Skip to main content
DoneThat

AI Adoption GuideITSelect

Selection decision audit trail

LLM generates a structured, audit-ready decision memo documenting scoring rationale, alternatives considered, and risk acceptance.

IT processPlanSelectDeployProvisionSupportUpgradeReplaceRetire

By Don, DoneThat’s AI coach · updated

What the audit trail memo is for

A selection decision audit trail is a structured memo that records why a shortlist survived scoring, what alternatives were weighed, and which risks the organization accepts before contract. It is not the award. It is the evidence package a governance or sourcing lead can hand to internal audit, legal, and the executive sponsor without reconstructing six weeks of email.

The memo answers three questions in plain language: what was evaluated, how each option scored against documented criteria, and what remains unresolved at decision time. Every substantive claim should trace to a row on the vendor shortlist scoring engine output or to a fact stated in the RFP, vendor response, or reference notes. When the source does not contain the fact, the field stays empty. The committee still decides. Nothing in the memo auto-awards a vendor or fabricates a risk acceptance the business never recorded.

Platforms such as ServiceNow, Archer, SAP Ariba, and Coupa often hold workflow state, approval chains, and attachment stores. They do not replace the narrative that ties a score to a decision. Your audit trail memo is that narrative, written so a reader who was not in the room can follow the logic.

Inputs the memo must cite

Before drafting, load the artifacts the selection actually used. At minimum:

  • The finalized score sheet with criterion weights, evaluator inputs, and computed rankings or tier placements
  • RFP sections that defined mandatory requirements and evaluation rubrics
  • Vendor proposals and clarification responses referenced during scoring
  • Reference or peer input captured during diligence, if it influenced scores or risk flags
  • Any TCO or commercial model outputs that affected the comparison

Cross-check commercial assumptions against the total cost of ownership calculator export if TCO drove a criterion or tie-break. Pull contract and liability themes from contract risk extraction when risk acceptance lines depend on proposed terms, not on scoring alone. If reference calls changed how evaluators interpreted a capability claim, tie those notes to the relevant criterion through peer review and reference mining rather than paraphrasing from memory.

The memo structure should mirror how governance reads risk: executive summary, alternatives considered, scoring summary with row-level cites, open issues, and explicit risk acceptances only where a named approver has stated them.

Drafting the memo from your score sheet

Work criterion by criterion, not vendor by vendor hype sheet. For each scored requirement, draft one memo line that states the outcome and cites the source.

Illustrative pattern (fictional names, no metrics):

Identity governance integration (weight 12%): Vendor A met the mandatory SAML and SCIM requirements per RFP §4.2; score sheet row ID-03 = 4/5 based on documented connector list in proposal p. 14. Vendor B scored 2/5 on the same row (ID-03 = 2/5) because the response described a roadmap item without a committed delivery date. Vendor C was not evaluated on this row; listed as not shortlisted after mandatory gate failure on data residency (score sheet row DR-01, blank numeric score, gate = fail).

Notice what this does: it names the criterion, points to a score sheet row or RFP section, and describes alternatives in the same breath. It does not declare a winner. It does not invent a risk acceptance for Vendor B's roadmap gap; that gap becomes an open issue unless someone with authority has already accepted it.

Repeat for each material criterion and for mandatory gates. Summarize alternatives considered in a short table or bullet list that matches the shortlist actually scored, including options eliminated before scoring if governance expects that visibility.

For risk-related lines, only document acceptance when you have a recorded statement: approver name or role, date, and the specific risk language they accepted. If legal has not signed off on uncapped liability or a missing SLA, the risk acceptance field remains empty and the issue list carries the item forward.

When a line stays blank

Empty fields are a feature, not a drafting failure. Leave a memo line blank or mark it TBD when:

  • The score sheet row exists but no evaluator entered a value
  • The vendor response did not address the requirement and no clarification was obtained
  • TCO or contract analysis was not completed for that option
  • Risk acceptance was discussed informally but not recorded in the approval system

Do not backfill blanks with plausible-sounding rationale. Internal audit treats invented narrative worse than an explicit gap. If the committee must decide with incomplete evidence, the memo states what is missing and what decision is being requested anyway.

Similarly, do not convert a high score into an award recommendation. A row cite explains how an option was measured; it does not trigger selection. Wording like "therefore we select Vendor A" belongs in a separate committee resolution, not in the audit trail body.

Committee review without auto-award

The committee's job is to ratify, redirect, or defer based on the evidence package. Circulate the draft memo with the score sheet and source attachments so members can click from summary line to underlying row or RFP fact.

A productive review agenda covers four items:

  1. Scoring integrity: Do row cites match the score sheet evaluators signed? Any criterion scored without documentary support?
  2. Alternatives: Were all in-scope options represented, including incumbents and build alternatives if the charter required them?
  3. Open issues: What blanks or conflicts remain, and who owns closing them before signature?
  4. Risk acceptances: Which items require explicit acceptance, and are those fields populated from real approvals only?

If the committee directs a re-score or additional clarification, update the score sheet first, then regenerate the memo lines affected. The audit trail should reflect the final scored state, not a draft that never synced.

Record the committee outcome in the governance system of record. The memo remains the rationale artifact; the resolution records the decision. Keep both linked by selection ID or project code so downstream contract work in SAP Ariba, Coupa, or similar tools can attach the same bundle.

Failure modes that invalidate the trail

Three patterns routinely undermine audit readiness. Catch them in peer review before submission.

Rationale with no row cite. A paragraph that says "Vendor A offers stronger security" without pointing to SEC-02 or an RFP mandatory clause is opinion, not audit evidence. Rewrite until every evaluative sentence has a cite or is clearly labeled as committee judgment recorded in the resolution.

Treating the memo as the award. Publishing the memo to vendors, or wording it as a final selection notice, collapses governance steps and creates procurement exposure. The memo supports decision; it does not execute it.

Inventing risk acceptance. Stating that "the business accepts Vendor B's limitation on audit rights" when no approver said so creates false comfort and legal exposure. Leave the field empty and list the item under open issues until acceptance is documented.

Secondary failures include stale cites after score sheet revision, mixing proposal claims with verified reference findings without distinction, and listing vendors that were never in the scored shortlist. Each is fixable by reloading inputs and regenerating affected sections.

A disciplined audit trail memo makes selection defensible: scored, cited, honest about gaps, and separated from the moment the committee actually chooses.

Is this worth automating for you?

Whether this pays back depends on how much time it takes your team today. Most teams estimate that from memory, and the estimate is usually wrong in one direction or the other.

DoneThat reconstructs where the time actually went, with no timers to forget, so you can measure the baseline before committing to a project and check the gain afterward.

Measure the baseline first