is-acquisition10 min read

Software Acquisition: Build vs. Buy Analysis

Understand the build vs. buy decision framework and audit considerations that CISA candidates must know for the exam.

CISAPractice|

One of the most significant decisions in IS acquisition is whether to build custom software or buy a commercial off-the-shelf (COTS) product. For CISA candidates, understanding this decision framework and its audit implications is essential because it fundamentally affects project risk, cost, and control.

Build (Custom Development)

Custom development involves designing and building software specifically for the organization's needs.

Advantages of Building

  • Tailored to exact business requirements and processes
  • Full control over functionality, architecture, and future enhancements
  • No dependency on a vendor's product roadmap or support lifecycle
  • Potential competitive advantage from unique capabilities

Disadvantages of Building

  • Higher upfront development costs and longer time to deployment
  • Requires skilled development resources (in-house or contracted)
  • Full responsibility for testing, maintenance, and security updates
  • Risk of project failure, scope creep, and budget overruns

Buy (COTS Products)

Purchasing commercial software involves selecting and implementing a product that is available in the market.

Advantages of Buying

  • Faster implementation timeline compared to custom development
  • Lower initial cost, with development costs spread across the vendor's customer base
  • Vendor provides maintenance, updates, and security patches
  • Proven functionality with an established user community

Disadvantages of Buying

  • May not perfectly fit the organization's unique requirements
  • Dependency on the vendor for support, updates, and product direction
  • Customization may be limited, expensive, or create upgrade complications
  • Vendor viability risk (the vendor may be acquired, change direction, or go out of business)

Decision Framework

The build vs. buy decision should be based on a structured analysis that considers:

  • Strategic Importance: Systems that provide competitive advantage may justify custom development. Commodity functions (such as email or accounting) are typically better served by COTS.
  • Requirements Fit: How closely does the COTS product match the organization's requirements? What gaps exist, and can they be addressed through configuration rather than customization?
  • Total Cost of Ownership: Include all costs over the expected life of the system, encompassing licensing, implementation, customization, integration, training, maintenance, and eventual replacement.
  • Time to Market: If rapid deployment is critical, COTS may be preferred over the longer timeline of custom development.
  • Internal Capabilities: Does the organization have the development skills and capacity to build and maintain a custom solution?

Audit Considerations

IS auditors should assess:

  • Whether a structured analysis was conducted comparing build and buy options
  • Whether the total cost of ownership was calculated for each alternative
  • Whether the decision was approved by appropriate management
  • Whether vendor due diligence was performed for COTS products (financial stability, reference checks, product roadmap)
  • Whether the impact of customization on future upgrades was considered

CISA Exam Tips

The exam may present a scenario and ask which acquisition approach is more appropriate. Focus on understanding the trade-offs: custom development offers flexibility at higher risk and cost, while COTS offers speed and lower cost at the expense of customization. The auditor's role is to verify that the decision was made through a structured, objective process rather than based on bias or incomplete analysis.

Related Tags

IS AcquisitionBuild vs BuySoftware AcquisitionCISA Exam

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free