Banking procurement crisis: why mid-level managers are trapped between survival and success

In brief: Mid-level procurement managers in banking are expected to act as strategic partners while their day-to-day work is still manual data entry, email chains, and disconnected systems. Three pressures have converged: DORA compliance, which has applied across the EU since January 2025 and now faces evidence-based supervisory scrutiny; a heavy administrative load that leaves no room for strategic skill-building; and a widening skills gap. On top of that, poor contract management quietly leaks an estimated five to nine percent of contract value, and static due diligence leaves supplier risk unmanaged. The way out is not incremental improvement but AI-native source-to-contract platforms that shift procurement from reactive firefighting to predictive intelligence, and make compliance systematic rather than a scramble. 

Mid-level procurement managers in banking are being asked to deliver strategic value while their day-to-day reality is manual data entry, endless email chains, and tools that have barely changed in a decade. The title says strategic procurement; the work says otherwise. When costs rise and efficiency targets stall, the manager usually knows exactly why, but explaining it means admitting the department is stretched past its limits.

The underlying problem is a widening gap. External pressures such as regulation, cost scrutiny, and third-party risk have expanded rapidly, while the internal capabilities and systems meant to handle them have stayed frozen in time. The result is a profession fighting tomorrow's challenges with yesterday's tools, and it is not sustainable.

The perfect storm facing banking procurement

Three pressures have converged at once, and none of them is going away.

DORA compliance is no longer on the horizon

The Digital Operational Resilience Act is not future planning. It has applied directly across the EU since January 2025, and it sets out comprehensive requirements for managing ICT third-party relationships across their entire lifecycle: detailed risk assessments, mandatory contractual clauses, and a centralized, auditable register of information. What changed in 2026 is the supervisory posture. Regulators have shifted from reviewing remediation plans to demanding evidence, examining firms for real proof of resilience rather than good intentions.

The uncomfortable reality is that managing third-party risk with spreadsheets and email chains leaves an institution poorly equipped for that level of scrutiny. This is no longer about efficiency. It is about building the systematic, defensible processes that a regulatory audit now expects. When supervisors review those processes, fragmented approaches create audit gaps, and in banking such gaps can define careers.

Administrative overload buries the strategic work

Procurement professionals spend most of their time on low-value administrative tasks rather than strategic ones. Manual data entry, chasing approvals, and switching between systems consume the workday, leaving little room for market analysis, supplier relationship management, or planning.

The stakes in banking are higher than in most industries. Manual data entry carries error rates in the range of half a percent to several percent, and in a financial institution those are not minor slips. They surface as payment disputes, compliance breaches, and operational disruption. And while procurement teams stay buried in administrative work, peers in other functions are spending that same time building strategic capabilities, executive relationships, and a case for their own advancement.

The skills trap closes the loop

Industry research consistently points to a widening skills gap in financial services procurement. Organizations struggle to find people who combine traditional expertise with modern strengths in data analytics, AI, sustainability, and strategic thinking.

The irony is structural. The current workload makes developing those very skills nearly impossible. Managers know what they need to learn, but cannot find the time, because they are kept busy holding broken source-to-contract processes together. The work that would make them more valuable is precisely the work they never reach.

The million-dollar problem hidden in banking contracts

Contract value quietly leaks away

Research from World Commerce & Contracting has long put the loss from poor contract management at roughly five to nine percent of contract value. Auto-renewals lock institutions into unfavorable terms. Obligations buried in supplier contracts go untracked. Savings written into the fine print stay invisible.

For a mid-sized institution with substantial third-party spend, that percentage is a large and preventable number. Leadership wants cost optimization, yet fragmented systems make it almost impossible to capture value leaking through contract mismanagement. Suppliers hold terms they should not, and renewals happen with no renegotiation, but pulling the contract data to prove it is so manual that the opportunity often passes before anyone can act.

Third-party risk is a moving target

Traditional due diligence is a snapshot, but supplier risk in financial services is dynamic. A critical vendor can suffer a cybersecurity breach overnight. New sanctions can drop a key supplier into a high-risk jurisdiction. Financial instability can threaten service continuity without warning. This is exactly why DORA now puts continuous, risk-tiered monitoring of ICT providers at the center of its requirements.

Without real-time monitoring, teams manage risk on outdated information, in an environment where yesterday's safe supplier can become tomorrow's failure. Accountability for risks that cannot be seen coming is not risk management; it is unmeasured exposure.

Strategic expectations, tactical tools

Perhaps the most demoralizing part of the crisis is the mismatch in expectations. Leadership promotes procurement to strategic partner and asks for sophisticated metrics such as total cost of ownership, procurement ROI, and risk-adjusted performance.

Yet the available tools can barely track basic cost savings. The integrated data needed to calculate strategic metrics simply does not exist across fragmented systems. Managers are held accountable for measurements they cannot make with tools they were never given, evaluated on strategic contribution while working with tactical instruments. The expectation is reasonable; the means are not.

Regional pressure: the extra weight on CEE banking

In Central and Eastern European banking, these challenges carry additional weight. In markets like Hungary, where procurement transparency is under intense scrutiny and single-bid contract rates have historically been high, every choice has to be defensible, competitive, and transparent.

At the same time, ambitious ESG mandates from central banks add data-intensive sustainability criteria on top of already complex processes, so teams must track and report supply chain environmental and social metrics alongside traditional cost and quality factors. Here, poor documentation is not just internal inefficiency. It becomes reputational risk that can define careers and institutional standing.

Fluenta Blog CTA - Industry Subpage

Want to learn how to optimize your processes?

Discover our solutions for companies in finance and banking

What transformation actually looks like

The way forward is not incremental improvement. Organizations that adopt AI-native source-to-contract platforms are not only solving today's problems; they are building tomorrow's capabilities. In practice, the shift shows up in three places.

  • From reactive firefighting to predictive intelligence. Instead of managing crises after the fact, teams receive an automated alert that a critical supplier's financial health is deteriorating, complete with alternative sourcing options and mitigation strategies. Problems are seen coming and resolved before they reach operations.
  • From administrative burden to strategic impact. When automation handles the manual work, procurement gains bandwidth for market analysis, supplier innovation partnerships, and data-driven decisions that turn the function from a cost center into a value driver.
  • From compliance anxiety to audit confidence. A modern platform makes compliance systematic rather than an added burden. Every risk assessment, mandatory clause, and monitoring requirement becomes part of the workflow, so DORA readiness is built in rather than bolted on across all five of its pillars, and audits become routine rather than a scramble.

The strategic imperative

The uncomfortable truth is that transformation is no longer optional. The external pressures of regulation, cost, and risk will only intensify. The choice is not whether to modernize but whether to lead that change or be overtaken by it.

The managers succeeding right now are not simply working harder. They have recognized that fighting tomorrow's battles with yesterday's tools is not dedication but self-sabotage. The technology to solve these challenges exists and the business case is clear. The open question is which institutions will champion the transformation that turns these pressures into a lasting advantage, and which will keep fighting a losing battle with inadequate tools.

Standing still is no longer neutral. In a landscape moving this fast, it carries its own risk. The realistic choice is between continuing to absorb the cost of manual processes and building the strategic procurement function the organization actually needs.

Downloadable resource

The Procurement Software Evaluation Checklist helps assess options against the criteria that matter, including process efficiency, cost management, supplier performance, integration, reporting, risk and compliance, and operational resilience. It is available to download here.

Frequently asked questions

Why is DORA such a pressing issue for banking procurement? The Digital Operational Resilience Act has applied directly across the EU since January 2025 and sets comprehensive requirements for managing ICT third-party risk, including risk assessments, mandatory contractual clauses, and an auditable register. In 2026 the supervisory focus shifted from reviewing remediation plans to demanding evidence of resilience, so managing that risk with spreadsheets and email chains leaves an institution exposed during audits.

How much value do banks lose through poor contract management? Widely cited research puts the loss at roughly five to nine percent of contract value, through auto-renewals on unfavorable terms, untracked obligations, and savings buried in contract language. For an institution with substantial third-party spend, that is a large and largely preventable figure.

Why aren't manual processes good enough anymore? Manual data entry carries meaningful error rates, and in banking those errors become payment disputes and compliance breaches rather than minor slips. Manual work also does not scale, and it consumes the time managers would otherwise spend on strategic sourcing, supplier relationships, and skill development.

What does an AI-native procurement platform change? It shifts the function from reacting to problems toward anticipating them, for example flagging a supplier's deteriorating financial health with alternative sourcing options attached. It also makes DORA readiness systematic, building risk assessments, mandatory clauses, and monitoring into the workflow rather than treating them as extra work.

Is this only relevant to large banks? No. While the largest institutions face the most complex obligations, DORA applies to financial entities of every size, and the underlying pressures of cost, risk, and manual overload affect mid-sized banks and their procurement teams just as directly.

Sources

The sooner you start, the sooner you experience the benefits.