Australian Government Architecture
Search

Guide to procuring cloud services

View more Cloud policy guidance.

On this page

About this guidance

This guidance helps agencies meet requirement 2 of the Whole-of-government cloud computing policy: Entities must leverage contemporary cloud technology to empower innovation, including Artificial Intelligence.

This guidance sets out a whole-of-life approach to procuring cloud services, from early planning and market engagement through to contract management, transition and exit.

It helps agencies navigate layered contracts and supplier arrangements while maintaining value for money, security, resilience and service quality.

Who this guidance is for

This guidance is for people involved in planning, funding, approving, procuring, delivering, operating and reviewing cloud services.

The guidance sets out a pathway for different roles involved in cloud procurement:

  • Accountable executives are expected to sponsor the procurement approach, approve investment and risk decisions, confirm that unresolved risks have clear owners, and ensure the service supports agency outcomes, security, continuity and value for money.
  • Delivery and program teams are expected to define business and operational requirements, coordinate input from procurement, legal, finance, cyber security and technical experts, manage procurement activities, and maintain evidence that supports decisions across the service lifecycle.
  • Operational and specialist teams are expected to assess technical, commercial, legal, security, privacy, data, records management and service management requirements, identify dependencies and risks, and confirm that the arrangement can be operated, monitored, supported, transitioned and exited effectively.

When to use this guidance

Use this guidance when planning, procuring, renewing, extending or reviewing cloud services.

It should be applied before market engagement, during procurement activities and negotiations, and before contract finalisation. It can also be used when reviewing existing arrangements, assessing supplier performance or planning transitions between services.

How to procure cloud services effectively

Effective procurement begins with a clear process: define the need, bring the right expertise together, test the market, assess options and risks, negotiate suitable terms, and retain a clear decision record.

Technical, commercial, legal, cyber security, finance and business experts should be involved early enough to influence requirements, market engagement and contract negotiations.

What to include

Procurement documentation should capture the matters needed to support an informed and accountable decision, including:

  • the service scope and agency requirements
  • the supplier and supply-chain model
  • applicable terms, obligations, costs and residual risks
  • assurance, performance, continuity, transition and exit arrangements
  • decision owners, approvals and review points.

Key procurement considerations

Effective cloud procurement brings together multidisciplinary expertise to assess service suitability, contractual terms, supply chain dependencies, security and compliance obligations, commercial risks and exit arrangements, while leveraging government experience and procurement channels to support informed and accountable decision-making.

When procuring cloud services, agencies should consider the following areas:

Bring the right expertise together

Cloud procurement involves specialised terminology, architectural trade-offs and commercial risks. Agencies should maintain close collaboration with technical, legal, commercial, cyber security, privacy, records, finance and other subject matter experts. Multidisciplinary input helps identify risks early and supports better procurement outcomes.

Understand all applicable terms

Procurement teams should review all applicable agreements, including end-user licence agreements, online service terms, acceptable use policies and ancillary vendor terms. These terms may operate alongside, or in some cases override, the primary contract. Agencies should identify any non-negotiable or overriding terms early, including service suspension rights, unilateral service changes, data use provisions, audit limitations, liability caps and dispute resolution mechanisms.

Learn from government experience

Agencies can strengthen their approach by reviewing prior procurement activity on AusTender and consulting with other agencies. This helps identify negotiation outcomes, common risks, lessons learned and areas where standard supplier terms may or may not be flexible.

Understand the supplier model

Agencies should confirm whether they are contracting directly with the software provider or through a reseller, integrator or managed service provider. The procurement process should clarify how responsibilities, liabilities, assurances and escalation pathways are allocated across each party.

Confirm what is being procured

Many suppliers include additional software, services or embedded offerings by default in their contracts. Agencies should seek a clear view of everything being procured, including whether these services add to costs over time, contribute to lock-in or create other implications, such as security, privacy or operational risks.

Test negotiability during market engagement

Early market engagement helps agencies understand where suppliers may offer flexibility and where standard terms are unlikely to change. Agencies should use this phase to test commercial, technical, security, data, transition and exit requirements before commitments are made.

Assess platform and service suitability

Before selecting a cloud service, agencies should document how the proposed platform or service meets business, security, privacy, data, compliance, supply chain and operational requirements. This assessment should consider data sensitivity and classification, hosting requirements, data location, provider and subcontractor access, shared responsibility arrangements, lifecycle compliance obligations, operational support needs and the workforce capability required to manage the service.

Agencies should ensure that, where applicable, the hosting of security-classified information and data up to PROTECTED is provided by a service provider certified under the Hosting Certification Framework. The assessment should also consider relevant PSPF requirements and ASD guidance.

The assessment should create a clear decision record that explains why the platform or service was selected, what residual risks have been accepted, what controls are in place, and how those controls will be reviewed over time.

Assess dependencies across the supply chain

Where cloud services rely on underlying platforms, subcontractors, resellers or embedded services, agencies should understand how many agreements are involved and how obligations flow through the supply chain. This supports better visibility of risk, assurance, service continuity and accountability.

Protect information, records, FOI and privacy obligations

Where cloud services involve contractors holding agency information or records, agencies should ensure contractual arrangements support access to, and management of, documents needed to meet information management obligations, freedom of information obligations and the Australian Privacy Principles. This includes agency information or records held by subcontractors or in supplier-managed systems.

Plan for exit and transition early

Exit and transition should be considered during procurement, not deferred to the end of the contract. Agencies should explore exit rights, data migration support, pricing changes, transition assistance and service continuity during sourcing and negotiation.

Understand government procurement channels

Government procurement channels, including the Cloud Marketplace on BuyICT, may shape the options and commercial settings available to agencies. Agencies should understand how panel arrangements, catalogue listings and reseller models may affect procurement.

Procurement readiness checklist

Agencies should use the following procurement readiness checklist before market engagement and again before contract finalisation.

The checklist represents recommended better practice and can be used as a readiness gate where procurement decisions affect security, data, records management, continuity, exit arrangements or whole-of-life costs.

Procurement readiness gate What agencies should confirm before proceeding Evidence agencies should maintain
Multidisciplinary readiness review Technical, legal, commercial, cyber security, finance and business experts have reviewed the procurement approach before market engagement and before contract finalisation. Review records, expert input, unresolved risks, decision record and accountable owner.
Supplier model The agency understands whether the service is contracted directly, through a reseller, integrator or managed service provider, and how responsibilities flow through the arrangement. Supplier model map, roles and responsibilities, liability position, assurance dependencies and escalation pathways.
Applicable terms All end-user licence agreements, online service terms, acceptable use policies, ancillary vendor terms and overriding provisions have been identified and reviewed. Contract review showing applicable terms and any non-negotiable or overriding provisions.
Platform and service assessment The proposed platform or service has been assessed against business, security, privacy, data, compliance, supply chain and operational requirements before commitments are made. Platform assessment record, data classification and hosting assessment, shared responsibility assessment, residual risk decision, control review approach and decision record.
Dependencies Underlying platforms, subcontractors, embedded services, additional software and provider dependencies are visible and assessed before commitments are made. Dependency assessment and assurance approach.
Security obligations Cyber security, assurance, incident reporting, access control, logging, data protection, shared responsibility, vendor risk, supply chain risk and foreign ownership, control or influence risks are addressed before contract finalisation.

Security requirements, assurance evidence, shared responsibility assessment, vendor and supply chain risk assessment, foreign ownership, control or influence risk assessment, incident reporting obligations, unresolved security risk record and accountable owner.

Refer to Home Affairs’ Protective Security Policy Framework and Australian Signals Directorate Information Security Manual for security requirements.

Data and records obligations The arrangement supports information management, FOI, privacy, data access, retention, deletion and records obligations throughout the service lifecycle. Contract clauses, data handling requirements, records access arrangements, retention and deletion approach and accountable owner.
Exit and transition Exit rights, data migration support, transition assistance, pricing changes, termination obligations and service continuity are addressed during sourcing and negotiation. Transition plan, exit obligations, data migration plan, continuity approach, cost assumptions and review trigger.

Any unresolved commercial, legal, security or operational risks should be documented and assigned to an accountable decision owner before launch.

Related links

More cloud policy guidance

Was this information helpful?

Do not include any personal information. We are unable to respond to comments or feedback. If you would like a response, please email, or phone us. Our details are on the AGA contact page www.architecture.digital.gov.au/contact-us.