Before You Submit in Oracle: IT Software Purchase Guide
Purchasing software at UC San Diego involves more than placing an order. Every new software purchase and renewal must go through a security review, insurance verification, and — in some cases — a privacy review before a Purchase Order can be issued. This page walks you through everything you need to do before you submit your requisition in Oracle.
Why this matters
Submitting an incomplete requisition is the single biggest cause of delays in IT software procurement. On average, 75–80% of submissions arrive missing at least one required document — which means your request is returned, the clock restarts, and your software access is delayed.
Resources
Use these tools to prepare your IT Software submission.
When is a Data or Privacy Review Required?
IMPORTANT
All new software purchases and renewals must undergo an OIA security review, regardless of cost, vendor size, or perceived risk. Software involving UC San Diego data, system access, SSO integration, or payment processing must also be processed through Oracle with completed OIA approval. OIA approval is generally valid for up to three years; however, renewals may require a new review if there are changes to the data scope, system access, data volume, or software functionality. Confirm with your buyer before determining that a new Kuali submission is not required, and involve the ITS Office of Information Assurance early in the process.
When in doubt, ask your buyer first. Loop in the ITS Office of Information Assurance (OIA) early if any of the following apply:
Contract type
- New, upgrade, replacement, or renewal (mid-cycle or new contract)
Support & usage
- Requires ITS Maintenance and Support
- Used by multiple departments, or by students, staff, and/or faculty campus-wide
Data & risk
- Involves any campus data (review depth depends on classification)
- Involves PCI / point-of-sale processing
- Involves financial information
Budget & sourcing
- Budgeted for and purchased through ITS
- Requires an RFP, RFI, or is sole-sourced (>$100K)
Technical footprint
- Integrates with other systems — Activity Hubs, SSO, OFC, Recharge, etc.
- IT Professional Services
- Temp workers doing IT-related work on ITS-supported software
Common examples
- COTS software: Tririga, Maximo, GIS, NetSuite, Transact, Persona
- Custom development: .NET, Java, Python, React
How to Submit in Oracle: A Step-By-Step Guide
Before you submit in Oracle
All new software purchases and renewals require a completed OIA security review before you submit in Oracle. Do not skip to Oracle first. Submitting without the required approvals will result in your requisition being returned.Step 1 — Check if the software is already available at UCSD
Before purchasing anything, check whether the software is an approved campus-wide licensed software.
IT Agreement Suppliers List - If the software is already available, use the existing campus license — it is faster and avoids the full review process.
Instructional Tools - Are you an instructor? The list includes instructional tools that have been approved for use, are not recommended, or are under review. We recommend reading the full review before using any tool. If the tool you want to use is not listed, please contact Dan Suchy of Academic Technology Services (ATS). NEW link: Instructional Tools
Step 2 — Submit a Services & Support Ticket: Pre-Screening Questions
All software purchases must undergo an OIA Security Review. If you choose to use a UC San Diego IT Agreement Supplier or existing paid subscription, you can proceed to Step 9 - Submit your Oracle requisition with all approvals attached.
Pre‑screening questions help Procurement provide temporary guidance, especially when delays could cause service disruption or financial impact.
Submit Your Pre-Screening Responses
To submit your completed pre-screening responses for an IT software purchase:
- Go to the Budget & Finance Portal.
- Under More Specifically, select Software Purchase Pre-Screening.
- Provide complete and detailed responses so Procurement can determine the appropriate next steps and identify any required documents.
What Pre‑Screening Does Not Do:
Pre‑screening does not replace:
- the OIA Third‑Party Vendor Security Review (Kuali)
- the Campus Privacy Intake Form
Departments must still complete all required OIA and Privacy reviews through official processes.
How to Answer Pre‑Screening Questions
These questions determine which reviews your purchase requires. Answer based on the vendor’s actual access to UC San Diego data and systems — not your intent. When in doubt, answer yes.
OIA pre-screening questions:
- Is the software you're purchasing new or a subscription renewal?
- Are you purchasing Software on-premises (the application is hosted on a server within the department or the UCSD data center) OR Software off-site (vendors host it at their location or a third-party site)?
- What UC San Diego data will be provided to or accessible by this vendor? (e.g., student records, financial data, personally identifiable information, health data, payment card data)
- Will the vendor have access to UCSD systems or networks? (e.g., via VPN, API integration, Single Sign-On, or direct login)
- What volume of UCSD data will the vendor store or access? (approximate number of records)
- Does software involve Payment Card Integration or Point-of-Sale integration?
Reminder
This guidance is informational only and does not replace required OIA or Privacy reviews. Departments are responsible for completing all formal review processes.
Step 3 — Gather All Vendor Documents First
If software is not on the list of IT Agreement Suppliers, nor approved Instructional Tools, nor university Software Enterprise, OIA Review is Required.
All new software purchases and all renewals must have a completed OIA security review dated within the last 3 years.
OIA Required documents:
- Supplier Information Security Plan
- Please upload a network or data flow diagram if not included in the plan.
- Evidence the plan is working
- Demonstration that the plan is implemented and working effectively.
- Examples are: HECVAT, SOC 2 Type 2 Report, ISO 270001 certification, HITRUST certification, SSAE 16, FedRAMP certification, and/or 3rd party audit report
- Supplier Incident Response Plan
- Supplier Customer Notification Plan
- Evidence of cyberinsurance coverage
- Data-specific requirements
- If credit card information is in scope, a copy of the Supplier's AOC and a shared responsibility matrix are required.
Supplemental documents - in the case Supplier cannot provide one or more of the required documents above, some supplemental documents may help with the data security review:
- recent penetration test report
- recent vulnerability scan report
- Supplier policies and procedures.
Link: https://security.ucop.edu/resources/for-suppliers.html
Step 4 — Complete the Third-Party Data Security Review
- Visit the Supplier Review Site (login required) to begin the OIA review.
- Do not open the Kuali form until all vendor documents are ready to attach. Missing documents restart OIA’s 30‑day response clock and delay your purchase.
- If the vendor does not provide the required documents within 30 days of OIA’s follow‑up, the case is closed and must be resubmitted from the beginning.
- Respond promptly to all OIA requests.
- Do not submit your Oracle requisition until OIA approval is received.
Step 5 — OIA Recommendation
OIA may require:
- Required minimum cyber liability insurance per Protection Level classification.
- Appendix DS (Data Security addendum) incorporated into the vendor agreement to include one of the following in Appendix DS, Exhibit 2: - The vendor’s System Security Plan (SSP), or - The most recent SOC 2 Type II report
Contact OIA oia-rc@ucsd.edu if you need clarification.
Step 6 — Submit a Campus Privacy Office intake form
Software purchases may also require a privacy review if they process P3 or P4 data, or use AI on any personal data. For more details, please visit the Campus Privacy Office online.
To begin the privacy review, please access the Risk Intake Form.
To save time, if your data falls under P3 or P4, we recommend submitting concurrently with the OIA review.
The Privacy Office may require:
- Appendix GDPR — if the vendor processes EU/UK personal data
Contact ucsdprivacy@ucsd.edu if you need clarification.
Step 7 — Understand the UC data protection level (P1–P4)
University data is classified into four Protection Levels based on the potential impact to UC San Diego if the data were exposed or compromised. Higher levels require stronger security controls, while accurate classification ensures data receives the right level of protection without adding unnecessary compliance steps.
For more information, please visit Data Classification - Four Protection Levels.
Step 8 — Verify cyber liability insurance (COI)
A Certificate of Insurance (COI) is required for all IT software purchases regardless of data classification or review type. The COI must name “The Regents of the University of California” as additional insured. Exact wording is required — no variations are accepted.
Minimum coverage is based on the data protection level and record volume:
| Protection level | Record volume | Minimum coverage (per occurrence) |
|---|---|---|
| P1 | Any | $500,000 |
| P2 | Any | $1,000,000 |
| P3 or P4 | Under 70,000 records | $5,000,000 |
| P3 or P4 | 70,000 or more records | $10,000,000 |
Note: If the vendor cannot meet the required coverage, submit a Contract Review Request to Risk Management before proceeding. Do not submit your Oracle requisition until Risk Management has issued a determination.
Submit a Contract Review Request to Risk Management (Kuali)
Step 9 — Submit your Oracle requisition with all approvals attached
You are now ready to submit in Oracle! Attach all of the following directly in your Oracle requisition before submitting. Do not send documents separately by email.
- Vendor quote, price quote, or Statement of Work (SOW)
- OIA security review written approval notification
- Campus Privacy Office determination — if a privacy review was required
- Certificate of Insurance (COI) — or Risk Management exemption if the vendor could not meet coverage requirements
- SSPR (Sole Source Procurement Rationale) — if applicable
- Three comparable quotes — if applicable
If you have an agreement/order form review & signature request, submit a services & support case ticket; choose:
- Service: Oracle Procurement
- Service Offering: Procurement Forms
- Category: Requesting Document Signature
- Assignment Group: BFP-IPPS-Procurement Support
Step 10 — Oracle requisition
- When submitting your Oracle requisition, Procurement recommends choosing the amount-based form. Reminder: When using the Amount-Based request form, the PO generated will close when the full amount has been invoiced.
- Please choose the applicable Category:
- Software - Download
- Software - Saas /Saas/Cloud
- Complete the entire Oracle requisition form and submit.
- Tip: A complete submission with all documents attached is processed in 1–2 business days. Your assigned IT procurement buyer will contact you only if something additional is needed. Do not resubmit unless you receive a formal return notice.
Data Governance & Data Classification
What is Data Governance?
UC San Diego’s data governance framework defines who makes decisions about data and how those decisions are carried out. It ensures institutional data is properly valued, protected, and used appropriately across privacy, security, access, management, and maintenance.
Council of Data Stewards (CDS)
The CDS oversees campus institutional data. Each data stewards is responsible for a specific domain such as student, HR, financial, or research data and determines the official data classification for that domain.
Data Stewards
Data stewards are campus officials responsible for a specific domain of institutional data (such as student, HR, financial, or research data). They determine the official data classification for their domain and provide guidance to units on how that data must be handled, protected, and used.
Campus Units (Requesting Departments)
Units submitting IT requisitions must know the classification of the data their project will handle and confirm it with the appropriate data steward. Because context of use affects risk, the same dataset may require different controls depending on how it will be used—internal reporting, vendor‑hosted SaaS, integrations, or external sharing.
Why This Matters for IT Software Purchases
Data Classification
UC San Diego classifies all institutional data into four protection levels. The higher the protection level, the more security controls are required. The level assigned to your data determines which security reviews are required and the minimum cyber insurance coverage your vendor must carry.
Data classification directly impacts required security controls, privacy protections, and contract terms. Confirming classification early ensures the solution aligns with UC San Diego’s protection levels and governance standards.
For more details, please refer to the Four Protection Levels.
Procurement Card Use for Software Purchase
Departments may buy software on a P-Card — but only under specific, compliant conditions. Every software purchase, regardless of payment method, must meet UC San Diego's requirements for Information Security, Privacy, Accessibility, Data Use Agreements, and Software Licensing Terms.
P-card purchases of software that involve access to UCSD data, system integrations, or any data classified P2 or above still require the full OIA review process — even if the transaction is below the P-card threshold.
Purchasing software on a P-card to avoid the Oracle and OIA process is not compliant with UC policy and may create security and audit risks for your department. If you are unsure whether a specific software purchase qualifies for P-card use, contact your IT procurement buyer before making the purchase.
🔹 Required Reviews Before You Buy
Confirm these have been initiated or completed before purchasing:
- Office of Information Assurance (OIA) Security Review
- Privacy Review
- IT Security or Technical Assessment
Some purchases may need additional approvals or exceptions depending on data classification, system access, or integrations.
🔹 When P-Card Use Still Requires Full Review
Paying by P-Card does not exempt software from security and privacy review. A full OIA review is still required if the software:
- Accesses or stores UC San Diego institutional data
- Integrates with UC San Diego systems or networks
- Handles P2, P3, or P4-classified data
- Collects or processes personal data on behalf of UC San Diego
This applies even if the purchase amount is below the P-Card threshold.
🔹 Non-Compliant Use of P-Cards
Using a P-Card to bypass Oracle requisitioning or OIA review violates UC policy and can create:
- Security vulnerabilities
- Privacy risks
- Accessibility compliance issues
- Audit findings for your department
Learn more on the Procurement Card Blink Page.
FAQS
What should project teams know before negotiating a software agreement?
Project teams should plan for the following requirements before beginning negotiations:
- Procurement must sign all software contracts; departments and ITS are not authorized to sign.
- A Departmental Security Administrator (DSA) may need to be designated in accordance with UC San Diego requirements.
- Security, privacy, procurement, and contract reviews take time and should be included in the project schedule.
- The vendor must sign the agreement first; UC San Diego does not sign first.
- Prior use at UC San Diego or UCOP does not automatically mean the software is approved for your department’s use case. OIA will confirm whether an existing review applies or whether a new review is required.
- The sensitivity of the data being stored, processed, or transmitted determines the level of review and applicable insurance requirements. More sensitive data generally requires a more detailed review and additional documentation.
For additional guidance, see Engaging Suppliers and Classification of Information and IT Resources.
Who can approve changes to contract documents?
The person or role that approves changes depends on the document. For all documents except Appendix DS, consult the Policy BUS-43 to identify the Policy Exception Authority.
For Appendix DS, consult the CISO. See IS-3, Section III.15.2. Note that an “equivalent” must be approved. The DS checklist should serve as a guide to ensure that all items are covered.
How do we count “records” for cyber insurance purposes?
Records are based on the risk of an adverse event. Typically, records are counted using requirements found in law. The goal is to manage UC risk.
Some examples:
- The number of Workforce Members
- The number of patients
- The number of students
- The number of credit card transactions
- The number of research subjects
- The number of applicants
- The number of guests
- The number of members
- The number of attendees
What are the options for “cyber insurance”?
- Privacy, Technology and Data Security Liability;
- Cyber Liability;
- Technology Professional Liability;
- Technology Errors and Omissions.
Regarding insurance, Locations should also:
- Confirm insurance coverage with all Suppliers;
- Ensure that third-party cyber liability is included;
- Clearly state coverage on the Certificate of Insurance.
What is the purpose of Exhibit 2 to Appendix DS?
Exhibit 2 of Appendix DS allows the Supplier to demonstrate that it manages cyber risk. The Location CISO has considerable flexibility in determining what adequately shows that the Supplier is properly managing cybersecurity risks.
Examples of adequate risk management could be:
- A Supplier Security Plan;
- A SOC 2 Type 2 Report;
- A PCI Report on Compliance (ROC);
- A completed (and reviewed) Higher Education Community Vendor Assessment Tool (HECVAT);
- A Health Information Trust Alliance (HITRUST) Common Security Framework Certification;
- A Statement on Standards for Attestation Engagements (SSAE) No. 16, Reporting on Controls at a Service Organization;
- A FedRAMP Certification;
- A trusted third-party assessment report;
- Some combination of the above.
Can I submit in Oracle while the OIA review is still in progress?
- No. You must receive OIA’s written approval before submitting your Oracle requisition. Submitting before OIA approval is complete will result in your requisition being returned and your timeline restarting from the beginning. The same rule applies to the privacy review, if one is required. Do not submit your Oracle requisition while any required review is pending. The Buyer will return your requisition if lacking OIA review.
What are the most common reasons requisitions are returned?
The most common issues are:
- Missing vendor quote or SOW — required for every submission without exception
- Missing or incomplete OIA security review approval — a Kuali case number alone is not sufficient; the written OIA determination must be attached
- Missing Certificate of Insurance (COI) — or the COI does not name “The Regents of the University of California” as additional insured with exact wording
- COI coverage below the required minimum — thresholds are based on data protection level and record volume; confirm yours before attaching
- Missing vendor security documents — SOC 2 Type II, HECVAT, Incident Response Plan, and Customer Notification Plan are required for all OIA reviews
My vendor doesn't have a SOC 2 report. What can they provide instead?
OIA accepts several alternatives to a SOC 2 Type II report as evidence that the vendor’s security plan is working. Your vendor can provide any one of the following:
- HECVAT (Higher Education Community Vendor Assessment Toolkit — Full or Lite version)
- ISO 27001 certification
- HITRUST Common Security Framework Certification
- FedRAMP authorization
- PCI Report on Compliance — for PCI-related services
- SSAE No. 16 (Statement on Standards for Attestation Engagements)
- A third-party audit demonstrating effective cyber risk management
My vendor can't meet the insurance requirements. Can I still proceed?
You may be able to proceed, but you must take the following steps first. Do not submit your Oracle requisition until this process is complete.
- Submit a Contract Review Request to Risk Management (Kuali)
- Explain why the vendor cannot meet the required coverage limits and why the purchase is still necessary for your department
- Wait for Risk Management to issue a determination — they will either approve an exemption, require additional safeguards, or determine the purchase cannot proceed at the current coverage level
- Attach the Risk Management determination to your Oracle requisition in place of the COI
Risk Management resources on Blink
How long does the entire process take from start to PO approval?
When a submission is complete at intake, standard processing takes 1–2 business days for the buyer review and PO issuance. However, the OIA security and privacy reviews can add time. Plan accordingly:
- Simple purchase (P1/P2, no privacy review): approximately 3–5 weeks total
- Standard purchase (P3, privacy review required): approximately 6–10 weeks total
- Complex purchase (P4, PHI, contract negotiations): 10+ weeks
Starting vendor document collection early — before opening any review forms — is the single most effective way to reduce your timeline.
What is the difference between Software Download versus SaaS/Cloud Software?
|
Concept |
What it describes |
UCSD meaning |
Review impact |
|
Software On‑Site |
Hosting location |
UC controls system + data |
lower risk |
|
Software Offsite |
Hosting location |
Vendor controls system + data |
higher risk |
|
Delivery method |
Installed locally |
On‑site only if no cloud sync |
|
|
Delivery method |
Vendor‑hosted |
Always offsite → OIA required |
What do you need to Negotiate?
Before finalizing a license agreement, discuss these points with your purchasing director or professional buyer:
|
Term |
What's at Stake |
|
Field of use |
Is the software limited to a specific purpose (e.g., research only, not teaching)? |
|
Transfer / sublicense / assignment |
Can others use the software under your license — exclusive or non-exclusive? |
|
Site licenses & archival copies |
Can you install and run it on one machine, or many, simultaneously? |
|
Source/object code access, escrow, proprietary rights |
Can you customize or reverse-engineer it? Who owns any improvements you make? |
|
Export Administration Act |
Will you need to export the software internationally? This is federally regulated. |
|
Version/release |
Do you get upgrades or new releases — and at what cost? |
|
Maintenance, renewal, price protection |
What training or support is included, for how long, and at what price? |
|
Fixes/error correction |
Will you pay extra for bug fixes? |
|
Proprietary rights indemnification |
Is the licensor liable if someone accuses you of infringing their IP? |
Need Help?
- Ask TritonGPT for instant answers
- Browse the Knowledge Base
Contacts
For questions before or during the upstream review process, use the contacts below.
| Stage | Who to contact | How to reach them |
|---|---|---|
| General Questions | IT Procurement Office Hours | Attend office hours |
| Security Review | Office of Information Assurance (OIA) | oia-rc@ucsd.edu |
| Privacy Review | Campus Privacy Office | ucsdprivacy@ucsd.edu |
| Insurance | Risk Management | Bryce Besser |
| Contract Review | Services & Support | https://support.ucsd.edu/services |
| Oracle Status | IT Procurement Buyers | Andrew Bunker; Joy Contemprato |