[Entm-researchstaff] Software, SaaS & Cloud Purchases: Use the Approved Process

William Sutton bill.sutton at ucr.edu
Fri Aug 28 15:15:55 PDT 2026


Hello All

I’m not sure if everyone received or took notice of the email (BELOW) from
Asirra on Tuesday the 22nd with the subject line *“Software, SaaS & Cloud
Purchases.”* I wanted to highlight the key points, as these requirements
will affect how we handle software and related purchases going forward.



Effective immediately, *any type or form of software that is purchased must
be processed through the Oracle purchasing system.* We can no longer use
the ProCard for these purchases, nor can we reimburse individuals for
purchases made in this category. All software-related purchases must go
through *Campus Procurement and ITS* for review, vetting, and approval.



*What you need to do*

Before a requisition can be created, you will need to work directly with
ITS to obtain the required approval. Please start by using the following
ITS request form  Information Security Consultation
<https://ucrsupport.service-now.com/ucr_portal?id=sc_cat_item&sys_id=c0ecbe881ba7b300c675dac9bc4bcb6b>



When completing the request, use the dropdown menu to elect *“Software or
Vendor Risk Assessment,” *Because ITS will require specific information
about the software, vendor, and intended use, *the requester will need to
work directly with ITS to provide the necessary information and obtain
approval.*



Once ITS approval has been obtained, you can reach out to *Gian or me,* and
we can assist with creating and processing the requisition through Oracle
using the approval from ITS.





I also confirmed that these requirements are fairly broad and may
include *website
hosting, data hosting, SaaS services, and similar services*—essentially,
anything that falls within the software, SaaS, or cloud services category.



Please keep this process in mind before making any software or related
purchases. *Do not make the purchase personally with the expectation of
reimbursement.*



Thank you.

*Bill Sutton*

*Procurement Supervisor 2*

*University California Riverside*

*170 Entomology*

*Riverside, CA  92521*

*Phone: 951-827-5704*

*Fax:  951-827-3086*









*From:* Oraclefinancials-depttransactors <
oraclefinancials-depttransactors-bounces at lists.ucr.edu> *On Behalf Of *Asirra
Suguitan via Oraclefinancials-depttransactors
*Sent:* Tuesday, August 25, 2026 4:11 PM
*To:* oraclefinancials-depttransactors at lists.ucr.edu
*Cc:* bfsfinance bfsfinance <bfsfinance at ucr.edu>; Dewight F. Kramer <
dewightk at ucr.edu>
*Subject:* [Oraclefinancials-depttransactors] Software, SaaS & Cloud
Purchases: Use the Approved Process



Dear Campus Community,

Before purchasing software, Software-as-a-Service (SaaS), cloud services,
cloud storage, subscriptions, or other technology, departments must follow
the approved Procurement and ITS review process.

Procurement Services is experiencing an increase in software and technology
requisitions that must be returned because the required ITS security review
has not been completed. To help avoid delays, departments should determine
whether a Vendor Risk Assessment (VRA) is required before submitting an
Oracle requisition for technology that may access UCR data or connect to
the UCR network.

A VRA is UCR’s due-diligence process for evaluating the security, privacy,
and operational risks associated with third-party software, services, and
hardware. The review helps ensure that vendors handling UCR institutional
data or connecting to the UCR network meet UC information security
requirements.

Following the required process helps prevent duplicate purchases,
data-security risks, unauthorized commitments, and delays in issuing a
purchase order.
Before You Buy

   1. *Check for an existing solution.* Review the ITS Software Catalog
   <https://its.ucr.edu/faculty-staff-software> and existing campus or UC
   agreements for an approved site license, enterprise agreement, or
   previously vetted option.
   2. *Complete any required ITS review.* If the product or supplier is not
   listed, submit an ITS Software Request/VRA Intake
   <https://ucrsupport.service-now.com/ucr_portal?id=sc_cat_item&sys_id=c0ecbe881ba7b300c675dac9bc4bcb6b>
   as early as possible. Any required VRA must be completed and approved
   before a purchase order can be issued.
   3. *Route the purchase through Procurement Services.* Software, SaaS,
   and cloud or storage services must be submitted through Oracle Procurement,
   regardless of dollar amount.
   4. *Do not use a workaround.* A Procurement Card (PCard), personal
   funds, or another payment method may not be used to bypass required
   Procurement and ITS review.
   5. *Use the correct coding.* Select the appropriate Oracle Purchasing
   Category
   <https://docs.google.com/spreadsheets/d/1cvwoqkp5fceEK51vOjqy___fXjMBmcQ9zlXvLxovyXE/edit?usp=sharing>
   for the software or technology purchase.

Commonly used software/technology purchasing categories:

·         Cmpt Hardware Maint License [546050]

·         Cmpt ProgramSys Dev Non Cap [546000]

·         Cmpt Software Maint License [546020]

·         Cmpt Software Non Inventory [546010]

*Reminder:* For complex, multi-year, or multi-payment software purchases,
request and attach a pro forma invoice from the supplier.

School of Medicine departments should follow the School of Medicine IT
Procurement <https://somit.ucr.edu/it-procurement> process.

Do not assume a product is approved because another department or UC
location uses it. Renewals may also require reevaluation based on
applicable security, privacy, and risk requirements.
Additional Resources

   - Software Purchasing Guidance
   <https://procurement.ucr.edu/ptp/specific-purchases#software>
   - Recorded Session 4: Purchase Orders & Software — VRA Overview
   <https://youtu.be/DdFzuPVUZfA?si=qLuRYBqrS2_FhlQc&t=1350>

Thank you for engaging Procurement Services and ITS early and helping
protect UCR’s systems and data.

Sincerely,


*Jeremy Meadows*Chief Procurement Officer | Procurement Services
University of California, Riverside

*Dewight F. Kramer *
Chief Information Security Officer | Information Technology Solutions
University of California, Riverside

[image: ucr-logo-email]
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.ucr.edu/pipermail/entm-researchstaff/attachments/20260828/12b08596/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image002.png
Type: image/png
Size: 12023 bytes
Desc: not available
URL: <https://lists.ucr.edu/pipermail/entm-researchstaff/attachments/20260828/12b08596/attachment-0001.png>
-------------- next part --------------
_______________________________________________
Oraclefinancials-depttransactors mailing list
Oraclefinancials-depttransactors at lists.ucr.edu
https://lists.ucr.edu/mailman/listinfo/oraclefinancials-depttransactors


More information about the Entm-researchstaff mailing list