Global Advice Network | Borgergade 111 | DK - 1300 Copenhagen K
E-Mail: info@business-anti-corruption.org | Phone: (+45) 60 88 10 44

How to Identify and Avoid Kickback Schemes in IT Procurement

Information technology procurement can involve large budgets, complicated specifications and long supplier relationships. That combination creates opportunities for kickbacks: secret payments, gifts, commissions or personal benefits offered to influence a purchasing decision. The arrangement may involve an employee, consultant, vendor, subcontractor or intermediary, and it can be disguised as a legitimate referral fee or project expense.

Australian organisations face these risks when buying cloud platforms, cybersecurity services, software development, hardware, telecommunications, managed services and technical support. A strong procurement process should therefore examine how decisions are made, who benefits from them and whether the organisation receives fair value. Controls need to work in practice, rather than exist only as policies stored on an intranet.

Recognise How Kickbacks Are Concealed

A kickback usually involves an undisclosed benefit exchanged for favourable treatment. A procurement officer might steer a tender towards a preferred supplier, inflate a statement of work, approve unnecessary licences or ignore poor performance. The supplier then returns part of the gain through cash, an inflated subcontractor invoice, a paid holiday, entertainment, cryptocurrency, shares or a job opportunity for a relative.

The payment does not need to be described as a bribe. It might appear as a “marketing fee”, “success commission”, “consulting charge” or “business development expense”. An employee could also receive a benefit indirectly through a partner, friend or company they control. In IT procurement, the arrangement is especially difficult to spot when technical services are hard for non-specialists to evaluate.

The risk is relevant to public and private organisations. Commonwealth agencies must consider applicable public-sector procurement rules and criminal offences involving bribery of Commonwealth public officials, while state and territory laws can apply to other government and commercial conduct. Corporations should also maintain accurate books and records and investigate conduct that could breach anti-bribery, fraud or conflict-of-interest requirements. Guidance on broader corporate responsibility, including the failure to prevent bribery, can help Australian businesses compare how different legal systems approach corruption risk.

Map Exposure Across the Technology Buying Cycle

Risk assessment should begin before a request for quotation is released. A business should identify who defines the technical requirement, who selects potential vendors, who evaluates bids, who negotiates price and who approves invoices. When one person controls several of these stages, an undisclosed relationship can influence the entire purchase without attracting effective review.

The highest-risk areas often include sole-source procurement, urgent purchases, renewals, change requests and engagements made through a systems integrator. A vendor may win an initial contract at a competitive price and later recover margin through expensive variations, proprietary add-ons or support charges. Subcontractors can add another layer of opacity, particularly where a prime contractor chooses consultants without the customer’s approval.

Australian market conditions create familiar pressure points. A business in Sydney may use a multinational cloud provider through a local reseller, while a regional organisation in Queensland or Western Australia may depend on a small number of specialist suppliers. Commonwealth entities commonly work with formal panels and AusTender processes, whereas state agencies and private companies may use different portals and purchasing rules. A panel appointment is not proof that every later purchase is fair; individual call-offs still require sound evaluation and documentation.

The same principle applies to technology partners responsible for websites or business systems. A supplier’s technical capability may be genuine, yet the commercial process can still be manipulated. For example, a web development project may include unnecessary work that sounds technical, such as custom URL mappings, bundled with vague deliverables that make value difficult to test. Clear acceptance criteria and independent technical review reduce that opportunity.

Warning Signs That Deserve Investigation

No single red flag proves that a kickback has occurred. Several weak signals appearing together, however, should prompt a confidential review. Procurement and finance teams should compare the commercial record with staff communications, supplier ownership information, approval patterns and the quality of delivered services.

Common warning signs include:

  • A specification that closely mirrors one supplier’s product or terminology
  • Repeated exemptions from competitive tendering without a documented rationale
  • Invoices containing vague descriptions such as “strategic support” or “special services”
  • A buyer resisting independent review, staff rotation or supplier due diligence

A relationship can also become suspicious when the chosen supplier is linked to a decision-maker through a family member, former employer, social group or side business. Personal familiarity is not itself misconduct, and Australia’s business culture often values trusted relationships. The issue is whether the relationship was disclosed, assessed and managed before the person influenced the purchase.

Look for operational clues after contract award. A supplier may invoice above agreed rates, split charges to stay below approval thresholds, bill for staff who were not assigned, or seek payment to a different entity. The organisation may receive unusually poor documentation but continue to renew the contract. A vendor that insists on cash, offshore accounts, personal bank details or unexplained “facilitation” costs presents a particularly serious concern.

Employees sometimes rationalise questionable conduct as “just how business is done” or accept small benefits because the procurement appears commercially sensible. Training should make clear that value, familiarity or a supplier’s strong reputation does not excuse undisclosed inducements. A modest gift can still matter if it is offered during an evaluation or contract negotiation.

Build Controls That Resist Manipulation

An effective control environment separates duties without making procurement impossibly slow. The person who writes the business requirement should not be the sole evaluator, contract approver and invoice authoriser. Evaluation panels should record scoring reasons, retain conflicts declarations and explain any material departure from the published criteria.

Due diligence should cover more than a company search. Obtain beneficial ownership information, identify directors and key intermediaries, check sanctions and adverse media where appropriate, and understand the supplier’s use of subcontractors. Ask vendors to disclose commissions, referral arrangements and relationships with employees or public officials. High-risk providers should accept contractual audit rights, accurate-records obligations, anti-bribery warranties and termination rights for serious misconduct.

Procurement teams should also test whether the price and scope make commercial sense. An independent technical specialist can review architecture, licence volumes, staffing assumptions and delivery milestones. Finance can compare rates with market benchmarks and prior contracts. Internal audit can examine whether the same people repeatedly favour particular suppliers or whether override approvals cluster around one business unit.

Digital records help, but only if access is controlled and data is reviewed. Keep tender questions, scoring sheets, conflict declarations, approvals, purchase orders, change requests, timesheets and invoices in a system with an audit trail. Analytics can identify split purchases, weekend approvals, rapid vendor onboarding, duplicate bank accounts and unusual invoice descriptions. A risk-based approach is more useful than trying to investigate every transaction manually.

Training should use realistic situations rather than abstract legal language. Staff should know that a supplier paying for an expensive meal in Melbourne during a live tender may create a conflict, just as a “mateship” arrangement in a smaller regional market can create pressure not to challenge a familiar contractor. Clear gift thresholds, approval rules and confidential reporting channels give employees a practical way to refuse or report improper benefits.

Investigate Concerns and Protect the Organisation

When a concern arises, preserve records before alerting people who may destroy or alter evidence. Relevant material can include emails, chat messages, procurement files, calendar entries, access logs, tender drafts, expense claims and supplier communications. An investigation should be proportionate but independent, with legal advice considered where privilege, mandatory reporting or potential criminal conduct is involved.

The organisation should assess whether the suspected conduct affects current payments, security access, data handling or service continuity. It may need to pause invoices, restrict system permissions, suspend a procurement exercise or appoint an interim service provider. These actions should be carefully documented so that legitimate suppliers are not unfairly penalised while credible evidence is protected.

A reporting channel must be accessible to employees, contractors and vendors. It should allow anonymous reporting where legally and operationally appropriate, protect people from retaliation and route allegations to an experienced function rather than the manager implicated in the complaint. Organisations can also use specialist external support; the Business Anti-Corruption Portal’s contact page is a useful point of reference for seeking information about anti-corruption resources.

The investigation should examine both the individual act and the control failure that allowed it. If a buyer accepted a benefit, ask why the conflict declaration was not reviewed. If an invoice was inflated, determine whether technical sign-off was meaningful. If a subcontractor made the payment, assess whether the prime contractor performed adequate due diligence and monitoring.

Good judgement in procurement resembles disciplined decision-making in any environment where incomplete information creates temptation. A continuation decision in a card game, for example, should be based on evidence and calculated risk rather than emotion; this explanation of a poker continuation bet illustrates how a seemingly small choice can shape later outcomes. In procurement, the equivalent is pausing a renewal or challenging a convenient variation before a questionable pattern becomes embedded.

A practical anti-kickback programme should include:

  • Clear ownership for conflicts, gifts, due diligence and supplier monitoring
  • Independent review of high-value, urgent and sole-source technology purchases
  • Contract clauses covering records, audits, subcontractors and termination
  • Safe reporting routes supported by prompt, documented investigations

The organisation should communicate outcomes without exposing confidential details or breaching employment and privacy obligations. Disciplinary action, contract remedies, recovery of funds and regulatory reporting may all be appropriate depending on the evidence. Lessons should then be translated into revised approval thresholds, stronger vendor screening, better technical assurance or targeted training.

Procurement leaders can monitor a small set of useful indicators: the percentage of purchases awarded without competition, the number of overdue conflict declarations, supplier concentration by category, contract variations after award, and exceptions to standard terms. Trends matter more than a single figure. A rising rate of urgent purchases in a particular team may indicate weak planning, commercial pressure or deliberate avoidance of controls.

The most reliable safeguard is a documented chain of accountability from business need to final payment. Define the requirement independently, disclose relationships, test supplier ownership, compare value, separate approvals, monitor delivery and investigate anomalies. In practical terms, every IT purchase should leave enough evidence for an informed reviewer to explain why that supplier won, what was delivered and who benefited.

copyright © Global Advice Network