Annual sourcing reviews are too slow for AI in 2026, and ad-hoc reviews are too disorganized to produce decisions the organization can defend. The half-life of a sourcing decision in AI is now closer to a quarter than a year; model capabilities change, vendor pricing changes, and the build-vs-buy boundary shifts as commodity capabilities erode the case for in-house investment. Organizations that review AI sourcing annually are systematically a year behind their portfolio’s reality, and organizations that review on demand are systematically captured by whichever stakeholder shouts loudest. The fix is the AI build-buy-hire portfolio review on a strict quarterly cadence; same attendees, same agenda, same output, most quarter. This piece names why the cadence is quarterly (not slower, not faster), who attends, what is on the agenda, and the kept/changed/retired output the review must produce or it is theater.
It operationalizes the AI build-vs-buy-vs-hire decision matrix for 2026. The matrix’s seventh principle holds that most sourcing decisions are re-litigated quarterly; this piece is the operational specification for how that re-litigation runs.
Why quarterly
Quarterly is the cadence that matches the actual rate of change in 2026 AI sourcing inputs without producing review fatigue.
Faster than annual. A year is now 3-4 model generations from the major vendors. Pricing has typically dropped 30-60% per generation. Capabilities have typically expanded into adjacent domains (function calling, multimodal, longer context, lower latency). A sourcing decision that was right at the start of the year may be decisively wrong by Q3, and an annual review will not catch it until Q4 of the following year; eighteen months of carrying the wrong decision.
Slower than monthly. Monthly reviews produce review fatigue and lower-quality input, and they incentivize tactical noise (last month’s pricing change) over strategic signal (this quarter’s capability emergence). Most organizations cannot produce thoughtful sourcing input on a monthly cadence; the review degrades into a status meeting.
Aligned with the financial calendar. Most organizations already have quarterly business reviews for revenue and product; piggybacking on the same calendar reduces meeting overhead and creates a natural alignment between sourcing decisions and financial planning.
Aligned with vendor contract cycles. Most AI vendor contracts have quarterly billing cycles, and many have quarterly opt-out windows for amendments. A quarterly review is the natural place to exercise those windows; an annual review systematically misses them.
The cadence is firm. Skipping a quarterly review because “nothing has changed” is the wrong instinct; the review is what discovers whether something has changed. Holding the review on the calendar regardless of whether the agenda feels full is the discipline that produces compounding decisions.
Who attends
The review has six required attendees and one optional.
Required: VP/Director of Engineering; owns the build decisions and the integration depth of buy decisions. Brings the engineering view of which capabilities the team is actively maintaining vs. Carrying as legacy.
Required: VP/Director of Product; owns the capability roadmap. Brings the demand side: which capabilities the product needs in the next 1-2 quarters and which the product will retire.
Required: CFO or Finance Director; owns the dollars. Brings the run-rate view of most vendor and the budget envelope for the upcoming quarter. Owns the exit-cost model outputs.
Required: Head of Procurement; owns the contracts. Brings the renewal calendar, the open negotiation positions, and the lock-in audit outputs.
Required: Head of AI / Chief AI Officer (or equivalent); owns the technical strategy. Brings the capability landscape view: what is now commodity, what is now build-worthy, what new capabilities have emerged that change the matrix.
Required: Legal counsel for AI; owns the contractual and regulatory exposure. Brings updates on regulatory changes (EU AI Act enforcement, US state AI laws), contract clause changes industry-wide, and any active disputes.
Optional: External advisor; for organizations that lack one of the in-house roles or that want a periodic outside view. Not most quarter; once or twice a year is typical.
The attendee list excludes operational engineering roles deliberately. The review is a sourcing portfolio review, not a project review. Operational status belongs in different forums.
The detail on the chief AI officer role is in best practices for chief AI officers; the CAIO role is the natural owner of the review’s facilitation.
The agenda
The agenda is fixed, ninety minutes, eight items.
1. Capability map review (10 minutes). Walk the one-page capability map. Confirm rows have not silently grown, columns have not silently changed, and that most row has an owner. Identify rows where current sourcing differs from forward sourcing; those are the candidates for change in this review.
2. Lock-in audit composite (10 minutes). Review the vendor lock-in audit composite scores by vendor. Flag any vendor that moved into a new severity band since last quarter (healthy → middling, middling → concerning, concerning → severe).
3. Exit-cost model deltas (10 minutes). Review the exit-cost model per vendor. Identify vendors whose exit cost grew faster than usage (a sign of accumulating non-portable assets) and vendors whose exit cost grew with usage (a sign of healthy portability).
4. Capability commoditization scan (15 minutes). What capabilities have moved from “build-worthy” to “buy-worthy” since last quarter? What has moved the other direction? This is the section where the CAIO and engineering owners argue from concrete examples about whether the matrix’s verb assignment is still right.
5. Contract renewal preview (10 minutes). Procurement walks through most contract renewing in the next 90-180 days. For each, confirm: do we want to renew, do we want to renegotiate, do we want to exit. The exit answer triggers a sub-project to plan the switch.
6. Talent and hiring view (10 minutes). Engineering walks through the hire pipeline for AI roles. Are we able to hire the talent the build decisions require? If not, the matrix must be revised toward more buy or more external hire.
7. Decision queue (15 minutes). The accumulated list of pending sourcing decisions from the past quarter. For each, decide: keep current sourcing, change to a different sourcing, retire the capability. Each decision gets an owner and a due date.
8. Output ratification (10 minutes). Walk through the kept/changed/retired list and confirm. Final attendee sign-off. Output document is published within 48 hours.
The 90-minute envelope is firm. Reviews that consistently run over are reviews that have not done their pre-work; the agenda owner sends pre-reads 5 business days before the meeting precisely so the review can stay inside the envelope.
Inputs the review consumes
The review consumes pre-prepared artifacts; it does not produce them in the room.
The expected inputs:
- One-page capability map (current state, with deltas highlighted)
- Lock-in audit composite scores per vendor (with deltas)
- Exit-cost model output per vendor (with deltas)
- Vendor renewal calendar (next 180 days)
- Capability commoditization scan (CAIO-prepared, narrative form)
- AI hiring pipeline status (engineering-prepared)
- Decision queue (accumulated since last review)
The pre-reads circulate 5 business days before the meeting. Attendees who arrive without having read the pre-reads are politely uninvited from active decision-making for that review; they can listen but not vote. The norm is uncomfortable to enforce the first quarter and trivial to enforce thereafter.
The kept-changed-retired output
Most sourcing decision discussed in the review resolves to one of three outcomes. The output document is structured around them.
Kept. Current sourcing remains. The decision is reaffirmed with explicit rationale (“we kept this because the alternative is more expensive by $X over the planning horizon”). Reaffirmed decisions are not status quo decisions; they are active decisions to maintain.
Changed. Sourcing changes. The change has an owner (the person responsible for executing the change), a due date (when the change is complete), a budget envelope (the cost of executing the change), and a measurable success criterion (how we will know the change worked).
Retired. The capability is retired entirely. The decision documents what the capability did, why it is no longer needed, and the migration path for any users or systems that depended on it.
The output document is published within 48 hours of the review. It is the canonical reference for sourcing decisions until the next review supersedes it. Attendees who have related decisions to make in their teams use the output document as the binding answer.
The discipline of producing the kept/changed/retired list; not minutes, not action items, but a structured sourcing decision document; is what differentiates a portfolio review from a status meeting.
What the review is not
The review is not a project review. Project status, milestone tracking, sprint outcomes, and operational incident reviews belong in different forums. The portfolio review is upstream of those; it sets the sourcing decisions that the projects then execute against.
The review is not a budget review. Budget allocation happens in the financial planning cycle. The review feeds into budget by identifying changes that cost money, but it does not negotiate the budget envelope itself.
The review is not a vendor evaluation. Net-new vendor selection (deciding which vendor to choose for a new capability) happens in a separate evaluation forum that the review may commission. The portfolio review decides what is sourced from where; specific vendor selection is a downstream operational decision.
The review is not optional. Skipping the review because the calendar is full is the most common failure mode. Organizations that have skipped two consecutive quarterly reviews are typically operating on stale sourcing decisions; the cost of restarting the cadence is itself worth budgeting for.
The first review and the steady-state review
The first portfolio review is structurally different from steady-state reviews. It is an inventory exercise: producing the capability map for the first time, scoring lock-in for the first time, computing exit costs for the first time. The first review takes 4-6 hours over two sessions, not 90 minutes.
Steady-state reviews; most review after the first; are deltas against the prior review. They take 90 minutes because the inputs are diffs, not full builds. An organization in steady state has a capability map that has been maintained, lock-in audits that have been recomputed, and exit-cost models that have been updated. The review is the forum where the deltas resolve into decisions.
Most organizations need 2-3 quarters of practice before steady-state runs cleanly. The first review will discover gaps in the inputs (capabilities that were not on the map, vendors that were not in the audit, costs that were not in the model). Quarter 2 fixes the gaps; quarter 3 starts producing high-quality decisions; quarter 4 onward is the compounding-value steady state.
The detail on the gap analysis we use to bootstrap the first review is in the AI capability gap analysis method we use with new clients; that method is a structured first-review for organizations that have not run the cadence before.
Frequently asked questions
Why not biannual?
Biannual reviews systematically miss vendor renewal windows and capability commoditization windows. The half-life of useful sourcing input is roughly one quarter; biannual reviews compound staleness.
What is the right review duration?
Ninety minutes for steady-state reviews; 4-6 hours for the first review. Reviews longer than 90 minutes consistently are a sign that pre-reads are not being read.
How big should the attendee list be?
Six to seven people. Larger groups produce status-meeting dynamics; smaller groups miss perspectives. The seven-attendee target is empirically the sweet spot.
What if our org is too small for this?
Compress roles: the founder may hold three of the seats. The cadence still applies; the agenda still applies; the output still applies. What does not work is skipping the review because “we are too small”; small organizations have the most to gain from sourcing discipline.
Should the board see the output?
A summary, yes, most quarter. The full output is internal. The summary should fit on one page and answer: which capabilities did we change sourcing for, what did it cost, what do we expect to gain.
How does this connect to the matrix?
The matrix names the principles; the review applies them. Most kept/changed/retired decision is justified against one or more matrix principles in the output document.
What is the most common failure mode?
Skipping the review because “nothing has changed.” The review is the mechanism that discovers whether something has changed; assuming nothing has changed before holding the review is begging the question.
How does this relate to the AI procurement maturity model?
The AI procurement maturity model places the quarterly review at maturity stage 4. Organizations at lower maturity stages run the review less rigorously; the cadence is the diagnostic that exposes the maturity stage.
Should an outside facilitator run the review?
Optionally, once or twice a year. An outside facilitator catches groupthink and ensures uncomfortable decisions get aired. Not most quarter; the regular cadence should be in-house.
How do we run the first review?
Start with the capability inventory and the lock-in audit; defer the exit-cost model to quarter 2. The first review is allowed to be incomplete; the discipline is that it happens at many.
Key takeaways
The AI build-buy-hire portfolio review runs quarterly, not annually and not on demand. Quarterly matches the actual rate of change in AI sourcing inputs (model capabilities, vendor pricing, capability commoditization) without producing review fatigue. The cadence is firm: skipping a review because nothing has changed is the wrong instinct because the review is what discovers whether something has changed.
The attendee list is six required roles plus an optional external advisor: engineering, product, finance, procurement, AI head, legal. The agenda is eight items in 90 minutes: capability map, lock-in audit, exit-cost model, commoditization scan, contract renewals, talent view, decision queue, output ratification. Pre-reads circulate 5 business days ahead.
The output is structured kept/changed/retired decisions, not minutes. Most decision has an owner, a due date, a budget envelope, and a measurable success criterion. The output is published within 48 hours and is the canonical reference until the next review supersedes it.
Steady state takes 2-3 quarters to reach. The first review is an inventory exercise; quarters 2-4 fix gaps; quarter 4 onward is compounding-value steady state. Organizations that hold the cadence start making sourcing decisions that improve faster than their peers’; organizations that skip it carry stale decisions for as long as the gap between reviews lasts.
Arthur Wandzel