We are opening up the procurement risk flags

Published: 2026-08-18

Every rule by which we mark a contract as risky is now public — threshold, legal basis, when the check applies at all. Along with the three things we decided to write down rather than leave out: one check that currently does nothing on any contract; one whose direction is unsettled; and two grades using different weights without our being sure they should. 62.6% of contracts fire no flag at all.

Every rule by which we mark a public contract as risky is now published: the threshold, the legal basis, when the check applies at all, and what the number does not say. The catalogue is machine-readable and MIT-licensed — take it, check it, reuse it, no need to ask.

The reason is not transparency for its own sake. When a contract page says "connected to an MP" or "the value grew to the legal cap", that is a claim about a named company. Until now those definitions lived only in code. Anyone who wanted to dispute such a claim had to take our word for it — which is the opposite of what we are trying to do with public data.

What we are publishing

Seventeen checks: thirteen on a signed contract and four on the procedure itself, which can fire while bids are still open. Each one now states its threshold, where that threshold comes from, what data it needs before it can be evaluated at all, and how often it fires in the Bulgarian corpus.

The "fired flags" block on a contract page: the letter grade, the "4 of 10 applicable checks" counter, and the full ledger — the four checks that fired, the six that passed, and the three that cannot be evaluated at all, each with its explanation and legal basis.

Here is what that looks like on one contract — awarded by the Road Infrastructure Agency to Avtomagistrali EAD. The ledger is always open and always complete: not only what fired, but what passed, and what could not be checked at all — with the reason why.

A few of those numbers are worth saying out loud, because on their own they answer the question "how bad is it":

  • 62.6% of contracts fire no check at all. Another 30.5% fire exactly one.
  • About nine of the checks can actually be evaluated on a typical contract. Contracts where five or more fire number 81 out of 409,392 — 0.02%.
  • Splitting purchases below the direct-award ceilings — the flag that sounds most scandalous — fires on 0.09% of contracts.

So: the tool does not find corruption everywhere. If it did, that would be grounds to doubt the tool rather than the contracts.

Three things we decided to write down rather than leave out

One check currently does nothing. "Submission window too short" is implemented, but the procedure-window fields are unpopulated in the data — across a sample of 20,000 contracts, zero carry those dates. The check neither fires nor counts as passed; it simply drops out. It could have stayed in a list of thirteen and nobody would have known. It says so instead.

One check points in an unsettled direction. We score a decision period that is too short. The source we build on justifies the risk through the opposite mechanism — that a long decision period leaves room for repeated appeals until the contract reaches a chosen company. The international catalogue we compared against publishes indicators for both directions. Ours has one. That contradiction is unresolved, and it is recorded next to the check itself.

The two A–F grades use different weights, and we are not certain they should. The buyer grade was rebalanced in July 2026: the weight on direct award went up and the weight on single bidding went down, because against the European comparison Bulgaria is a dramatic outlier on the first and thoroughly average on the second. The supplier grade kept the old weights. Whether that is deliberate — a supplier does not choose the procedure type — or simply an unfinished change, has not been decided. We publish both sets and say the question is open.

Two grade cards for the same entity: "as a buyer" — B, 23 of 100, with components politically linked suppliers 0%, single-bid awards 26%, direct awards 3%, supplier concentration 74%, КЗК-upheld appeals 33%; and "as a supplier" — F, 90 of 100, with components politically linked 100%, single-bid awards 87%, direct awards 65%, reliance on one buyer 100%.

One entity can carry both grades at once. Avtomagistrali EAD is a B as a buyer and an F as a supplier — not because one grade refutes the other, but because these are two different roles, measured over different components and with different weights. Those weights are the question we leave open.

A flag is not a verdict

The framing is the Open Contracting Partnership's and we adopt it literally: a fired flag may mean a) behaviour that is entirely lawful and unremarkable; b) lawful but poor value for public money; or c) illicit. In that order — the two innocent explanations first.

There is a more uncomfortable caveat, also on the page. A study covering almost the entire population of Italian roadwork contracts found that the most scrutinised red flags are either uncorrelated with corruption or correlated with it in the opposite direction. That is the strongest argument against reading any single flag as evidence — and the reason the grades we show for an organisation carry more weight than the letter beside a single contract.

It is also why the denominator works the way it does: the index counts the checks that could actually be evaluated, not all seventeen. A contract with no recorded bid count is not scored zero on competition — the check simply drops out of its denominator. A contract with sparse data does not get to look cleaner than it is.

How it lines up with the international catalogues

We mapped every check to its closest indicator in OCP's Red Flags for Integrity (2024) and in the iMonitor 2.0 methodology. Not from memory — we read the documents. Doing so showed that two of the mappings we had assumed were wrong: the contract-splitting flag pointed at an indicator for a single award below the threshold, and the over-estimate flag at one that compares against the category average rather than against the procedure's own estimate.

Four of the seventeen checks have no equivalent anywhere. Two of them are the political-connection ones — an MP or an official recorded as a manager or owner of the winning company. That is the most Bulgaria-specific part of the set, and simultaneously the heaviest claim we make. Which is why it rests on a verified identity for a specific person rather than on a name match.

There is also a difference that cuts against us, and we publish it anyway: we suppress the single-bidder flag in sectors where one bid is the market norm, and on textbooks, where the law provides for a single source. The international catalogues do not. That means our single-bid rate is not directly comparable to theirs until the suppression is undone.

What comes next

The catalogue is versioned. The page shows not the version in the code but the version the flags you are looking at were actually computed under — the two diverge in the window between a site update and a data rebuild, and that is precisely the moment when a citation would be wrong.

If you use any of this, cite the version rather than the date. And if you find an error in a definition, a threshold or a mapping, there is now something concrete to point at.

  • The flag methodology — thresholds, legal bases and limits.
  • risk-flags.json — the machine-readable catalogue.
  • Public procurement — the data itself.

Explore the data

  • Home
  • Governance
  • National Assembly
  • Roll-call votes
  • Governments
  • MP business connections
  • Public procurement
  • State budget
  • EU funds
  • Indicators
  • Consumption
  • Prices
  • Party financing
  • Opinion polls
  • Seat simulator
  • Parties
  • Results by region
  • Extraordinary local elections
  • Local-elections reconciliation
  • Sofia
  • About the project

Recent analysis

  • We are opening up the procurement risk flags
  • Why Bulgaria does not pay for outcomes
  • Budget 2026: adopted in month seven — what the numbers show