Security or vendor risk review
Owned by information security or IT. Usually a standard questionnaire, frequently queued behind other reviews already in progress. This is the step most often underestimated and the one most easily started early.
Legal review and negotiation
Owned by legal, internal or external. Duration is driven by the number of redline cycles rather than by any single clause, and each cycle carries waiting time at both ends.
Procurement approval
Owned by the procurement function. Checks that policy has been followed, that alternatives were considered where required, and that commercial terms are acceptable.
Supplier onboarding
Creating you as a vendor in their systems: bank details, tax documentation, compliance declarations. Frequently forgotten and capable of adding a week or more on its own.
Purchase order
Required by many organisations before any invoice can be paid. A contract signed without one can still leave the seller waiting.
Signature
By someone with authority at that value. Authority is banded almost everywhere, and a contract requiring a signature two levels above the project sponsor introduces a person with no context and other priorities.