Category Archives: Market Intelligence

P2P: Points 2 Ponder when People are Pushing Off S2P Platforms

Years are passing and still not enough companies are using good, modern, fully electronic, Source 2 Pay Technologies when they should be. (We’re using technologies and not platform because it doesn’t necessarily have to be one platform from one vendor, as long as the S2C can be tightly integrated, even if by way of a third party like Per Angusta, and the P2P are tightly integrated and the S2C and P2P are integrated at the end points, that is sometimes the best solution for some companies.) Even worse, many of these companies have realized the importance of good Supply Management and adopted point-based Sourcing, Procurement, and/or and Supplier (Performance/Information/Risk) Management software. But that’s not enough. SI has been ranting for years about the fact that it’s Sourcing AND Procurement and that if you don’t implement the full cycle, you’re not only leaving savings on the table but failing to capture all of the value available to you.

Why are otherwise smart, moderately progressive, companies doing this? Because they have deep concerns that the platform won’t do what they need it to do and fears that the only reason these platforms exist is to eliminate their jobs the same way machines and automation have led to our manufacturing woes. And while they have good points, since some of the early solutions didn’t do everything they needed to do in order for the company to obtain the promised benefits, and since automation of any sort typically leads to elimination of workforce in the function, when you look at some of the current solutions and look at the goal of Procurement in the right light, their points are no longer valid. And this is true even if the platform has cognitive or auto-buy elements. There’s still only so much it can do, and so much more you have to analyze these days when doing high-dollar or strategic buys.

Nevertheless, if the points of trepidation are not addressed, the solutions won’t be considered, the function will not advance, and, vendors, you won’t survive. So, because SI encourages the proper use of technology platforms to increase efficiency, eliminate non-value-add tactical tasks, and augment the capability of your workforce (which is different from replacing it), SI is going to give the vendors building these solutions a helping hand by identifying the common trepidations, the solution requirements needed, and, as a result, the message you have to get across to calm the prospective buyer’s nerves (provided, of course, that you do have the solution requirements).

Trepidation # 5: It Won’t Save Money. There will always be exceptions to manage, suppliers who can’t use it, and administrative requirements and the costs will just be shifted.
Many early systems claimed big savings, typically in the 80% range, but never really delivered. The reality is that if the organization still has to support offline paper processes, still has to review all the invoices for errors, has to have an IT person administer the system, etc., the costs just shift. A modern S2P system has to support, and be usable by, all suppliers (and not just the top X that constitute 80% of spend), has to automatically detect errors and unmatched bids, invoices, and documents and has to be low, or no, cost to administer for the 80% savings to materialize. Otherwise, the buying organization won’t be able to achieve the 3X to 5X ROI the system is supposed to deliver and will not want it.

Trepidation # 4: We use X for purchase orders and / or Y for payables tracking and / or Z for Strategic Supplier Management. We can’t replace these systems.
A lot early systems expected that they would be the system of record for whatever the system did, and that all the system had to do was export the payments to a flat file for importing into the finance system. This is not the case. The platform has to integrate, in a straightforward manner, with the systems the buying organization uses for Purchase Orders and Inventory Management and Supplier Masters and the systems the buying organization uses for Accounts Payable.

Trepidation # 3: It Won’t Work For Us. Our Processes are Unique.
A lot of early systems followed the Henry Ford philosophy in that “you can have any colour as long as it’s black“. This doesn’t work for organizations that have distinct sourcing processes depending on the category type and value, distinct supplier relationship management processes depending on what the supplier supplies and where the supplier is located, distinct contract negotiation processes depending on contract value and risk, unique invoice approval workflows, distinct payment procedures, and different master-data storage policies. While the basic workflow is the same at a high level, it is different in the implementation across companies and the platform needs to support workflows that can be customized.

Trepidation # 2: Our Suppliers Can’t Use It / It’s Too Much Work for Our Suppliers
A lot of early systems took the view that “we have a portal that accepts EDI format and/or manual data entry and that’s good enough“. The problem is that supply organizations, like buying organizations, have different systems and different processes and, typically, don’t have the manpower to support a different bidding, data submission, and invoicing mechanism for each customer and, frankly, won’t. The system has to support the common processes and technologies used by suppliers in the buyer’s market. A few (small) suppliers can be given a single “portal” solution, but this has to be a minority.

Trepidation # 1: They Took Their Jobs and Now They Will Take Our Jobs!
A good S2P system with guided buying and auto-buy for low-dollar / non-strategic categories, which is exception-driven and requires a buyer to only manually review buys above a certain dollar amount, supplier approvals for key categories, and invoices that don’t match POs and / or exceed a certain dollar value, and which provides mechanisms all suppliers can use to submit electronically, should reduce the tactical invoice processing effort by 80% or more. This means that if the people doing the invoice processing had no other skills, then 4 out of 5 would lose their jobs. But if these are true procurement people, their job function would just be shifted to a more strategic role as redeploying these resources to spend more time on strategic supplier management, category management, and risk management would provide the organization with a value that (far) exceeded their cost. You don’t get rid of smart people just because you got a new system. You just ask them to deliver many times more, which they can do thanks to the new system.

Time for Alternative Design!

The US President slapped 16.1 Billion of tariffs on Canada. Canada retaliated. The US slapped Billions on the EU. The EU retaliated. Trade is getting quite expensive between these countries, especially since the US slapped tariffs on goods and services it needs (because it just doesn’t have enough of them) — which is kind of contrary to one of the main purposes of tariffs, to prevent the market from being flooded from lower cost goods you don’t need.

Now global companies that can are moving production out of the US to other markets when they can to produce goods for sale in those markets in those markets to avoid tariffs — home manufacturing. (At least the US can say it’s tariffs are helping to deliver on job creation — it is creating jobs, in other markets.)

But what do you do if your primary market is the US and your factories are also in the US but you currently rely on raw materials, goods, and/or services where the home-based supply is not enough? Well, right now you pay more, but at some point this could price your product out of the range of your target market, and put your organization out of business.

You could try making a different product, but if it’s not one the market wants, that could also put it into bankruptcy.

Or you could get creative and find an alternate design that uses alternate materials that are lower cost. This is not easy, but it is possible. You’ll just need some creative thinkers, good engineers, and an open mind. (And if they need a methodology to get started, check out SI’s classic post on The Operations Research Process which gives you some hints, including the possibility of adopting TRIZ.) Or, if that’s too onerous, you could always try crowd-sourcing. Post a challenge on a secure platform that uses blockchain where researchers or groups can post responses (that can be unarguably traced back to them) and offer a guaranteed contract or reward if the response is chosen.

With a lot of elbow grease, you’ll find that you probably can successfully home-source, even if the best answer would be to near-source (as that option might not be available for a while).

GDPR Just Made The Best Argument for Making Your Data — And Applications — Available Online 24/7 Even Better!

Seven years ago SI published a short article that stated if your data isn’t immediately accessible online, either behind your firewall or behind someone else’s firewall or in the cloud, when your employees need it, then they are going to download it to their machines. If their machine is a laptop, and the data is not securely encrypted, and the laptop is stolen then … it could cost your organization 1 million (or more) based upon research conducted by ZoneAlarm. There were a host of reasons for this including fraud costs (if financial information was stolen), lawsuits (if personal data was stolen), market loss (if trade secret data was stolen and sold to your competitor who then got a jump start on a competing product), and so on.

However, GDPR has upped the cost of a breach. Given that a single violation could result in a fine equal to 4% of your organization’s annual revenue, that could be a 4 Million, 40 Million, or even a 400 Million fine. And it’s not unreasonable to think that the EU could slap that size of a fine on you if you didn’t have any controls or policies around personal data and didn’t even notice when a junior HR employee decided to download your entire corporate directory to his laptop to do “statistical processing” on the weekend, didn’t bother to even encrypt the data, left the laptop at the bar where he stopped for a drink on the way home, where it got stolen, and the entire corporate directory, complete with SIN numbers and banking information, ended up on the dark web Saturday morning.

But if your data is online 24/7, and all of your applications your employees need to process that data is online 24/7, then they have no need to download the data, and if it’s easier to do it online than download, they won’t even try.

And don’t say its insecure to put your data and applications online. Don’t forget that as long as you have an internet connection coming in (and you do), your data is online whether you like it or not, and if the appropriate security precautions aren’t in place, any script kiddie who wants it can get it.

And unless you are an IT SaaS solutions provider, chances are your internal security controls are not as strong as the security controls the provider has put in place. Offering data and application security is part of their core business, it’s not part of yours. You can be sure they have strong encryption in place, multiple firewalls, DDoS detection capability, deep logging capability, penetration attempt detection, and other security controls that you likely don’t have.

Also, modern SaaS providers support private database instances (so if someone hacks your competitor, you don’t get hacked), private application instances (on your own private virtual machine that can be configured to only be access through your own private VPN), and deep security controls around users and roles.

So unless you plan on going 100% offline, and keeping all your data on machines only accessible on servers in highly secure facilities surrounded by Faraday cages, it’s probably safer for your organization to go 100% online.

GDPR: The Dreaded DPIA (Part XV)

Today’s guest post is from Tony Bridger, an experienced provider of Procurement Consulting and Spend Analysis services across the Commonwealth (as well as a Lean Six Sigma Black Belt) who has been delivering value across continents for two decades. He is currently President of UK-based TrainingWorx Ltd, a provider of a wide range of Procurement and Analytic business training programs (inc. GDPR, spend analysis, project management, process improvement, etc.) and focussed short-term consulting solutions. Tony can be contacted at tony.bridger@data-trainingworx.co.uk.

One of the key changes in the GDPR legislation involves the creation of DPIAs or Data Protection Impact Assessments.

At first glance this appears to be what can only be termed as a “mindless piece of bureaucracy”.

However, perhaps not.

Historically, it may be hypothesised that many personal data breaches have been the result of “mindless planning” neatly followed by badly managed execution.    It has been incredibly easy to obtain data, endlessly spam individuals — and share that data around.   Often, little or no thought, planning or impact assessment has been conducted in the process of managing this type of data.

Conceptually, the DPIA is a very good idea.   However, like many EU regulations the “how” is more obtuse and intricate.

The United Kingdoms ICO site (Information Commissioners Office) states that:

“You must do a DPIA for processing that is likely to result in a high risk to individuals”.

High risk is hard to define in the procurement world.   Many hosted procurement technologies contain considerable volumes of personal data as we are all aware – both controllers and processors need to stop and carefully assess any new data management proposals.   A DPIA creates a structured approach and framework that can be used to help define if the targeted processing could breach the regulation.

A DPIA is effectively a combined project brief and risk assessment of any new data processing activity that an organisation intends to conduct.   The DPIA contains a variety of what appears to be simple requirements.   The DPIA must:

  • describe the nature, scope, context and purposes of the processing;
  • assess necessity, proportionality and compliance measures;
  • identify and assess risks to individuals; and;
  • identify any additional measures to mitigate those risks.

If you think about it carefully, it is eminently sensible in its approach.

However, deductively there are several core organisational processes that need to be in place to achieve the outcome.   In many respects, this is the point at which the DPIA becomes a little more complex in the implementation and management.   If the organisational processes do not currently exist – then these are likely to add to the complexity.

In response to this, supervisory authorities have attempted to provide guidance and checklists that can help organisations manage this process and reduce risk.   We have left the discussion on DPIAs until this stage as there are options to use the process to overcome some of the risks with personal data in this domain.  However, there may be some good news.

In our next post we will start to evaluate how procurement data could be managed through the DPIA process.

Thanks, Tony!

Zycus – Expending their Horizons in the EU

Zycus recently held their inaugural event in Europe — the last three days in Prague, to be precise. the doctor was there and he has to say he was impressed with

  • the conference organization
    (less snafus or lack of organization then a few conferences he’s been to recently organized by larger peers),
  • the content
    (they did a great job blending content from them, their partners, their customers, and leading analysts),
  • the progress
    both on the customer front and the product front

Recently we’ve seen a number of companies break out of Europe and into North America — like Ivalua and Synertrade — but we rarely see companies, even those from North America (and definitely those from India), break in, especially in a short time-frame. In the last two years Zycus has went from almost no presence in Europe to a known provider of S2P services with dozens of local customers among its 300+ worldwide deployments supported by local partners.  That’s quite impressive.

This last fact is key — Zycus understands fully that Europe is not India or America. It is dozens of countries with dozens of languages and dozens of local cultures that need to be supported by a provider that wants to effectively support its customers and the continent in, and on, which they do business. And Zycus understands that there are local implementation partners and providers in Europe that understands these needs. So while some providers try to sell locally with their own staff that they hire in Europe (who can’t know everything as they are few), others try to sell exclusively through partners (who are better equipped for local support, but if not well trained, can’t accurately represent the provider), they sell as a partnership with the local implementation partner, provider of software and provider of service (but take all the responsibility for ensuring the customer receives a successful deployment).

And a successful deployment is something they are quite capable of achieving. Not only do they have 300+ people to support implementations, but they have a history of working with partners to ensure that any localizations that need to happen, happen. We expect that as long as all parties go in with a solid understanding of what needs to happen, and what the true effort is, deployments will be appropriately planned and be successfully realized. And customer progress will continue.

Then we have the product front. Zycus continues to develop and have made good progress on a couple of modules, and their iRequest module in particular. While this may seem the least sophisticated from a sourcing perspective, it is the most important from a success perspective.

When one thinks about why most mavericks try to bypass the Procurement department, it’s typically because they see the Procurement department as a bottleneck. Too long to get approvals. No visibility into the sourcing event. Etc. Etc. With iRequest, anyone in the business can make any sort of request or requisition to Procurement and follow it through to the conclusion, with visibility not just into the status, but into the sourcing event, contracting process, or anything else that is relevant. It links into almost all of their other modules and allows a buyer to kick off events, approval chains, and information request processes with relative ease. It makes Procurement look like an enabler and that is key to organizational acceptance and success. It’s definitely worth checking out.

More coverage on Zycus, here and in depth on Spend Matters Pro (membership required), is coming, so stay tuned.