Where the four months go
A specialist engineering firm and a global advisory firm usually meet at exactly the right moment and then lose a quarter. The meeting goes well. A partner has a client problem that needs a model built, a data pipeline rebuilt, or a system actually integrated, and the specialist can obviously do it. Then the thread goes quiet and nobody explains why. What happened is that the conversation left the practice and entered three or four other systems, each with its own queue, its own standard of proof, and no reason to hurry. The partner who wants the work and the systems that can pay for it are two different organizations, and only one of them has a deadline.
None of those systems are irrational. A firm with a global audit practice carries independence obligations enforceable against the firm itself. A firm holding federal prime contracts carries flow-down clauses it cannot waive. Any firm that puts a third party near client data owes a professional confidentiality duty that predates your engagement. Every step that feels like friction is somebody's regulated obligation, and knowing which one is being satisfied ends the guessing.
What follows is the path itself: the four doors technical work enters through, what clears before money can move, and in what order. It applies to a Big Four buyer, to a strategy firm of the McKinsey, BCG, or Bain tier, and in modified form to any large integrator sponsoring a new supplier into its own machinery.
Gating power: how likely each step is to stop a purchase outright
Editorial ranking of how often each step ends a purchase rather than delaying it, drawn from published rules and standard supplier processes. Illustrative, not a measured statistic.
Read that as gating power, not a scorecard. The top four can end a purchase outright; the bottom two usually just reschedule it.
Four doors, four different owners
Technical delivery does not enter a large advisory firm through one entrance, and the common failure is knocking at the wrong one. The four doors have different owners, different documents, and cycle times that differ tenfold.
The alliance door. Every major firm runs a published ecosystem program. Deloitte describes more than 150 alliances built over more than 35 years, centered on organizations like AWS, Google, NVIDIA, Oracle, Salesforce, SAP, ServiceNow, and Workday, and McKinsey publishes a comparable ecosystem across the major cloud and model providers. These programs are built around platforms that change what the firm can sell across many clients at once. A services specialist without a product rarely fits.
The engagement door. A partner has a signed or nearly signed engagement and scope the firm cannot staff. This is the door that works for most specialists: a named client, a start date, a sponsor under budget pressure. It is also the only door where the specialist's own speed changes the outcome.
The contingent-labor door. Procurement, or an outsourced managed service provider, buys hours against a rate card through a vendor management system. Fastest route to a first transaction, worst structure for a firm that sells finished systems, because the rate card sets a ceiling that is hard to escape later.
The federal door. The government practice is usually a distinct legal entity holding prime contracts, buying through a subcontracts group under Federal Acquisition Regulation rules. Everything about the paper differs, including who may say yes.
| Door | Who owns it | What gets signed | What ends it |
|---|---|---|---|
| Alliance / ecosystem | An alliance or ecosystem lead, with a capability leader as sponsor | Alliance agreement, joint go-to-market terms, sometimes referral or resale terms | No product, and no client demand already attached |
| Engagement subcontract | The engagement partner, gated by risk, independence, and procurement | Master services agreement once, a statement of work per engagement, then a purchase order | Independence or conflict clearance fails on the end client |
| Contingent labor | A procurement category manager or an outsourced managed service provider | Supplier terms inside a vendor management system, a rate card, timesheets | The work is a deliverable and does not map to a labor category |
| Federal subcontract | The government practice's subcontracts and compliance group | Non-disclosure agreement, teaming agreement, then a subcontract carrying FAR flow-downs | Registration, reps and certs, or cyber posture is not clean |

Independence is the gate with no appeal
This is the single largest structural difference between a Big Four buyer and a strategy firm, and specialists routinely miss it. Deloitte, EY, KPMG, and PwC sit inside firms that audit public companies. That makes them subject to the Securities and Exchange Commission's auditor independence rule at 17 CFR 210.2-01, whose general standard in paragraph (b) is that the Commission will not recognize an accountant as independent if the accountant is not capable of exercising objective and impartial judgment on all issues encompassed within the engagement.
Two parts of that rule reach into a delivery purchase. Paragraph (c)(4), implementing Section 201 of the Sarbanes-Oxley Act, lists non-audit services an accounting firm may not provide to an audit client at all: bookkeeping and services related to accounting records, financial information systems design and implementation, appraisal and valuation, actuarial services, internal audit outsourcing, management functions, human resources, broker-dealer and investment banking, legal services, and expert services unrelated to the audit. The second item is exactly where a data platform or a finance-adjacent machine learning build often lands. Paragraph (c)(3) then bars direct or material indirect business relationships with an audit client or its decision-makers, outside professional services and ordinary consumer transactions.
The practical consequence is counterintuitive. The clearance is mostly not about the specialist. It is about the end client, run against the firm's global audit relationships. A specialist can be excellent, fast, and fully compliant, and the answer can still be no because the firm audits the company the work is for. There is no appeal and no version of the pitch that changes it.
What a specialist can do is ask early and out loud: which client is this for, and has clearance been requested yet. Clearance also comes back restricted rather than binary more often than people expect, meaning the work is permitted with the scope trimmed. Knowing that early lets the scope be written to fit instead of rewritten twice.
Strategy firms are a different animal. McKinsey, BCG, and Bain have no audit practice, so this rule set does not apply to them. Their gate is client conflict, which asks whether serving this client on this subject collides with a commitment elsewhere in the firm. That check is faster, but it is not absent, and it is decided centrally rather than by the partner.
Confidentiality arrives as a contract clause, not a courtesy
A second rule explains a pattern specialists find strange: the non-disclosure agreement and a data-handling exhibit show up before anyone has agreed on scope. Under the AICPA Code of Professional Conduct interpretation on disclosing information to third-party service providers, ET 1.700.040, a member should either obtain specific client consent before disclosing confidential client information to such a provider, or contract with the provider to maintain confidentiality and obtain reasonable assurance that it has procedures preventing unauthorized release.
That is a duty the firm owes its client, discharged through paper with the specialist. It is why the data-handling terms are fixed while the commercial terms are still open, and why offering to pull an extract into your own environment for a quick look is a hard no. The proposal that clears fastest is the opposite one: we work inside your environment or the client's, we take no copies, and here is the control evidence.
What supplier onboarding actually checks
Onboarding is mechanical, and it is the part a specialist controls completely. A firm that assembled the packet once can answer most of it in a day.
- Legal entity and tax identity: exact registered name, state of formation, W-9, and remit-to details matching the entity on the contract. A mismatch between the signing entity and the invoicing entity stalls payment for weeks.
- Sanctions, debarment, and anti-corruption screening, including beneficial ownership disclosure and an anti-bribery attestation.
- Insurance certificates: professional liability, cyber, commercial general liability, and workers compensation, each at the buyer's stated limits. Limits are set by policy and rarely move.
- Security posture with evidence: a SOC 2 Type II report or an ISO/IEC 27001:2022 certificate, with its date. The transition window from the 2013 edition of ISO 27001 closed on 31 October 2025, so a certificate against the old edition no longer counts.
- Data processing terms: where data rests, who has access, subprocessor disclosure, retention and deletion, breach notification timelines, and cross-border transfer terms.
- Intellectual property and personnel terms: assignment of deliverables, background IP carve-outs, and a non-solicitation clause that is standard at this scale.
- Independence questionnaire at audit-affiliated firms, covering your own financial relationships and any services you provide to the firm's audit clients.
- Portal registration and purchase order discipline. PwC, for example, runs a public supplier portal where a prospective supplier registers and submits details about its organization, and states plainly that registering does not guarantee any business will be awarded. Registration is administrative, not a sale.
The last item costs specialists the most money. Work performed before a purchase order exists is work performed at risk, and no sympathetic partner can conjure a PO number that accounts payable will honor after the fact. Get the number in writing before the first hour.
The federal arm is usually a different company
A specialist who assumes the brand and the contracting entity are the same thing will sign the wrong paper. Federal practices are separated, sometimes by legal entity and sometimes by sale. Guidehouse is the clearest case: formed when Veritas Capital acquired PwC's US public sector business in 2018, it absorbed Navigant Consulting in 2019 and Grant Thornton's public sector practice in 2022, then was acquired by the private equity firm Bain Capital for $5.3 billion in a deal that closed on 14 December 2023. What was once part of a Big Four firm is now an independent company with its own vehicles and its own supplier process.
Scale explains the rest. Deloitte reported aggregate global revenue of $70.5 billion for the fiscal year ending 31 May 2025, with a workforce above 470,000. An organization that size has dozens of procurement processes partitioned by entity, geography, and service line, and the sponsor may not know which applies until they ask. Build capability is partitioned the same way. BCG launched BCG X in December 2022 as its tech build and design unit, describing nearly 3,000 technologists, scientists, programmers, engineers, and human-centered designers across more than 80 cities. McKinsey's AI arm, QuantumBlack, joined the firm through acquisition in 2015. These units are the internal competition for any external delivery purchase. A specialist wins that comparison on depth in a narrow domain, speed to a working artifact, or capacity when the internal bench is committed, never on breadth.
Flow-downs and the arithmetic of a pass-through
Once the work is federal, the clause set drives the structure. The clause that shapes how a prime wants a specialist scoped is FAR 52.215-23, Limitations on Pass-Through Charges. The government will not pay excessive pass-through charges, defined as indirect costs or profit and fee charged on work performed by a subcontractor by a contractor that adds no or negligible value, excluding the costs of managing subcontracts and applicable indirect costs. Under the companion provision at FAR 52.215-22, if subcontract effort exceeds 70 percent of total cost, the contractor has to identify the revised amount and verify that it will provide added value, and the contracting officer may examine and audit records to test whether pass-through charges are excessive.
This is why a prime resists being a pure conduit for a subcontractor's hours, and why a specialist scoped as a discrete, managed, acceptance-tested body of work is easier to buy than the same people billed as loose labor. The clause pushes both parties toward the structure the specialist wanted anyway.
Three more mechanics matter to a small delivery firm. Under FAR 19.702, an other-than-small prime submits a small business subcontracting plan on awards expected to exceed the threshold, raised to $900,000 effective 1 October 2025 in the inflation adjustment finalized that 27 August, with $2 million for construction of a public facility; FAR 19.704 requires percentage goals by socioeconomic category, which is the machinery behind the question about your size status. Under FAR 52.232-40, within 15 days of receiving accelerated payments from the government, the prime is to make accelerated payments to its small business subcontractors to the maximum extent practicable, with no fee charged to the subcontractor. And under FAR 44.302, a contracting officer determines whether a contractor purchasing system review is needed when sales to the government are expected to exceed $25 million in the next twelve months, with the Department of Defense threshold at $50 million. That review is why a large prime's purchasing process is rigid: its own approvals depend on documenting that it followed it.
Cyber posture is a gate rather than a discussion. DFARS 252.204-7012 flows down to subcontractors handling covered defense information, DFARS 252.204-7019 and 252.204-7020 put the self-assessment score into the Supplier Performance Risk System where a prime can see it, and the DFARS rule integrating CMMC into contracts took effect on 10 November 2025. One live nuance worth getting right: a Department of Defense class deviation issued in May 2024 kept assessments under 252.204-7012 tied to Revision 2 of NIST SP 800-171 even though Revision 3 has been published, so confirm which revision the flow-down you are handed actually names rather than assuming the newest one.
One caution on citations for 2026. The Revolutionary FAR Overhaul entered its rulemaking phase in June 2026, and agencies are working from model deviation texts that keep being revised. The obligations described here are stable; the part and paragraph numbers may not be. Verify against the deviation text your contracting activity is actually using.
Conflicts of interest are the advisory firm's chronic condition
FAR Subpart 9.5 recognizes three organizational conflict patterns: unequal access to information, biased ground rules, and impaired objectivity. Advisory firms live with the third one permanently, because a firm that advises a program on what to buy has an obvious problem bidding to supply it. That exposure is inherited by anyone the firm adds to a team.
Congress directed a rewrite in the Preventing Organizational Conflicts of Interest in Federal Acquisition Act, enacted 27 December 2022. The FAR Council published a proposed rule on 15 January 2025, comments due 17 March 2025, that would move the coverage out of FAR Part 9 and add new definitions, examples, and clauses. As of this writing it is proposed rather than final, so expect the screening questions to keep broadening without a settled citation to point at.
The practical rule is to disclose adjacent work early and specifically. If your firm supports the same program office in another capacity, or advised on the requirement, say so in the first written exchange. A disclosed conflict gets mitigated. A conflict found by a reviewer three weeks before submission removes you and damages the relationship.
The pricing pressure that changed what is easy to buy
Federal buying conditions for advisory work moved sharply in 2025, and the direction matters. On 27 February 2025, then-acting GSA administrator Stephen Ehikian wrote to agencies naming ten firms — Accenture Federal Services, Booz Allen Hamilton, CGI Federal, Deloitte Consulting, General Dynamics IT, Guidehouse, HII Mission Technologies, IBM, Leidos, and SAIC — stating that based on available procurement data they were set to receive over $65 billion in fees in 2025 and future years, and that this needed to change. Agencies were asked to identify by 7 March which of those contracts they intended to terminate. GSA widened the review to more companies in May 2025, and the responses included terminations and restructuring toward outcome-based arrangements.
Whatever one thinks of the exercise, the effect on buying behavior is real and it favors a particular kind of supplier. A buyer under pressure to show outcomes rather than hours finds a fixed-scope deliverable with written acceptance criteria far easier to defend than an open-ended body of labor. A specialist who prices a working artifact, names what done means, and accepts an acceptance test is selling into that pressure instead of against it.
How the purchase actually moves
The sequence below is the ordering, not a promise about duration. Durations vary by firm, by entity, and by how many steps the specialist has already completed on arrival. The ordering is stable, and two steps run in parallel only if the specialist pushes for it.
The path a delivery purchase follows inside a large advisory firm
Steps three and four are worth attacking. Clearance can be requested on day one instead of day thirty if someone asks. Onboarding is entirely in the specialist's hands, and returning a security questionnaire in hours with complete evidence routinely saves a month.
What makes a specialist easy to buy
Assemble one document and keep it current: exact legal entity name and state of formation, tax identification details, federal registration data if federal work is in scope, insurance carriers and limits by policy, the security attestation with its date and scope, the data-handling defaults, the named people who would do the work with their real availability, and one page on a system your firm built and what it measurably did. That answers most of onboarding without a meeting.
Then bring a scope rather than a rate. A partner deciding whether to sponsor an outside firm through this process is calculating whether the effort is worth it, and a proposal with a deliverable, a duration, an acceptance test, and a price makes that easy. A rate card turns it into a staffing conversation, and those get routed to the contingent-labor door.
Finally, remove work from the sponsor. Track your own onboarding status, flag adjacent engagements before compliance finds them, and ask for the purchase order instead of waiting. Sponsors repeat with the firms that made them look organized, which outlasts being the cheapest name on the list.
The mistakes that stall a promising conversation
Knocking at the alliance door when the work is an engagement subcontract. Alliance programs are built around platforms and move in quarters. If there is a named client and a start date, the engagement partner is the buyer and the alliance team is a detour.
Asking the partner to move procurement. They cannot, and the request signals inexperience. The useful ask is different: who owns supplier onboarding here, and can we start it in parallel now.
Starting on a verbal go-ahead. Enthusiasm from a partner is not a commitment the finance system recognizes. Without a purchase order, the invoice has nowhere to land.
Redlining the master agreement on terms that never move. Insurance limits, the non-solicitation clause, and the data-handling exhibit are policy at this scale. Spend the negotiating capital on scope boundaries, change control, and payment timing, where there is real room.
Offering to take the data. A specialist who volunteers to copy client data into their own environment has created the exact confidentiality problem the firm's rules exist to prevent. Propose working inside their environment first.
Answering security slowly. The questionnaire is the one place a specialist can visibly outperform much larger competitors, and most do not.
Bottom line
Buying technical delivery inside a large advisory firm is a regulated sequence wearing the appearance of a relationship. The partner supplies the demand. Clearance decides whether the work is permissible at all, and that turns on the end client rather than on you. Confidentiality rules decide how the data can be touched, onboarding decides how fast the paper moves, and the purchase order decides when work legally begins. A specialist who arrives with the packet assembled, a scope instead of a rate, early disclosure of adjacent work, and same-day responsiveness on security has removed nearly every reason to stall. The rules are public and the sequence is knowable; the differentiator is being easy to put through it.
Frequently asked questions
Because the firm audits public companies and its independence is judged against the SEC rule at 17 CFR 210.2-01. Paragraph (c)(4), implementing Section 201 of Sarbanes-Oxley, prohibits categories of non-audit services to an audit client, including financial information systems design and implementation; paragraph (c)(3) restricts business relationships with audit clients. The clearance turns on who the end client is, not on the subcontractor's qualifications, and there is no practical appeal.
Not the same ones. Firms of the McKinsey, BCG, and Bain tier have no audit practice, so the SEC auditor independence rule does not apply to them. They run client-conflict checks, which ask whether serving this client on this subject collides with existing commitments, plus confidentiality review. That is usually faster, but it is decided centrally rather than by the partner who wants the work.
Because the buyer owes its client a confidentiality duty independent of your engagement. The AICPA interpretation at ET 1.700.040 directs a member either to obtain specific client consent before disclosing confidential client information to a third-party service provider, or to contract with the provider for confidentiality with reasonable assurance that controls exist. The paper has to precede the data, and the scope conversation depends on seeing the data.
You can, and you will be working at risk. Large buyers match invoices to purchase orders, and an invoice without a PO number generally cannot be paid no matter who authorized the work verbally. Get the PO number in writing and confirm the entity name on it matches the entity that signed the agreement.
The entity, the clause set, and the approver all change. Federal practices are frequently separate legal entities buying through a subcontracts group under FAR rules. Expect flow-downs including subcontracting plan obligations under FAR 19.7, pass-through limitations under FAR 52.215-22 and 52.215-23, Section 889 representations, and for defense work DFARS 252.204-7012 with a Supplier Performance Risk System score. FAR part and clause numbering is in motion during the 2026 overhaul, so confirm citations against the deviation text in use.