Three news items, no adjectives
In June 2026, Bucharest Airports National Company signed the design contract for the new Otopeni terminal: a 176,000 sqm terminal sized for 30 million passengers by 2040, under a contract spanning 10.5 years. Estimated value of the procedure: roughly €40 million. Bids received: nine, from major international engineering firms. Award value: roughly €18.4 million — 46% of the estimate. The airport has been over capacity for years, and traffic growth was visible and predictable as far back as 2015. Design starts now and takes two years at most. Construction, estimated at three and a half years, only after that.
The A3 Bucharest–Ploiești motorway, opened in July 2012, has operated for 14 years with no petrol stations and no working toilets along some 60 kilometres. The explanation offered over the years: the concession procedures for service areas ran into difficulty for lack of bids. A winner — OMV Petrom Marketing — was finally designated on 6 February 2025, for a package of 12 parking and service areas concessioned for 23–32 years; design work on the first six began in June 2026, with opening estimated for 2027. And for the second batch of six areas — Palanca, Moara Domnească, Bărcănești — the concession procedure was cancelled in 2024 and never relaunched. Fourteen years: tenders with no bids, tenders cancelled, files in perfect order.
In July 2026, the Digital Barometer — an independent civic initiative — assessed the digital hygiene of 2,487 Romanian public institutions: city halls, prefectures, county councils, hospitals. National average: 7.09 out of 10. The authors' own verdict: "mediocre". County hospitals average 7.0, and the bottom of the ranking drops below 4.
Three different stories: a strategic investment delayed by a decade, a mundane service absent for fourteen years, a national digital infrastructure scoring seven out of ten.
Now the interesting part: none of these three stories is a story about breached procedures. The tenders were published. The deadlines were met. The files are, almost certainly, in order.
That is the problem. Not that the system fails to work — but that it works perfectly for what it was designed to do. It was simply designed to produce files, not results.
The thesis, without softening it
The Romanian public procurement paradigm optimises for exactly one thing: passing the audit. Not meeting the need. Not the quality of the outcome. Not total cost over the lifetime. Passing the audit.
And the audit, in turn, checks exactly one thing: the legality of the paperwork. Don't take my word for it — I read the Court of Accounts report on public procurement findings for 2024, cover to cover.
So no, the audit function is not asleep. It is intense. The question is what it looks at.
The report classifies irregularities by stage, and there is — to the credit of the methodology — an entire chapter for the planning/preparation stage: 605 irregularities, 26% of the total. But read the typology of these "planning" irregularities: the annual strategy and annual programme not drawn up on time or in the legal format; programme extracts not published in SEAP; splitting contracts to fall below thresholds; wrong choice of procedure; failure to follow the rules for estimating value; items in needs assessments unrelated to the entity's activity; technical and economic documentation not legally approved.
All real. All necessary. And all about the same thing: whether the planning paperwork exists, is on time, and follows the legal form. Not one irregularity type in the report asks: was the need real and correctly sized? was the market consulted before the estimate? was quality defined in the specifications? what does life-cycle cost say?
The remaining 74% of irregularities split between running the procedure (16%) and — the lion's share, 58% — post-award: payments for undelivered goods, overstated expenditure, missing supporting documents, quantity and quality clauses not monitored. The legality of performance and payments. Still paperwork, different file.
With growing intensity, we check whether the documents of each phase comply. Nowhere do we check the quality of the purchasing decision.
Government Decision 395/2016 requires the contracting strategy to document the decisions of the planning stage (art. 9 para. 3) — the audit checks whether the strategy exists and has been approved, not whether the decisions documented in it were any good.
Weak specifications, awarded impeccably, produce a weak result with the paperwork in order. An unattractive concession, tendered repeatedly with no bids at all, produces fourteen years of nothing — and just as many perfect files in the archive. Nobody answers for the weak specifications. Nobody answers for the concession no one showed up for. Everybody would have answered for a procedural error.
This is what has to change. Not the law. The control paradigm.
"But we buy on price, that's the problem"
Let's first dismantle the standard explanation.
In 2024, Romania awarded 82% of its public procurement procedures to the cheapest bid, against 54% for the median European country, and 44% of contracts had a single bidder, against an EU average of 28%. Source: the European Commission's Single Market Scoreboard, based on TED data.
Awards on "lowest price"
Single-bidder procedures
2024 data, European Commission Single Market Scoreboard, based on TED data.
A clear diagnosis, isn't it? We buy badly because we buy cheap.
Except that the same scoreboard shows that Estonia — the country with the best-performing digital state in Europe — awarded 83% of its procedures to the cheapest bid in 2024. More than Romania. With one essential difference: Estonia has 28% single-bidder procedures — exactly the European average. "Cheap" price, healthy competition, excellent results.
Why does it work for them? Because when Estonia tenders an IT system, the specifications start from an architecture that already exists: the base registries, X-Road, the data model. The supplier does not propose the foundation — it is handed one and builds on it. What remains to be compared between bids is, to a large extent, price.
Lowest price applied to a very well defined specification gives a good result. Lowest price applied to a weak specification gives exactly what we deserve.
The award criterion is not the cause. It is the symptom. The cause is what happens — or fails to happen — before the notice is published.
And Romanian legislation not only permits everything we would need — it has already gone further than we think. Since September 2022, art. 187 para. (3^1) of Law 98/2016 (introduced by Law 208/2022) allows the "lowest price" criterion only below the European thresholds. Above the thresholds — that is, precisely the procedures measured by TED — price as the sole criterion has been prohibited for nearly four years. Art. 187 para. (8), as amended by Emergency Ordinance 52/2024, rules out cost and lowest price for intellectual services, for trans-European transport infrastructure and county roads, and for certain products with life-cycle environmental impact; art. 32 para. (6) of Government Decision 395/2016 caps the weight of price at 40% for these categories; art. 187 para. (7) explicitly allows life-cycle costing; art. 139 governs market consultation.
Now put the two figures side by side: the price criterion has been legally restricted above the thresholds since 2022 — and in the TED data for 2024, 82% of Romanian procedures are awarded to the cheapest bid. We have already lived through, without naming it, exactly the Polish experience: we changed the forms, not the results. The criteria complied on paper; the cheapest still wins.
Nothing is missing from the law. So what is missing?
The mechanism: rational fear
Put yourself in the position of the person who signs.
If you overpay
- ▸The damage is measurable — a price difference
- ▸It is immediate — it shows up at the first audit
- ▸It is personal — it is charged to you
- ▸You have one number to defend
If you buy badly
- ▸The effect is diffuse — visible in 3–5 years
- ▸It is delayed — you are in another post by then, or gone
- ▸It is collective — "the system"
- ▸You have a line of reasoning to defend
A rational civil servant, inside this system, minimises measurable risk. They choose price. Not because anyone told them to, but because price is the only decision they can defend without effort. A number is defended with a table. Quality is defended with an argument — and an argument, in an environment where the control institutions read the same legal texts differently, is an exposure.
That divergent interpretation is not an excuse but an officially acknowledged reality is shown by ANAP itself: in 2026 the agency resumed the inter-institutional dialogue with the Court of Accounts, the Audit Authority, the National Council for Solving Complaints, the Competition Council and the Ministry of Investments and European Projects, precisely in order to identify situations in which the same legal provisions are applied differently by contracting authorities, by verification and audit bodies, and by complaint-resolution bodies.
Read that sentence again. The state acknowledges, institutionally, that it does not agree with itself about its own rules.
The practical consequence is devastating for any reform: a single auditor who looks only at price cancels out the courage of ten contracting authorities. You can run ten pilot projects buying on quality — all of them die at the first audit carried out by someone applying a different reading. That is why the paradigm does not change through guidelines, training sessions and circulars. It changes only when the person signing knows in advance which grid they will be judged against — and when that grid also includes the question "what did you buy", not just "how did you award it".
Aligning interpretation across the control institutions is not a second-tier administrative objective. It is the precondition for any change. Without it, every quality initiative is a lottery staked on the signatory's career.
A 7.09 score is not an IT problem. It is a procurement problem.
Go back to the Digital Barometer. The five dimensions assessed — email security, encryption, security configuration, exposed surface, software updates — are, every one of them, things that were bought. An institution's digital hygiene score is, to a large extent, an X-ray of its specifications over the past ten years. A score of 4 does not mean "the IT department isn't doing its job". It means contracts in which nobody wrote the requirements, and audits in which nobody looked for them.
A ransomware attack on the supplier of the Hipocrate system simultaneously disrupted operations at 26 hospitals in Romania. Twenty-six units went down at once because they depended on the same supplier, through the same infrastructure. And the requirements that would have limited the disaster — recovery point objectives, restore testing, network segmentation — are minimum technical qualification requirements that can be written into any set of specifications. Legal. Free. With no risk of challenge.
Nobody writes them, because nobody is audited for their absence.
Methodological note: the Barometer is a private initiative measuring external signals, not an official audit — the figures should be read as orders of magnitude. But the order of magnitude says enough.
What the inverted paradigm would look like
I am not proposing more control. I am proposing control moved to where the decisions are made. Concretely, three changes:
First: control starts with planning
The first question of any check should not be "show me the minutes of the evaluation meeting", but: is there a needs assessment? was the market consulted under art. 139? how was the estimated value substantiated? is there a life-cycle calculation where the law allows one? is there a risk note? All of these are existing legal obligations or options. None of them is today a systematic object of control. A concession left repeatedly without bids — or cancelled and never relaunched — should trigger a planning question — "what did the market consultation say?" — not a fourth identical file.
And come back to Otopeni: an estimate of €40 million, an award at €18.4 million — less than half. I am not saying that is wrong; nine consortia competed seriously, and for intellectual services the law caps price at 40% of the score anyway. I am saying that when the winning bid comes in at 46% of the estimate for the design of the largest airport investment in the country's history, the legitimate question from a planning-stage audit is not "why is it cheap", but "how was the estimate substantiated, and what does the risk analysis say about delivering at this price". That is a question about the file, not about suspicion. And it is a question nobody asks under the current paradigm — because the substantiation of the estimated value is not an object of verification.
Second: the outcome enters the assessment
Poland demonstrated in 2014 that a well-drafted rule moves mountains on paper: after the law was amended, the share of procedures using price as the sole criterion fell from 93% to 31% in two and a half months. And Poland also demonstrated the limit: subsequent evaluation reports found that the cheapest bid still won in over 80% of cases, and that the "quality" criteria had often become fictitious — delivery time, warranty period. You changed the forms, not the results.
The lesson: if you do not measure what happened after acceptance — did it work? what did maintenance cost? how many defects under warranty? — any reform of criteria turns into scoring theatre. "We bought something that broke in three years" has to cost, institutionally, as much as "we paid 10% more".
Third: unified interpretation with binding effect
The inter-institutional dialogue started by ANAP is a step. But dialogue produces minutes; contracting authorities need precedent — published rulings on specific cases, owned by all control bodies, enforceable at audit. The day a head of procurement can put an official, unified interpretation on the table at an audit instead of a prayer, their behaviour changes that same day.
What you can do tomorrow, without waiting for anyone
For the contracting authority with no time for systemic reform, three levers, all legal today:
Define quality in the specifications, not in the scoring grid
A mandatory minimum requirement is not as easily challenged as an evaluation factor, and it cannot be "bought" with a declaration. You want data recovery within 4 hours? Don't score it. Require it.
Buy architecture, not applications
The ban on asking citizens for documents the state already holds has existed in Romanian law since 2022 (Law 267/2021, extended by Law 9/2023). Turn it into a procurement clause: no new IT system without documented APIs, without an obligation to interoperate with the base registries, without ruling out exclusive supplier rights over the data model. The cost of the clause at signature: close to zero. The cost of its absence: we live it daily.
Make the decision defensible
The manager who chooses quality does not need courage. They need a file: a documented needs assessment, market consultation, a life-cycle calculation with explicit assumptions, justification of the weightings, a risk note. Such a file does not guarantee you will not be audited. It guarantees that when you are audited, you will have something to show. The difference between "I considered it better" and "here is the calculation done in March, with these assumptions, verified through market consultation" is the difference between a finding and a closed file.
That, incidentally, is our day-to-day work: procurement decisions that survive audit because they were built to survive it.
The question that closes the circle
The Romanian state does not buy badly because it wants to. It buys badly because it has built a system in which the only decision carrying no personal risk is the cheapest one — and in which nobody, ever, is asked what became of the thing that was bought.
The change does not require a new law. It requires the control institutions to look where the fate of public money is decided — at planning — and to speak the same legal language to each other while they do it.
Until then, one question, left open for anyone who reads audit reports:
How many reports over the past ten years find damage because an institution bought too cheaply?
In the Court of Accounts' 2024 report, among all the catalogued types of irregularity, across three stages and eight years of historical series, no such category exists. Not because the phenomenon does not exist. Because nobody is looking for it.
Sources
- Romanian Court of Accounts — report on public procurement findings, 2024
- European Commission — Single Market Scoreboard, public procurement indicators based on TED data (2024)
- Law 98/2016, Law 208/2022, Emergency Ordinance 52/2024, Government Decision 395/2016, Law 267/2021, Law 9/2023
- ANAP — inter-institutional dialogue on unified interpretation of the legislation (2026)
- Digital Barometer — digital hygiene assessment of 2,487 public institutions (July 2026)