alt
Mor Cohen-Tal August 13, 2026

The Compliance Bill Nobody Budgets For

Post image

A few months ago, we watched an organization’s internal build for intake and orchestration burn through roughly $20,000 a week in engineering and compliance overhead, and it still hadn’t reached feature parity with the off-the-shelf platforms it was supposed to replace. Not $20,000 total. $20,000 a week, every week, with no finish line in sight.

That number sticks with us because it’s not an outlier. It’s what the math predicts once you understand what an intake and orchestration platform actually is in a regulated business. And right now, more regulated companies than ever are deciding to find that out the hard way.

Mor Cohen-Tal
By Mor Cohen-Tal, Co-Founder & CTO, Opstream
Co-Founder and CTO of Opstream, previously Cloud CTO at Turbonomic (acq. IBM for nearly $2B) and holds 8 patents in cloud and AI infrastructure.
View LinkedIn profile →

Why does “just build it” feel so tempting right now?

AI coding tools changed the calculus on building software in-house. An intake form, an approval chain, a couple of integrations, maybe a chatbot layered on top: two engineers with a Claude or Copilot license can stand that up in a couple of sprints. A project that used to require a funded, 12-to-18-month initiative now looks achievable before the quarter closes. It’s no surprise that “let’s just build it” is having a moment, even inside insurance carriers, banks, and pharma companies that would never say the same thing about, say, their claims system or their drug safety database.

That’s the gap. The tool got dramatically easier to build. The obligations attached to that category of tool didn’t get any lighter. If anything, 2025 and 2026 have been the busiest stretch in a decade for regulatory attention on exactly the kind of system this is: one that touches vendor onboarding, compliance attestations, approval trails, and increasingly, AI agents making or influencing decisions inside that workflow.

An intake and orchestration platform was born as internal tooling. It graduates, almost immediately, into a system of record. Nobody sends the memo when that happens.

Gartner Research

“AI use cases in procurement can be categorized as defend, extend, and upend. Most procurement use cases fall into defend and extend, which typically do not justify building AI from scratch.”

“The blend-AI approach on an S2P solution should be the default approach for most procurement organizations as it ideally combines the best of the build and buy approaches.”

Source: Gartner, “When to Buy, Build or Blend AI for Procurement,” Magnus Bergfors, 23 April 2026.

What risk do you absorb when you build instead of buy?

The classic build-vs-buy argument is about time, money, and feature parity, and it’s a fine argument. But leading with it in a regulated industry is a mistake, because it invites the easy rebuttal: “we have great engineers, we’ll get there eventually.” Maybe you will. That’s not really the point.

Here’s the sharper version: when you buy an orchestration platform from an established vendor, you’re buying independently attested controls, contractual indemnification, and a compliance function whose full-time job is tracking regulatory change on your behalf. When you build it yourself, you keep all of that. Every bit of it. With no external validation, no shared liability, and nobody else’s compliance team keeping pace with the rulebook for you.

Buying transfers and shares risk. Building means you’re now the vendor, the auditor, and the party on the hook if it’s wrong, all at once, without any of the infrastructure that job actually requires.

Gartner Research

“AI-driven orchestration transforms procurement from a collection of disconnected processes into a unified, intelligent function that delivers governance, compliance, and speed.”

Source: Gartner, “Unlocking New Sources of Procurement Value With AI,” Chaithanya Paradarami, 26 March 2026.

What do regulators actually require from these systems?

You don’t need a single sweeping regulation to make this case. The pressure is already there, industry by industry, and it’s more concrete than most people expect.

Insurance

NAIC’s Model Bulletin (adopted by ~24 states + D.C.) requires a written AI governance program regardless of build-or-buy. Colorado’s Reg 10-1-1 assumes a “vendor selection” step in the lifecycle. A homegrown system has no equivalent, so the insurer originates and documents every control itself, then still signs the annual attestation.

Banking

The 2023 Interagency Guidance (OCC, Fed, FDIC) assumes risk gets managed through vendor contracts, audit rights, and indemnification. Build it in-house, and every lifecycle stage still applies, examined the same way, with zero contractual risk transfer anywhere in the chain.

Pharma & Life Sciences

Systems touching GxP activity must be validated under 21 CFR Part 11. Every material change, a new field, a workflow tweak, an updated model, can trigger re-validation. It’s a tax on every future change, and a DIY build pays it alone, every time.

Scope Carefully

A note on DORA and the EU AI Act. Both are real, and both are severe where they apply. DORA reaches EU-licensed subsidiaries; the EU AI Act’s high-risk obligations reach AI used to underwrite or price risk for EU residents, with obligations phasing in through August 2026 and penalties up to 7% of global turnover. But neither is a blanket US obligation, and it would be dishonest to pretend otherwise. Where they apply, they’re one more compliance apparatus a DIY build has to construct from scratch. Where they don’t, they’re not the reason to avoid building in-house.

Gartner Research

“S2P failures commonly come from underestimated integration complexity, weak data foundations, and governance mechanisms that are assumed rather than explicitly engineered.”

“AI value depends on data and governance readiness: As S2P platforms become increasingly AI-enabled, value realization depends on robust data foundations, explainability standards, and governance models.”

Source: Gartner, “Leverage the 5Cs Framework for a Successful Source-to-Pay RFP Process,” Katarzyna Fonteyn et al., 10 April 2026.

Can a DIY platform pass a SOC audit?

Everything above involves some amount of regulatory interpretation. This part doesn’t.

SOC 1 attests to controls relevant to a service organization’s impact on its customers’ financial reporting. Any system touching purchase orders, invoicing, spend approvals, or contract value is exactly the kind of system your own financial auditors are going to ask about. SOC 2 attests to security, availability, processing integrity, confidentiality, and privacy, and enterprise procurement and vendor-risk teams now routinely require it before they’ll sign a contract at all. Under the AICPA’s own CC9.2 criteria, a company’s SOC 2 audit requires it to assess and manage the risk of every vendor and business partner in its environment, continuously, not as a one-time checkbox.

A homegrown intake and orchestration system has none of that. There’s no external auditor. There’s no independent attestation process, because nobody built one around it. That creates two separate problems, and they point in opposite directions.

Upward, toward your own auditors and examiners: when your SOC 2 renewal comes up, or a state insurance examiner or bank examiner asks for evidence of control effectiveness over the system managing vendor and compliance data, “we built it and we trust it” isn’t evidence. Independent attestation is the entire point of a SOC report. Self-attesting your own internal tool doesn’t close that gap, it just restates it.

Downward, toward your own customers and partners: if the businesses you sell to run vendor risk assessments on you, and this system is in scope, there’s now a documented control gap with no report to hand over. Retrofitting a homegrown system to SOC 2 Type II readiness after the fact means rebuilding access controls, change management, and logging into something never designed against those controls, then paying for and passing an external audit, then doing it again every year after that. That’s not a one-time cost. It’s a new permanent line item, and it’s one a vendor’s actual customers get to split across their entire customer base. A DIY build carries it alone.

If you remember one line from this post, make it this: ask your own auditor whether “we built it and we trust it” would satisfy them. You already know the answer.

How much does compliance maintenance really cost?

This is where the compliance argument and the plain old cost argument meet, and it’s worth spelling out because it’s the part everyone underestimates.

In a regulated environment specifically, “maintenance” means something heavier than bug fixes: re-validation every time a GxP-adjacent workflow changes, updated model documentation every time a state’s AI rules move (the NAIC’s own AI Systems Evaluation Tool is already in a 12-state pilot as of March 2026), refreshed technical documentation every time the EU AI Act’s phased obligations advance, re-attestation every time NYDFS or a state DOI updates its expectations. None of that is optional. It’s compliance maintenance, and it never stops, because the regulatory floor keeps moving under the system you already built.

60–80%
of total lifetime software cost is ongoing maintenance, not development
27%
average cost overrun on IT projects (Gallup); 1 in 6 overrun by 200%
45%
of AI-generated code tested introduced exploitable security flaws
2.74×
more vulnerabilities in AI-generated code vs. human-written code

There’s also a newer wrinkle specific to how these systems are getting built in 2026: fast, and with AI doing a lot of the typing. That’s not a knock on AI coding tools in general. It’s a specific problem for a system that’s about to sit in the middle of vendor onboarding and compliance data: the same tooling that made the DIY build fast is documented, independently, to make it less secure by default.

Gartner Research

“Without private GenAI-driven automation, procurement faces: Productivity stall-out… Heightened intellectual property (IP) and data security risk (employees turn to public tools, increasing uncontrolled data exposure).”

Source: Gartner, “Elevating Procurement Performance Through GenAI Fluency,” Andrea Greenwald, Lynne Phelan, 2 March 2026.

Run all of that forward and the $20,000-a-week number from the top of this post stops looking like a horror story and starts looking like exactly what the data predicts. For a deeper look at the financial case, try the Opstream ROI calculator to model the numbers for your organization.

When does building in-house actually make sense?

To be fair about it: not everything in a regulated company needs to clear this bar. An internal tool that never touches a regulated decision, never handles vendor or policyholder PII, and never feeds a compliance attestation is a genuinely different risk category. Build that one. Ship it fast. Nobody’s auditor is going to ask about your team’s internal Slack digest bot.

The line isn’t build versus buy in the abstract. It’s whether the system in question is going to end up inside the perimeter regulators, examiners, and your own auditors already care about. An intake and orchestration platform, almost by definition, is.

What should you ask before greenlighting a DIY build?

It isn’t “can our engineers build this.” Increasingly, the honest answer is yes, they probably can, at least a first version. The question that actually matters is: who audits this system, who’s indemnified if it’s wrong, and who’s tracking the next twelve months of regulatory change on our behalf, so we don’t find out about it from an examiner.

That’s the product a vendor is actually selling in this category.

Not just the software. The compliance infrastructure wrapped around it, the independent attestation that backs it, and the team whose full-time job is making sure it still passes muster next year, and the year after that. Building it yourself doesn’t make that job disappear. It just moves it onto a team that didn’t sign up to do it forever.

Key Takeaways

Building an intake and orchestration platform is faster than ever, but the compliance obligations attached to it haven’t gotten lighter.
The real argument against building isn’t cost. It’s who holds the liability, who provides independent attestation, and who tracks regulatory change on your behalf.
Insurance (NAIC), banking (OCC/Fed/FDIC), and pharma (21 CFR Part 11) each impose compliance obligations a DIY build must shoulder alone.
There’s no SOC report for a homegrown system, and retrofitting one is a permanent line item, not a one-time fix.
Gartner recommends a “blend” approach for most procurement AI: buy the platform, customize on top of it, and let the vendor carry the compliance infrastructure.

Frequently Asked Questions

What compliance obligations apply to a DIY procurement platform?

A homegrown intake and orchestration platform must meet the same regulatory requirements as any commercial vendor system. In insurance, NAIC’s Model Bulletin requires a written AI governance program regardless of build-or-buy. In banking, the 2023 Interagency Guidance (OCC, Fed, FDIC) applies the same lifecycle risk management expectations to internal builds. In pharma, systems touching GxP activity must be validated under 21 CFR Part 11, with every material change triggering re-validation. Where applicable, DORA and the EU AI Act impose further obligations with penalties up to 7% of global turnover.

Can a homegrown procurement system pass a SOC 2 audit?

Not without significant retrofit work. SOC 2 covers security, availability, processing integrity, confidentiality, and privacy. A DIY intake platform has no external auditor and no independent attestation process by default. Retrofitting it to SOC 2 Type II readiness means rebuilding access controls, change management, and logging from scratch, then paying for and passing an external audit every year.

How much does it cost to maintain a custom procurement platform in a regulated industry?

Industry data shows that 60 to 80 percent of total lifetime software cost goes to ongoing maintenance, not initial development. In regulated environments, maintenance includes re-validation for every GxP-adjacent workflow change, updated model documentation as state AI rules evolve, refreshed technical documentation for EU AI Act obligations, and re-attestation for each regulatory update. One organization tracked roughly $20,000 per week in engineering and compliance overhead before reaching feature parity.

When does building a procurement platform in-house actually make sense?

Building makes sense for internal tools that never touch a regulated decision, never handle vendor or policyholder PII, and never feed a compliance attestation. The critical distinction is whether the system will end up inside the perimeter that regulators, examiners, and your own auditors already care about. An intake and orchestration platform, almost by definition, does.

What should you ask before greenlighting a DIY procurement build?

The question is not whether your engineers can build it. The question that matters is: who audits this system, who is indemnified if it is wrong, and who is tracking the next twelve months of regulatory change on your behalf. Gartner research confirms that most procurement AI use cases do not justify building from scratch, and recommends a blend approach that combines commercial platforms with custom features for the best ROI.

About the Author

Mor Cohen-Tal
Mor Cohen-Tal
Co-Founder & CTO, Opstream

Mor Cohen-Tal is a visionary technology leader and the Co-Founder and Chief Technology Officer of Opstream, an intelligent procurement orchestration platform that is transforming the way companies buy. With a career marked by a relentless pursuit of innovation, Mor has earned 8 patents for her groundbreaking work. As a leading thought leader in cloud and AI, Mor plays a critical role in cultivating partnerships with leading cloud providers such as AWS and Microsoft Azure, and has presented and keynoted at conferences around the world, including Microsoft Ignite and AWS re:Invent. Mor holds an M.Eng from Cornell University and a B.Sc from the Hebrew University.

Connect on LinkedIn →

Want to see how Opstream handles compliance for regulated industries?

Get a walkthrough of the platform, the attestation infrastructure, and the compliance coverage your auditor will actually accept.

Book a Meeting

References

1. Gartner, “When to Buy, Build or Blend AI for Procurement,” Magnus Bergfors, 23 April 2026.

2. Gartner, “Unlocking New Sources of Procurement Value With AI,” Chaithanya Paradarami, 26 March 2026.

3. Gartner, “Leverage the 5Cs Framework for a Successful Source-to-Pay RFP Process,” Katarzyna Fonteyn, Chaithanya Paradarami, Alex Brady, Micky Keck, 10 April 2026.

4. Gartner, “Elevating Procurement Performance Through GenAI Fluency,” Andrea Greenwald, Lynne Phelan, 2 March 2026.

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved. Gartner does not endorse any vendor, product, or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

Want to see how it works?

Book a demo with our team or reach out at support@opstream.ai