Most corporate purchasing is not strategic sourcing. It is a facilities coordinator ordering toner or a lab manager reordering pipette tips. Procurement software handles that volume through two related mechanisms: punchout catalogs, which connect a buyer's procurement system to a supplier's web store, and guided buying, a front end that steers occasional requesters toward the right channel.
What a punchout is
A punchout is a round trip. The requester starts inside the procurement system, clicks a supplier's link, and is passed into that supplier's e-commerce site with their identity and session details. They shop using the supplier's own search, configurator and pricing. At checkout, instead of paying, they send the cart back to the procurement system, where it becomes lines on a requisition.
The point that matters most for controls: checking out on the supplier site does not place an order. North Carolina's e-procurement specification for suppliers states that no orders are sent when the user exits or checks out from the punchout site, and that a purchase order goes to the supplier only after the requisition has been fully approved (NC E-Procurement). The punchout supplies the cart. The procurement system still owns approval, budget coding and the PO.
The two protocols
Two standards carry most of this traffic.
cXML was created by Ariba, and version 1.0 of the specification is dated August 16, 1999 (cXML.org). It is still maintained, and the current cXML Reference Guide is published by SAP, which now owns Ariba (cXML.org). A cXML punchout starts with a PunchOutSetupRequest posted from the procurement system to the supplier. That request carries a BuyerCookie identifying the session and a BrowserFormPost URL telling the supplier where to send the finished cart (PunchOutCommerce). The supplier replies with a landing-page URL, the user shops, and the cart returns as a PunchOutOrderMessage. Coupa's supplier documentation describes the same sequence from the buyer platform's side (Coupa).
OCI, SAP's Open Catalog Interface, does the same job with simpler mechanics. The procurement system opens the supplier's catalog URL with parameters that include a HOOK_URL, the address the cart must be returned to. The cart comes back as HTML form fields posted to that address rather than as an XML document (SAP OCI 5.0).
Static catalogs, punchout, and the middle ground
A static, or hosted, catalog is a file the supplier uploads to the buyer's system, listing items, descriptions and contract prices. Search and pricing live on the buyer's side. Price control is straightforward, but the supplier carries the burden of keeping every line current.
A basic punchout, which the trade calls Level 1, inverts that. The buyer's system holds only a link, and everything else lives on the supplier site. It suits suppliers with large, fast-changing or configurable ranges, such as IT hardware.
An index punchout, often called Level 2, splits the difference. The supplier publishes an index of items that appears in the buyer's own search results, and each item links into the punchout at the right product page. SAP's catalog documentation notes a consequence buyers should understand: pricing in a punchout index file is ignored, because the supplier's site sets the price in each session (SAP).
Where guided buying fits
Guided buying sits in front of all of this. It is not a separate buying process: SAP's documentation says its guided buying capability follows the same procurement processes as its core SAP Ariba tools and does not replace them for work such as invoice reconciliation (SAP). What it adds is a simpler entry point for occasional requesters, a landing page of tiles, categories and forms that administrators configure per user group.
The practical job is routing. A requester who searches for a laptop should land on the contracted IT punchout, not a free-text request. One who needs a contractor should get an intake form that collects what legal and finance need. Punchout supplies the catalog content. Guided buying decides which channel a request goes through in the first place.
What to check when buying
- Protocol coverage. Confirm support for both cXML and OCI, and ask which of your largest suppliers already run punchouts to the platform.
- Price enforcement. With punchout, the contract price lives on the supplier's site. Ask how the platform detects a cart price that differs from the contract, and whether it can block or flag the line.
- Classification mapping. Returned cXML cart lines carry a commodity classification, commonly UNSPSC (PunchOutCommerce). Ask how those codes map to your own categories and GL accounts, because that mapping drives spend reporting.
- Reopening carts. The cXML setup request supports create, edit and inspect operations (PunchOutCommerce). Check whether requesters can reopen a returned cart to change it, or have to start over.
What commonly goes wrong
Many punchout failures are data failures at line level. Coupa's supplier guidance on its "Punchout failed to return a cart" error attributes it to missing data elements or incorrect formatting in the cart cXML, points to unit-of-measure setup as a first check, and notes that the cart is lost and has to be rebuilt (Coupa). One malformed line can cost the requester the whole cart.
The second failure is organisational. A punchout that works technically still goes unused if requesters never find it. That is the gap guided buying is meant to close, so landing-page configuration deserves real attention during rollout.
The third is drift. A redesigned web store, a new part-numbering scheme or a rotated credential can break a punchout that worked last quarter, and the procurement team may hear about it from a requester before any monitor fires. Ask who owns retesting each connection after a supplier-side change.
Sources
- North Carolina E-Procurement. "NC E-Procurement @ Your Service Punchout Catalog Technical Specifications." https://eprocurement.nc.gov/media/95/open
- cXML.org. "cXML/1.0." 1999. http://xml.cxml.org/schemas/cXML/1.0.001/cXML.pdf
- cXML.org. "cXML Reference Guide." https://xml.cxml.org/current/cXMLReferenceGuide.pdf
- PunchOutCommerce. "cXML PunchOut." https://punchoutcommerce.com/guides/punchout/cxml-punchout-setup-request/
- PunchOutCommerce. "cXML PunchOut Carts." https://punchoutcommerce.com/guides/punchout/cxml-punchout-order-message/
- Coupa. "Punchout Ordering." https://compass.coupa.com/en-us/products/product-documentation/supplier-resources/for-suppliers/integration-resources/purchase-orders-and-punchouts/punchout-ordering
- Coupa. "Punchout failed: Punchout failed to return a cart." https://compass.coupa.com/en-us/products/product-documentation/supplier-resources/for-suppliers/integration-resources/purchase-orders-and-punchouts/punchout-failed-punchout-failed-to-return-a-cart
- SAP. "Open Catalog Interface (OCI) Release 5.0." https://punchoutcommerce.com/docs/sap-oci-5.pdf
- SAP Help Portal. "PunchOut Catalog Items." https://help.sap.com/docs/ARIBA_PROCUREMENT/43cc25c2fa9d4789b058784e816a2af8/dd9dba78f0181014b52a898eb28ba247.html
- SAP Help Portal. "What is Guided Buying?" https://help.sap.com/docs/buying-invoicing/guided-buying-administration/2ea3652101604da5a13ea8a15f3a71e1.html
