Article: How Source-to-Pay Supports Public Sector Compliance
Source-to-pay, S2P, is the full run of steps an organisation goes through to buy something, from finding and evaluating a supplier through to actually paying the resulting invoice. It covers sourcing and tendering, contracts, requisitions and approvals, receipting, invoice matching, payment, and the reporting that ties it all together. For a public sector organisation, government agencies, councils and universities among them, that chain matters less as a process diagram and more as the thing that actually determines whether procurement policy is followed or quietly ignored.
Most compliance failures in the public sector don't happen in large, formal tenders. Those are scrutinised, documented and signed off at multiple levels almost by necessity. The real exposure sits in indirect spend, the ordinary, everyday purchasing that happens across dozens or hundreds of buyers: stationery, software subscriptions, consulting hours, minor equipment. It's high in volume, low in individual value, and precisely because no single purchase looks significant on its own, it's where off-contract buying, maverick spend and policy drift tend to accumulate unnoticed.
Why indirect spend is where public sector compliance usually breaks
A council or university doesn't lose control of spend through one large, obviously wrong decision. It loses control one small purchase at a time: a department finds a supplier faster than the approved panel allows, someone pays for a subscription on a personal card and expenses it later, a one-off consulting engagement never goes through a formal approval because it felt too small to bother with. None of these individually looks like a compliance problem. Collectively, across an organisation with many buyers, they add up to exactly that, spend nobody can see, suppliers nobody vetted, and no record of who approved what.
A source-to-pay platform's value in the public sector isn't that it makes buying faster, though it usually does. It's that it makes the compliant path the only practical path, so the controls built into procurement policy actually get applied every time, not just when someone remembers to apply them manually.
The S2P lifecycle, stage by stage, and what each stage controls
Sourcing and tendering
This is where a supplier is formally identified and evaluated, through an RFQ, RFT or panel arrangement. The control here is evidence: a documented, consistent evaluation criteria applied to every respondent, with the outcome and reasoning recorded. For a public sector buyer, this is also where probity requirements get satisfied, a record that the process was fair and followed policy, not just that a supplier was eventually chosen.
Contracts
Once a supplier is awarded, the contract becomes the reference point for everything that follows, pricing, terms, and the scope of what can actually be bought under it. The control this stage provides is enforcement: purchasing that stays within agreed terms rather than drifting into pricing or scope nobody actually signed off on. A contract that isn't connected to the purchasing system that follows it is just a document, it has no way to stop someone buying outside its terms.
Catalogues and approved suppliers
A catalogue of pre-approved suppliers and pricing is where policy becomes the easy option rather than an obstacle. If a buyer can find what they need from an approved supplier in the system faster than they could find it elsewhere, that's what closes off-contract buying at the source, rather than relying on a buyer remembering a policy document.
Requisitions and approvals
This is where policy-based approval thresholds and segregation of duties actually get enforced. A requisition above a certain value routes to a more senior approver automatically. The person raising a purchase isn't the same person approving it. These aren't things a manual, paper-based or email-based process reliably enforces, people are busy, exceptions get made, and a workaround becomes the new normal quietly. A system enforces the rule the same way every time, regardless of who's asking or how urgent it feels.
Receipting
Recording that goods or services were actually received, and by whom, closes a gap that's easy to overlook: without it, an invoice can be paid against an order for something that was never delivered, or delivered in a different quantity than billed. Receipting is what three-way matching, the next stage, actually has to check against.
Invoice matching
Three-way matching checks that the purchase order, the goods receipt, and the invoice all agree before payment proceeds. For a public sector finance team, this is one of the most direct fraud and error controls available, it catches a quantity that doesn't match, a price that's drifted from the contracted rate, or an invoice for something that was never actually received.
Payment
By the time payment happens, every earlier control should already have been satisfied, approved requisition, valid contract terms, confirmed receipt, matched invoice. The control at this stage is largely about keeping that chain intact and auditable, rather than allowing a payment to be pushed through with a step skipped because something was urgent.
Reporting
Reporting is where all of the above becomes something a finance controller or audit function can actually use. Spend by supplier, by category, by department, against budget and against contract, available on demand rather than reconstructed from spreadsheets when someone asks. This is also where off-contract spend, if any is still happening, actually becomes visible rather than invisible.
What auditors typically ask for, and how an S2P system produces it
A procurement audit in the public sector tends to ask variations of the same questions: who approved this purchase, and were they authorised to at that value. Was this supplier engaged through a compliant process. Does the invoice match what was ordered and received. Is spend tracking within approved budgets and contracts. Can you show a complete trail from requisition through to payment for any transaction we select.
In a manual or fragmented process, answering these means reconstructing a paper trail across emails, spreadsheets, and whoever happens to remember the details. In a connected source-to-pay system, the answer to each of those questions already exists as a record, timestamped and attached to the transaction, because it was captured as a normal part of the process rather than assembled afterward under audit pressure.
A practical example
Consider a university faculty that needs a piece of lab equipment costing a few thousand dollars, well under the threshold that would trigger a formal tender, but still a real purchase that should go through proper channels. Without a connected S2P system, a staff member might find a supplier directly, email a purchase order, and have the invoice paid once it arrives, with approval happening informally over email, if at all. There is spending, but almost no trail.
With a source-to-pay platform in place, that same purchase runs through a catalogue of approved suppliers, routes automatically to the appropriate budget holder for approval, gets receipted when the equipment arrives, and the invoice is matched against the original order before payment. Months later, if finance or an auditor asks about that specific purchase, the full record, who requested it, who approved it, what it cost against what was ordered, is already there, not something that has to be reconstructed from memory.
This is the kind of pattern a cloud source-to-pay platform built around public sector and higher education needs, Unimarket among them, is designed to support, connecting each of these stages so the audit trail is a by-product of normal purchasing rather than a separate task someone has to do afterward.
Frequently asked questions
Does a source-to-pay platform replace our existing finance or ERP system?
No, in most implementations an S2P platform sits alongside an existing ERP or finance system, handling the procurement side of the process and syncing transaction data into the finance system rather than replacing it.
Is this only relevant for large purchases or formal tenders?
The opposite, in fact. Large, formal tenders already tend to carry heavy documentation and sign-off by necessity. The real value of S2P controls shows up in everyday, lower-value indirect spend, where the volume of individual purchases makes manual oversight impractical.
How does this help with segregation of duties specifically?
By making approval routing a system rule rather than a manual check, a source-to-pay platform can prevent the same person from raising and approving their own purchase, and can route anything above a set value to a more senior approver automatically, consistently, regardless of individual judgement calls in the moment.
What's the realistic first step for an organisation still managing this manually?
Usually, mapping where spend currently happens outside any formal system or approval chain. That gives a concrete picture of how much indirect spend is actually unmanaged today, which is generally the clearest case for why each stage of a connected S2P process matters before a platform decision gets made.