You have a procurement policy. It says what has to go to tender, who can approve what, which terms are non-negotiable and what happens when a contract expires. Nobody in the business can tell you what share of last year's spend actually followed it.
Not because anybody is hiding anything. Because testing compliance means joining every purchase order to the contract it should have been written against, and no report does that.
The policy lives in a document and the spend lives in a ledger, and the two have never met. So compliance gets asserted annually rather than measured monthly, and the assertion is made by the people being measured.
Failures are not evenly distributed and they are not random. They cluster on the trades where the policy is hardest to follow — urgent work, small values, expired paper, a category nobody re-tendered because the incumbent was fine.
The rate paid differs from the awarded schedule, or there was no schedule. Real money, and it is credited to trade rate drift.
Awarded above threshold with a single bid. The tender that never ran, and the easiest of the three to schedule.
Backcharges not raised, retention released early, insurance and warranty terms not held. The fastest to move.
Still transacting past term. No rate, no recourse, no renewal conversation, and a premium on every order.
The rest of this model — the data sets it runs on, the cause split, the working behind the reference figure and a sample output — goes out by email. Two fields, nothing else.