ryanwold.net

A civic-minded citizen seeking the singularity

Back to Entries

Rating public sector vendor performance

Series: Civics
draft
Date: 2026-05-07

Yes — there are both legal constraints and significant room for improvement.

Public agencies absolutely can evaluate vendors, developers, consultants, contractors, and integrators. In fact, they are supposed to. But many procurement systems are structurally weak at:

  • preserving institutional memory,
  • sharing performance information,
  • and enforcing accountability across jurisdictions.

That creates a recurring pattern:

text bad implementation → cost overruns → change orders → political embarrassment → staff turnover → weak postmortem → same vendor wins elsewhere

Especially in ERP, EHR, civic tech, infrastructure IT, and consulting.


Legally: yes, vendors can be rated

Most public entities already maintain some combination of:

  • contractor performance evaluations,
  • debarment/suspension lists,
  • responsibility determinations,
  • references,
  • litigation history,
  • liquidated damages,
  • corrective action notices,
  • and audit findings.

Federal contracting has systems like:

  • CPARS (Contractor Performance Assessment Reporting System),
  • SAM exclusions,
  • past performance scoring.

States and cities often have weaker/localized variants.

So legally, performance assessment is normal.


Why it often fails

1. Fear of litigation

Agencies fear:

  • defamation claims,
  • bid protests,
  • retaliation,
  • procurement challenges.

So evaluations become sanitized:

text "Vendor generally met expectations."

instead of:

text "Project failed due to repeated staffing instability, missed milestones, and poor requirements discipline."


2. Staff turnover destroys memory

A city may:

  • suffer through a failed implementation,
  • lose the project manager,
  • lose the CIO,
  • lose the procurement lead,

and five years later:

  • nobody remembers.

Institutional amnesia is enormous in government.


3. Procurement focuses on compliance, not outcomes

Many procurement systems optimize for:

  • fairness,
  • process legality,
  • documentation,
  • anti-corruption controls,

rather than:

  • actual delivery quality,
  • maintainability,
  • operational outcomes.

This is understandable historically — procurement law evolved heavily around preventing favoritism and corruption.

But the side effect is:

  • lowest bidder dynamics,
  • checkbox compliance,
  • and weak operational accountability.

4. Vendors specialize in procurement gaming

Some firms become extremely skilled at:

  • proposal writing,
  • certifications,
  • incumbent relationships,
  • staffing optics,
  • change-order economics.

Meanwhile agencies often:

  • under-scope projects,
  • lack technical evaluators,
  • or lack independent architecture review.

This creates asymmetric sophistication.


Existing formal recourse

There are mechanisms.

Formal mechanisms include:

| Mechanism | Purpose | | -------------------------------- | ------------------------------- | | Cure notices | Formal warning | | Termination for cause/default | Remove contractor | | Liquidated damages | Financial penalties | | Withholding payment | Enforcement | | Performance bonds | Financial protection | | Debarment/suspension | Ban future contracting | | Litigation | Recover damages | | Audit findings | Oversight/public record | | Inspector General investigations | Fraud/waste review | | Grand jury reports | Local government investigations |

But many are:

  • politically painful,
  • slow,
  • expensive,
  • risky,
  • or avoided.

The deeper issue: no shared public reputation layer

Private markets have:

  • Yelp,
  • GitHub reputation,
  • AWS reviews,
  • Gartner,
  • references,
  • open-source credibility,
  • developer communities.

Public procurement often lacks:

  • interoperable operational reputation systems.

That means: a vendor can fail in one city and quietly reappear elsewhere.


What could improve this constructively?

This is where your thinking around:

  • civic registries,
  • operational transparency,
  • machine-readable governance,
  • and public accountability systems

becomes extremely relevant.

A modern approach could include:


1. Structured implementation postmortems

Every major project should publish:

text budgeted cost actual cost timeline variance staff turnover scope changes uptime adoption metrics maintenance burden security findings technical debt lessons learned

Not blame theater. Operational learning.

Like aviation incident reporting.


2. Public vendor performance registries

Imagine a machine-readable cross-jurisdiction database:

text vendor project type agency budget variance schedule variance resident impact security incidents maintenance quality references audit findings

Not simplistic star ratings. Operational history.

This would radically improve procurement intelligence.


3. Independent technical review boards

Especially for:

  • ERP,
  • EHR,
  • cybersecurity,
  • cloud migrations,
  • AI systems.

Many public failures happen because: decision-makers cannot independently validate vendor claims.

An external architecture review layer helps enormously.


4. Open-source reference implementations

One huge structural problem: cities repeatedly buy custom implementations of commodity systems.

Open-source civic infrastructure changes leverage:

  • procurement becomes integration/support,
  • not reinvention.

This can dramatically reduce:

  • lock-in,
  • opaque change orders,
  • and vendor dependency.

5. Procurement memory systems

One underexplored idea:

Treat procurement history as a longitudinal civic memory problem.

Cities need:

  • durable institutional memory,
  • reproducible histories,
  • searchable implementation outcomes,
  • public lessons learned.

This aligns closely with your repeated themes:

  • Git-like histories,
  • append-only operational records,
  • civic registries,
  • structured accountability.

Important caution

There are real risks.

Poorly designed rating systems can become:

  • politicized,
  • retaliatory,
  • captured,
  • defamatory,
  • biased toward incumbents,
  • or hostile to smaller vendors.

So a healthy system needs:

  • evidence-based reporting,
  • standardized metrics,
  • due process,
  • response rights,
  • auditability,
  • and contextual nuance.

The most important shift

The biggest improvement is probably not: “rate vendors harder.”

It is:

move procurement from document-centric compliance toward observable operational outcomes.

Meaning:

Instead of asking:

text Did they submit the right paperwork?

Ask:

text Did the system improve service delivery sustainably?

That is a fundamentally different governance philosophy.

By Ryan Wold · © 2026 Ryan Wold

Licensed CC BY-NC 4.0. AI training requires a license — machine-readable terms.

Tip: $afomi on HandCash · afomi@handcash.io