
Why Adopt a Platform-Based Approach to Generative AI for Enterprise Success?
Raghavendra Prasad
•
Nov 15 2024
Deepa Krishnan
•
Sep 25 2026
Contract leakage and maverick spend are two different procurement challenges. This comparison shows where each occurs, their common causes, how they appear in ERP systems, and how Scorpio’s Workplace Compliance Agent (WCA) helps detect them through continuous procurement monitoring.
Most procurement teams talk about contract leakage and maverick spend as if they were the same problem wearing two names. They are not. One happens inside a contract that everyone agreed to. The other happens outside the contract entirely. Treating them as a single category is why so many compliance programs catch neither.
This piece breaks both into their actual component parts, the way they show up in a spend ledger rather than the way they are described in a policy deck.
Contract leakage is value lost on spend that is already under contract. The supplier is approved, the pricing is agreed, and the terms are signed. The loss comes from what happens after signature: rebates never claimed, price escalators never checked, obligations never enforced.
Maverick spend is different. It is purchasing that happens outside the approved contract altogether, with an unapproved supplier, through an unapproved channel, or after a contract has expired. There is no negotiated term being violated, because there was never a term in play for that purchase.
The World Commerce & Contracting research group, in a 2026 report produced with Ironclad, found that organizations lose an average of 11% of contract value after signature, and cautioned that the real number is likely higher, since most organizations do not formally track leakage at all. Separately, The Hackett Group's benchmark study on maverick spend found that organizations lose up to 16% of negotiated savings when stakeholders buy outside preferred channels. Two different mechanisms, two different numbers, and two different fixes.
Volume rebates, tiered discounts, and early-payment terms that were negotiated into the contract but never claimed because no one tracked whether the triggering conditions were met. According to WorldCC, missed savings from poor negotiation follow-through are among the single largest contributors to leakage, accounting for two to three percent of lost contract value on their own.
A scope change agreed over email, a quantity adjustment approved verbally on a call, a service level quietly renegotiated at the account level. None of it makes it back into the master contract or the ERP record, so the organization keeps paying against terms that no longer reflect reality.
Contracts that auto-renew at last year's, or a supplier-favorable, rate because no one flagged the renewal window in time to renegotiate. WorldCC identifies renewal costs from poor forward planning as another two to three percent of lost value, on par with missed savings and unauthorized changes.
Index-linked pricing clauses, currency adjustment terms, and cost-escalation formulas that exist in the contract but are never independently checked against what the supplier actually invoices. WorldCC places unmanaged clauses and overpayment from untracked price adjustments at one to two percent of lost value each, alongside penalties and disputes from missed obligations.
A buyer purchases from a supplier procurement already uses, but outside the negotiated contract, at list price, missing the discount tier entirely. This is the most common and the most invisible form of maverick spend, because the supplier's name on the invoice looks correct.
Purchases made by a department or an individual with a company card or a direct vendor relationship, entirely outside procurement's visibility. Software and professional services are the most common categories, since a single manager can subscribe to a tool or engage a consultant without a purchase order.
Two or more smaller purchases made to stay under an approval threshold that would otherwise trigger procurement review, and one-off “urgent” purchases that bypass sourcing on the promise that the process will be fixed retroactively. It rarely is.
A contract lapses, and the buying relationship continues on whatever terms the supplier proposes, because no one flagged the expiry date before it passed. This is maverick spend that started as compliant spend and drifted into it unnoticed.
The two taxonomies above share a common root cause: the data needed to catch each one lives in a different system. Contract terms live in a CLM or in a shared drive. Purchase orders live in the ERP. Invoices live with accounts payable. Supplier master data is rarely reconciled across any of them. A three-way match between contract, PO, and invoice can catch some of this, but only if it runs continuously and understands the entities well enough to know that “Acme Corp” on one invoice and “ACME CORPORATION LTD” on another are the same supplier.
Most compliance monitoring today is a quarterly spot-check, a sample of transactions, or a manual audit triggered after the loss has already compounded for a year.
Scorpio's Workplace Compliance Agent, WCA, is built to run the three-way match continuously rather than periodically. It maps contract terms to actual purchase orders and invoiced spend, and flags price variances, quantity overruns, unauthorized suppliers, and off-contract buying as they happen, not at the next audit cycle.
Because WCA sits on top of the same enriched, normalized data layer that unifies supplier and category records across ERPs, it can catch the version of maverick spend that hides in plain sight: a known supplier billed under a slightly different name, a purchase order raised against an expired contract, a threshold-split pair of invoices submitted two days apart. It also tracks contract utilization and supplier compliance scoring over time, so a renewal window or an unclaimed rebate does not depend on someone remembering to check.

Contract leakage and maverick spend fail for opposite reasons: one is a contract that stops being enforced, the other is spend that never enters a contract at all. A single taxonomy that lumps both together produces a single, vague fix. Two taxonomies, each mapped to where the loss actually originates, produce two fixes that a compliance program can actually run.