Software, SaaS & Cloud Purchases: Use the Approved Process
Before purchasing software, Software-as-a-Service (SaaS), cloud services, cloud storage, subscriptions, or other technology, departments must follow the approved Procurement and ITS review process.
Procurement Services is experiencing an increase in software and technology requisitions that must be returned because the required ITS security review has not been completed. To help avoid delays, departments should determine whether a Vendor Risk Assessment (VRA) is required before submitting an Oracle requisition for technology that may access UCR data or connect to the UCR network.
A VRA is UCR’s due-diligence process for evaluating the security, privacy, and operational risks associated with third-party software, services, and hardware. The review helps ensure that vendors handling UCR institutional data or connecting to the UCR network meet UC information security requirements.
Following the required process helps prevent duplicate purchases, data-security risks, unauthorized commitments, and delays in issuing a purchase order.
Before You Buy
- Check for an existing solution. Review the ITS Software Catalog and existing campus or UC agreements for an approved site license, enterprise agreement, or previously vetted option.
- Complete any required ITS review. If the product or supplier is not listed, submit an ITS Software Request/VRA Intake as early as possible. Any required VRA must be completed and approved before a purchase order can be issued.
- Route the purchase through Procurement Services. Software, SaaS, and cloud or storage services must be submitted through Oracle Procurement, regardless of dollar amount.
- Do not use a workaround. A Procurement Card (PCard), personal funds, or another payment method may not be used to bypass required Procurement and ITS review.
- Use the correct coding. Select the appropriate Oracle Purchasing Category for the software or technology purchase.
Commonly used software/technology purchasing categories:
- Cmpt Hardware Maint License [546050]
- Cmpt ProgramSys Dev Non Cap [546000]
- Cmpt Software Maint License [546020]
- Cmpt Software Non Inventory [546010]
Reminder: For complex, multi-year, or multi-payment software purchases, request and attach a pro forma invoice from the supplier.
School of Medicine departments should follow the School of Medicine IT Procurement process.
Do not assume a product is approved because another department or UC location uses it. Renewals may also require reevaluation based on applicable security, privacy, and risk requirements.
Additional Resources
Thank you for engaging Procurement Services and ITS early and helping protect UCR’s systems and data.
Sincerely,
Jeremy Meadows
Chief Procurement Officer | Procurement Services
University of California, Riverside
Dewight F. Kramer
Chief Information Security Officer | Information Technology Solutions
University of California, Riverside