Skip to content
Economic Roundtable Associates
← All insights
GovernmentMay 20263 min read

Buying Technology Well in a Compliance-Heavy World

How to run a procurement that protects the mission without strangling the project.

The longest RFP we ever read specified the button colors. Screen by screen, field by field, for a system that wouldn't exist for another three years. By the time it shipped, half those screens were solving last decade's problem.

Here's what people get wrong about public-sector buying. The compliance isn't what kills these projects. FAR clauses, security reviews, accessibility requirements, none of that ever sank a program we've seen. Vague requirements dressed up as precise ones did.

Compliance is not your enemy

Compliance is a fence, and fences are honest. They tell you where the edge is and you plan around it. Section 508, FedRAMP, records retention: these are knowable, bounded, and any vendor worth hiring has done them a hundred times.

What strangles projects is the requirement that sounds specific but isn't. The system shall provide comprehensive reporting. Comprehensive to whom, for what decision? Twenty stakeholders will read that line twenty ways, and you'll discover the disagreement during user acceptance, which is the most expensive possible moment to discover anything.

Buy outcomes, not blueprints

The instinct, once you've been burned, is to specify harder. More shall statements, more detail, more pages. It feels safer. It's the opposite of safe.

A document that nails down every technical decision has made those decisions years before anyone learned anything. You're locking in the judgment of the people who knew the least, at the moment they knew it.

Write outcomes instead. A caseworker completes an eligibility determination in one sitting. A resident pays a bill without calling anyone. Those are testable, they survive technology churn, and they let vendors compete on how, not just on price.

An RFP that specifies everything is buying yesterday's solution at tomorrow's price.

One utility procurement rewritten this way cut the requirements document roughly in half. The proposals got better, not worse. Vendors who could only parrot specs back dropped out. Vendors who understood the mission leaned in.

Leave room to learn

Structure the buy so the first release is small and real. A pilot with actual users beats a design phase with actual binders. Score vendors on a working demo against your data, not on the thickness of their past-performance volume.

Put change into the contract on purpose. Not open-ended scope, which terrifies everyone for good reason, but a deliberate mechanism: a re-prioritization checkpoint each quarter, a budget line for what you'll learn along the way. The alternative isn't stability. It's change orders, which are the same learning at triple the price and quadruple the paperwork.

And keep your compliance people in the room from day one, not waiting as a gate at the end. Every painful eleventh-hour security finding we've seen was knowable in month one. The reviewers aren't obstacles. They're early-warning systems that agencies keep pointing at the finish line instead of the start.

The mission deserves protection. So protect it from the real threats: ambiguity, premature certainty, and the fantasy that a thick enough document eliminates risk.

The best procurements we've seen were the shortest ones, written by people humble enough to admit what they didn't yet know.

Scenarios in ERA notes are illustrative composites drawn from two decades of prior work, not ERA client engagements.

This is how we workSee the Strategy & Advisory practice
Previous / AIBefore You Buy the AI Tool, Answer These Five QuestionsNext / EngineeringWorking Across Time Zones Without Losing the Thread
Working through one of these? Start a conversation.