Requirement evaluated: Mandatory IT security review for all software/SaaS purchases regardless of amount
For a technology company whose CFO is trying to eliminate maverick software spend, SAP Ariba's Approval Rules engine in the Ariba Buying module directly addresses this requirement. An administrator navigates to Manage > Approval Processes, selects the Requisition approvable type, and configures a rule whose condition evaluates the commodity code field on each line item (represented in Ariba's field path syntax as `LineItems.CommonCommodityCode.UniqueName`). The condition is set to match software/SaaS-specific UNSPSC codes or custom commodity codes, with no amount field included in the condition, so the rule fires on every purchase in that category regardless of dollar value. …
Limitations: The buyer must ensure every software/SaaS request is classified to the correct commodity code at submission time; if a requester mislabels an ad-hoc SaaS purchase under a non-software category (e.g., 'professional services'), the IT security rule will not fire, so governance of the commodity code taxonomy and requester …