All vendor management guides

Vendor management Guide

A Lightweight SaaS Procurement Process for Growing Companies

A lightweight SaaS procurement process has five parts: a single intake form, tiers that set how much review each purchase gets, RFPs only for large or high-risk buys, a short list of contract terms you always check, and a renewal calendar with named owners. Adding more steps than that tends to slow the business and push people toward buying around you. This guide explains how to set up each part and what to put in it.

Start with one intake form

Most SaaS sprawl begins with someone putting a subscription on a corporate card. A procurement function cannot fix what it never sees, so the first step is a single front door for every software request.

Keep the form short. If it takes more than five minutes to complete, people will skip it. Ask for:

  • What problem this solves, in one or two sentences
  • Requesting team and budget owner
  • Vendor name, if known, and any alternatives considered
  • Estimated annual cost and number of users
  • Data involved: none, internal only, customer data, or personal or financial data
  • Integrations with existing systems, such as SSO, CRM or the data warehouse
  • Needed-by date, plus the reason for that date

Send every request to one queue. A shared inbox, a ticketing tool or a spreadsheet all work at first. What matters is that finance, IT and security see the same list, and that procurement checks it for overlap with tools you already pay for before anyone starts vendor calls.

Sort requests into review tiers

Not every purchase needs the same scrutiny. Tiering stops a $40-a-month tool from waiting in the same line as a six-figure platform. Base the tiers on two factors, annual spend and data risk, and use whichever one puts the request in the higher tier.

Example tiers. Adjust the dollar amounts to your company's size and budget:

  1. Tier 1: Low spend, no sensitive data. Example: under $5,000 a year with no customer or personal data. The budget owner approves, IT confirms there is no overlap, and the team buys. Target turnaround: two to three business days.
  2. Tier 2: Moderate spend or internal data. Example: $5,000 to $50,000 a year, or any tool touching internal business data. Add a light security review and a finance check. Get at least two quotes or confirm list pricing. Target: one to two weeks.
  3. Tier 3: High spend, sensitive data, or core systems. Example: over $50,000 a year, anything holding customer or payment data, or systems of record such as ERP or HRIS. Run a structured evaluation or RFP, a full security review and legal review. Target: four to eight weeks.

Publish the tiers and the target times. When requesters can see why their purchase takes three weeks, they are far more likely to plan ahead and less likely to go around the process.

Run an RFP only when it earns its keep

A formal RFP costs time for your team and for vendors. Keep it for Tier 3 purchases, or for cases where you truly have three or more credible options and switching later would be expensive.

For everything else, a structured comparison is enough: a one-page scorecard, two or three demos and a pricing quote from each vendor.

When you do run an RFP, keep it tight:

  • Limit it to three to five vendors. Do a quick screen first so you don't waste anyone's time.
  • Write requirements as must-haves and nice-to-haves. A 200-line requirements matrix mostly measures how well a vendor fills in spreadsheets.
  • Ask for pricing in a set format. Include per-user or per-unit cost, implementation fees, support tiers, and price caps for years two and three.
  • Set a firm timeline. Two to three weeks for responses is a common, reasonable window for SaaS.
  • Score before demos, then again after. This keeps a polished demo from outweighing weak answers.

Example scorecard weighting for a mid-size tool: functional fit 35%, security and compliance 20%, total cost over three years 20%, implementation and support 15%, vendor viability 10%. Agree on the weights with stakeholders before any responses arrive.

Check the contract terms that matter

You don't need to negotiate every clause. Focus on the terms that cost growing companies the most when they go unnoticed. Keep this checklist and use it on every Tier 2 and Tier 3 contract:

  • Auto-renewal and notice period. Many SaaS contracts renew automatically unless you give notice 30 to 90 days in advance. Try to shorten the notice period, or at least record it.
  • Renewal price increases. Ask for a cap on uplifts at renewal.
  • User or usage minimums. Watch for commitments that assume growth you may not reach.
  • True-up terms. Know how and when overages get billed.
  • Termination rights. Look for exit rights for material breach, and ideally for repeated SLA failures.
  • Data return and deletion. Confirm you can export your data in a usable format and that the vendor deletes it after termination.
  • SLA and service credits. Check uptime commitments and whether credits are automatic or have to be claimed.
  • Liability caps and security obligations. These matter most when the vendor handles sensitive data. Bring in legal here.

Example wording for a renewal cap:

"Upon renewal, Vendor may increase fees by no more than the lesser of 5% or the change in CPI over the preceding twelve months, provided Vendor gives Customer written notice at least 60 days before the renewal date."

Vendors often accept a cap like this during the initial deal, when they want the signature. It is much harder to get at renewal.

Make approvals and signatures predictable

Slow approvals usually come from unclear ownership, not from too many approvers. Write down who approves what, and give every step a backup.

A simple approval matrix:

TierBudget ownerIT/SecurityFinanceLegalSignatory
1YesOverlap checkNoNoBudget owner
2YesLight reviewYesIf non-standardDepartment head
3YesFull reviewYesYesExecutive per policy

Run reviews in parallel wherever you can. Security can review a vendor's questionnaire while legal marks up the contract. Running each review only after the previous one finishes is the most common reason a two-week purchase turns into two months.

Before signing, record the key facts in one place: vendor, contract owner, start date, end date, notice deadline, annual value and payment terms. That record is the basis for everything in the next step.

Track renewals before they turn into emergencies

The work doesn't end at signature. Renewals are where most avoidable SaaS spend comes from: tools no one uses anymore, seats that never got removed, and price increases that went through without anyone questioning them.

Set up a renewal routine:

  1. Keep a contract register. Include every active contract, its owner and its notice deadline. A spreadsheet is fine until you have more than a few dozen contracts.
  2. Set reminders from the notice date, not the renewal date. For a 60-day notice period, the first reminder should go out around 120 days before renewal.
  3. Run a renewal check. Ask the owner three questions: are we still using this, how many seats are active, and is there a better option?
  4. Pull usage data. Most SaaS admin consoles show login or activity data. Remove inactive seats before the renewal quote arrives.
  5. Decide: renew, renegotiate, downsize or cancel. Record the decision and the reason.

Review the register quarterly with finance. A short meeting to look at the next two quarters of renewals catches most problems while you still have time to act.

Let pingpong run it for you

pingpong drafts the RFP, finds and invites vendors, collects proposals through a private portal, scores them with five AI models and flags the gotchas above. It drafts every negotiation message for your approval, then keeps watching the market so you renegotiate before renewal. $100 for the first month, then $799 a month.

Common questions

How do I get teams to follow a procurement process instead of using corporate cards?

Make the process faster than working around it, especially for small purchases. Publish your tiers and target turnaround times, and approve Tier 1 requests within a few days. It also helps to have finance flag recurring card charges from software vendors so you can bring them into the register.

When should a growing company hire a dedicated procurement person?

Common signs include software spend that no single person can track, renewals that keep slipping past notice deadlines, and frequent security or legal bottlenecks. Before that point, many companies give procurement ownership to someone in finance or operations, supported by a clear intake form and approval matrix.

What should a lightweight security review include for SaaS vendors?

For moderate-risk tools, ask for the vendor's current SOC 2 Type II report or ISO 27001 certificate, confirm SSO support, and check where data is stored and how it is encrypted. For vendors handling sensitive data, add a security questionnaire, check subprocessors, and review the data processing agreement. Scale the depth to the data involved, not to the contract value alone.