NAO grants that frameworks make process compliance easier, then says this:
Frameworks "risk encouraging a contracting approach based on time usage rather than specifying what the supplier is meant to achieve." They are, in the NAO's words, "geared to buying inputs rather than outcomes."
The same report found that government's ability to manage what it had bought was structurally thin: at least £14 billion is spent annually on public sector digital procurement, yet only 15 people managed relationships with government's largest digital suppliers. Commercial directors told the NAO that "very limited resource or priority is given to managing suppliers post-contract award," and that "very little information on supplier performance is available" to inform future awards.
The US picture is structurally identical. The Government Accountability Office has kept federal IT acquisition on its High-Risk List since 2015, noting that the government invests more than $100 billion a year in IT while those investments "too frequently fail or incur cost overruns and schedule slippages while contributing little to mission-related outcomes." Of 1,881 recommendations GAO made in this area since 2010, 463 remained unimplemented as of January 2025. (GAO-25-107852)
Read those together and the conclusion is uncomfortable but clear. These are not procurement accidents. They are the predictable output of buying inputs, not measuring afterwards, and having nobody left to notice.
The competition problem, and why it costs you
There is a second pattern, less discussed, that directly affects the quality of what you can buy.
The European Court of Auditors found that across the EU, the single-bidding rate rose from 23.5% in 2011 to 41.8% in 2021, while the average number of bidders per procedure almost halved, from 5.7 to 3.2. Its section heading was blunt: the share of contracts awarded to SMEs has not increased overall. (ECA Special Report 28/2023)
The European Commission's own scoreboard treats a single-bidder rate above 20% as unsatisfactory, and says of its SME-bids indicator that low percentages "indicate the existence of barriers to SMEs."
In the UK, SME share of public procurement in England reached a six-year high in 2025 at 21% of direct spend — but central government sits at just 10%, down from 13% in 2020. (British Chambers of Commerce and Tussell, May 2026)
If you are a public buyer, this is your problem rather than the market's. Fewer bidders means less price pressure, less innovation and more dependence on incumbents who know you cannot easily leave. Procurement processes designed to reduce risk frequently reduce competition instead, which increases it.
The frameworks, by jurisdiction
What follows is accurate as of September 2026. Two of these changed recently enough that most vendor websites still have them wrong.
European Union
The AI Act (Regulation (EU) 2024/1689) reached its general date of application on 2 August 2026, with transparency obligations now enforced. Prohibitions have applied since February 2025 and general-purpose AI obligations since August 2025.
The part most suppliers get wrong: the AI Omnibus, Regulation (EU) 2026/1744, deferred Annex III high-risk obligations to 2 December 2027, and Annex I to 2 August 2028. If a vendor tells you high-risk obligations landed in August 2026, they are working from outdated guidance. (European Commission)
Also relevant: Article 29 of the EU Data Act prohibits cloud switching charges entirely from 12 January 2027. (Regulation (EU) 2023/2854)
United Kingdom
Crown Commercial Service became the Government Commercial Agency on 1 April 2026. Existing contracts remain valid; documents published before that date will still say CCS.
G-Cloud 15 (RM1557.15), live since 6 August 2026, is the route for cloud hosting, software and support; G-Cloud 14 expires on 28 October 2026. It cannot be used for bespoke design and development — that goes through Digital Outcomes and Specialists 7 (RM1043.9), live since 30 January 2026, which absorbed the former Digital Specialists and Programmes agreement. Non-cloud technology services and data centre colocation each have their own routes again.
The Algorithmic Transparency Recording Standard has been mandated across central government departments since 6 February 2024, covering algorithmic tools that significantly influence decisions with public effect or interact directly with the public, once those tools reach pilot or production. Its most important sentence for buyers:
"Commercial suppliers that wish to sell algorithmic solutions to public bodies that are then used in processes that impact members of the public should be comfortable with this level of transparency that is expected of the public sector. Public bodies that are procuring solutions from vendors should make this expectation clear in their invitation to tender or other route to market."
(GOV.UK)
Put it in the ITT. A supplier who hesitates has told you something useful.
United States
FedRAMP standardises security authorisation for cloud services used by federal agencies, with a public marketplace of certified services. GovRAMP, formerly StateRAMP, provides an equivalent for state, local and education bodies.
OMB M-25-22, Driving Efficient Acquisition of Artificial Intelligence in Government (3 April 2025), is the most useful procurement document any buyer can read, in any jurisdiction. Agencies must, where applicable, include contract terms addressing IP rights and government data, privacy, vendor lock-in protections, compliance with M-25-21 for high-impact uses, and ongoing testing and monitoring. Specifically:
- Agency processes should ensure contracts "permanently prohibit the use of non-public inputted agency data and outputted results to further train publicly or commercially available AI algorithms, consistent with applicable law, absent explicit agency consent"
- Agencies must be able to evaluate performance "e.g., on a quarterly or biannual basis"
- Evaluation data "should not be accessible to the vendor"
- Contracts "must not prohibit agencies from internally disclosing how the vendor conducts testing or the results of testing"
Section 508 accessibility requirements belong in the requirements document and acquisition plan rather than being retrofitted. The 2021 FAR rule places them across FAR Subpart 39.2 and related parts, though note that the ongoing FAR overhaul is relocating this material — check the current text rather than a summary. (Section508.gov)
The NIST AI Risk Management Framework (AI 100-1) remains voluntary, and NIST states on its own page that it "is being revised as part of the White House AI Action Plan" — so do not treat it as settled. (NIST)
India
GeM is the national public procurement portal, recording ₹5.4 lakh crore GMV in FY 2024–25. (PIB)
The DPDP Rules, 2025 were notified on 14 November 2025 with an eighteen-month phased compliance window, activating the Act's penalties of up to ₹250 crore for failure to maintain reasonable security safeguards. Significant Data Fiduciaries face independent audits and impact assessments. The era of treating DPDP as an Act awaiting rules is over. (PIB / MeitY)
MeitY's India AI Governance Guidelines, released 5 November 2025, are principle-based and voluntary-first, structured around seven Sutras. They address anyone developing or deploying AI systems in India — which includes your suppliers — and expect them to demonstrate compliance on demand to agencies and sectoral regulators, maintain a grievance redressal mechanism resolving issues in a reasonable timeframe, and publish transparency reports evaluating risk of harm in the Indian context, with sensitive content shared confidentially with regulators. (PIB backgrounder)
What to put in the contract
Drawn from what the auditors say went wrong, and from M-25-22, which is the clearest published statement of good practice we have found anywhere.
Specify the outcome, not the hours. This is the NAO's central finding. If the contract describes effort, you will receive effort.
Reserve evaluation rights, and hold the evaluation data yourself. A supplier who marks their own homework will pass.
Prohibit training on your data without explicit consent, permanently. Not for the contract term — permanently.
Require transparency you can pass on. If you will need to publish an ATRS record or answer a parliamentary question, the supplier needs to be contractually capable of supporting that.
Price the exit at the start. What does it cost, in money and elapsed weeks, to move to another supplier? Get it in writing while you still have leverage.
Fund the post-award capability. The UK government's own State of Digital Government Review found that only 28% of survey respondents believed their organisation had sufficient internal capabilities to monitor, track and drive supplier performance. (DSIT, January 2025) A contract nobody manages is a contract nobody is honouring.
Three questions for any supplier
Which of your public sector deployments did not work, and what happened? Anyone who has delivered at scale has one. Anyone who has not will change the subject.
What would make this cost three times your estimate, and what catches it early?
What does it cost us to replace you?
We would want all three asked of us. If you are scoping a public sector technology project and want these questions applied properly before anything is committed, we are glad to have that conversation.
Kaizen Spark Tech designs and delivers software, AI, automation and digital infrastructure for businesses and institutions. Every statistic here is linked to its original published source. This guide is accurate as of September 2026 and is reviewed quarterly, because several of the frameworks above are still moving — framework numbers, AI Act dates and DPDP deadlines all change. If you find something here that has moved since we last checked, tell us and we will correct it in public.
