Industry trends

KPMG: Governance and procurement’s new operating model

What procurement is responsible for when agents execute more of the work.

Written By
Cesar Suarez and Peder Gustafson

For decades, procurement has been measured largely on execution-oriented indicators like cycle time, requests completed, savings captured and spend under management (SUM).

This form of measurement is what guided, and necessitated the operating model. As teams were organized into categories and queues, headcount rose with transaction volume and seniority often reflected the size or complexity of the work a person could personally run.

That model assumed people would execute each step, however today, agents can increasingly perform more of this work themselves. They tirelessly gather requirements, compare suppliers, draft materials, route requests and act within defined limits.

This shifting paradigm now raises questions about headcount. It also raises more difficult considerations about where human commercial judgment adds value once agents absorb high-volume process execution.

Procurement will always own strategic supplier relationships, complex negotiations and market-shaping commercial strategy; the structural change is in what surrounds that work. The function's primary value now moves from executing the process to architecting the decision environment. This means defining up front which decisions an agent can settle on its own, where commercial nuance calls for guidance, and where human expertise has to step in.

What breaks when AI agent pilots scale in procurement

The usual instinct is to treat operating discipline as the brake, and adoption as the accelerator. KPMG's research suggests the relationship is more complicated.

KPMG's AI Quarterly Pulse Survey for Q2 2026 found that the share of organizations orchestrating multiple agents across workflows doubled in a single quarter, from 9% to 18%. As agents move from isolated tasks into connected processes, questions a pilot could handle informally become harder to defer.

Organizations are putting controls in place. In the same survey, 66% report having monitoring dashboards and 61% have approval processes. Only 26% have full, real-time visibility into what their AI costs to operate. Autonomy is increasing faster than the information and decision structures needed to manage it.

For procurement, the practical questions arrive quickly. Who determines what an agent may decide? What commercial and supplier context must it consider? What triggers an exception, where does that exception go and who maintains the rules as conditions change?

Those questions are manageable when a deployment is small. At scale, ambiguity turns into delay, unnecessary escalation, unexpected cost or a growing queue of manual review. Defining the boundaries early costs far less than redesigning a process after agents are already operating inside it.

A global industrial enterprise piloted an autonomous sourcing agent in standard IT hardware. The category constraints were narrow, and experienced category managers informally reviewed edge cases. By every measure the team tracked, the pilot worked.

The problems started at enterprise rollout across a wider range of indirect spend categories. 

With no category-specific decision logic in place, legacy policies took over, including low-dollar approval thresholds calibrated for manual capacity. That produced two costly failures. Thousands of low-risk renewals jammed queues with false-positive escalations. Meanwhile, ambiguous multi-year statements of work with non-standard indemnities went through straight-through processing with no review. When commercial terms drifted, nobody had operational ownership to update the agent's decision parameters.

The organization kept the agent running and codified its decision boundaries. It separated straightforward catalog replenishments from variable-risk services and mapped escalation paths directly into the intake workflow. Manual touchpoints fell by 65%.

What AI governance in procurement looks like

The alternative is an operating model that moves the function from process execution to commercial architecture.

Architecture here means the active engineering of decision rights, done by procurement itself instead of a separate compliance committee. Procurement codifies baseline commercial judgment, sets the limits of what agents can do on their own and reserves scarce human expertise for complex exceptions.

This is an entirely different discipline. Decision rules become enterprise assets that procurement keeps current. They are tested against real volume and owned by category leaders who understand commercial market realities.

Policies written for human approvers do not translate automatically to an actor that operates continuously and never gets tired. Translating them requires procurement to identify the judgment embedded in its processes and make that judgment explicit.

Three requirements for a governed procurement operating model

There are three shifts that define this new operating model.

1. Decision rights are set before deployment

For each process handed to an agent, procurement needs to define what the agent may do autonomously, what it may recommend, what requires a person and what it may never do regardless of confidence. 

Producing that decision map is a practical starting point. The rules need to be precise enough to guide a real transaction.

2. Escalation thresholds are designed for agent volume

A threshold set for a human approver reviewing a handful of requests a day behaves differently when an agent processes hundreds. 

Each threshold needs to be tested against the new volume, speed and risk, and some will need to move. 

Suppliers may feel the consequences before anyone internal does. An agent acting on stale terms or mishandling a renewal can affect a relationship someone spent years building.

3. Agent boundaries have an operational owner, the way a category does

Enterprise governance may establish the organization's overall policies and risk appetite. Procurement translates those parameters into category-specific rules and updates them as supplier conditions, commercial priorities and market dynamics change.

Technology and risk teams remain essential partners, and category expertise still has to come from procurement. The person best placed to determine what "unusual" looks like in indirect services is likely someone who understands the suppliers, terms and commercial dynamics of indirect services.

Done well, this is what lets the function move fast. Clear boundaries cut unnecessary review and make it easier to identify the decisions that genuinely require human judgment. The teams that scale agents most confidently will define and maintain those limits as part of the operating model, before something goes wrong forces a revisit.

The decision engineer and the future of procurement talent

Indeed, this shift changes what procurement fundamentally needs from its people. Three years ago, high-performing procurement professionals were prized for execution discipline, things like managing RFP queues, navigating ERP screens, and shepherding transactions through rigid approval matrices.

In an agentic operating model, procurement talent needs three new strengths:

  1. Decision modeling: the ability to translate commercial intuition, risk appetite and category nuance into precise rule logic.
  2. Agent telemetry and drift management: what takes the data literacy to monitor agent outputs, analyze exception patterns and refine decision boundaries over time.
  3. High-stakes strategic influence: the hours saved on transactional processing go into supplier innovation, complex relationship structuring and cross-functional business partnering.

Example: Governing an AI agent in supplier renewals

Consider an agent handling supplier renewals. 

One renewal stays within agreed terms, falls below an established threshold and involves an approved supplier, so it may be eligible to proceed without individual review. Another includes a price increase above the category limit, or involves a supplier whose risk status has changed since the previous assessment.

In a governed model, that boundary doesn't depend on someone remembering a policy. 

The threshold, category rules and current supplier context are held in the system, and the agent applies them as it works. When it reaches the second renewal, it stops and routes the exception to the right procurement owner with the relevant information attached. Nobody finds out about it later in a report.

In Zip, that context and those controls travel with the work from intake to pay. Procurement's decision rights are enforced at the point where the decision happens, inside the workflow. They don't sit in a separate policy document.

Scaling autonomous agents takes work on both organizational structure and workflow software. 

KPMG advisory services can help procurement organizations design the underlying operating model, from establishing decision rights and calibrating risk-based exception thresholds across categories to restructuring roles around agentic capabilities. 

Zip provides the platform that embeds and enforces those business-defined rules directly in the intake-to-pay workflow, where the work happens.

Build procurement's decision rights into the workflow, so agents act within your category thresholds and send every exception to the right owner, from intake to pay.

Written By
Cesar Suarez and Peder Gustafson

AI procurement orchestration, from intake to pay

Enter your business email to keep reading