Software Project ManagementUnit 511 min read
Contracts, Risks & Agile in Software Projects
Unit 5 of Software Project Management covers contract types (fixed-price, T&M, hybrid), risk management frameworks (identify-assess-monitor), and real-world applications in Nepalese IT firms like eSewa and Daraz. Learn how to structure agreements, mitigate risks (e.g., scope creep, vendor delays), and apply risk matric
TAKEAWAYS:
- Contracts bind stakeholders: fixed-price suits well-defined projects (e.g., NTC’s billing system), while time-and-material fits evolving needs (e.g., Daraz’s AI integration).
- Risk management follows identify → assess → prioritize → monitor: use a risk matrix (likelihood vs. impact) to flag delays (e.g., Kathmandu traffic disrupting on-site testing).
- Agile contracts blend fixed milestones with flexible scope (e.g., Pathao’s ride-hailing updates).
- Risk responses include avoidance (e.g., backup vendors for NEPSE’s trading platform), mitigation (e.g., buffer time for monsoon delays in rural deployments), and transfer (e.g., insurance for hardware failures).
- Contract clauses must define scope, payment terms, penalties, and termination—critical for eSewa’s digital wallet upgrades.
- Real-world tie: Khalti’s time-and-material contract with a fintech consultant allowed iterative UPI integration, while a fixed-price contract failed for a bank’s legacy system migration due to unclear requirements.
1. Contract Management in Software Projects
Contracts are legally binding agreements between a client (e.g., NTC) and a vendor (e.g., a Nepalese IT firm) that define scope, deliverables, timelines, payments, and liabilities. Poor contracts lead to disputes (e.g., Daraz’s delayed order-tracking system in 2022).
Types of Software Contracts
Software projects typically use three main contract types, each suited to different risk profiles:
classDiagram
class ContractType {
+Name
+Use Case
+Risk Profile
+Payment Structure
}
class FixedPrice {
+Use Case: Well-defined scope (e.g., NTC’s billing software)
+Payment: Lump-sum or milestones
+Risk: High for vendor, low for client
}
class TimeAndMaterial {
+Use Case: Evolving requirements (e.g., Pathao’s dynamic pricing)
+Payment: Hourly/daily rates
+Risk: High for client, low for vendor
}
class Hybrid {
+Use Case: Mixed scope (e.g., eSewa’s API upgrades)
+Payment: Fixed + variable
+Risk: Balanced
}
ContractType <|-- FixedPrice
ContractType <|-- TimeAndMaterial
ContractType <|-- HybridWorked Example: Ncell’s App Redesign
- Contract Type: Hybrid (fixed UI/UX design + time-and-material for backend APIs).
- Why?
- Fixed scope for design (clear wireframes).
- T&M for API development (Ncell’s data needs evolved during the project).
- Clause Example:
"Vendor shall deliver a prototype within 3 months. Additional API endpoints will be billed at $50/hour, with client approval required for scope changes."
Real-World Tie: eSewa’s Digital Wallet Upgrade
- Contract Type: Time-and-Material for agile sprints.
- Outcome: Allowed eSewa to pivot from NFC to QR codes mid-project without legal disputes.
2. Risk Management Framework
Risk management is a proactive process to identify, assess, and mitigate threats to project success. The standard framework has 4 phases:
stateDiagram-v2
[*] --> Identify
Identify --> Assess: "Brainstorming, checklists"
Assess --> Prioritize: "Risk matrix (likelihood vs. impact)"
Prioritize --> Monitor: "Regular reviews (e.g., weekly standups)"
Monitor --> [*]Step 1: Risk Identification
Use techniques like:
- Brainstorming: Team discusses potential risks (e.g., "What if NEPSE’s trading system crashes during Diwali?").
- Checklists: Predefined risks for similar projects (e.g., "Vendor delays in Kathmandu traffic").
- SWOT Analysis: Internal/External threats (e.g., internal: poor team skills; external: government policy changes).
Example Risks in Nepalese Projects:
| Risk Type | Example | Likelihood | Impact |
|---|---|---|---|
| Technical | Legacy system incompatibility | Medium | High |
| External | Monsoon delays field testing | High | Medium |
| Resource | Key developer leaves mid-project | Low | High |
| Financial | Budget overrun due to scope creep | Medium | High |
Step 2: Risk Assessment (Risk Matrix)
Plot risks on a 2×2 grid to prioritize:
pie
title Risk Priority Matrix
"High Priority (Mitigate First)" : 30
"Medium Priority (Monitor)" : 40
"Low Priority (Accept)" : 20
"Negligible" : 10Worked Example: Daraz’s Order Fulfillment System
- Risk: "Third-party logistics partner fails during Dashain sales."
- Likelihood: High (peak season).
- Impact: High (lost revenue).
- Action: Mitigation = Pre-negotiate backup warehouses in Lalitpur and Chitwan.
Step 3: Risk Response Strategies
| Strategy | When to Use | Example |
|---|---|---|
| Avoid | Eliminate the risk entirely | Cancel a risky vendor (e.g., untested AI tool for Ncell). |
| Mitigate | Reduce likelihood/impact | Buffer time for monsoon delays in rural deployments. |
| Transfer | Shift risk to another party | Insurance for hardware failures in data centers. |
| Accept | Low-impact risks | Minor UI bugs in Pathao’s beta phase. |
Real-World Tie: NEPSE’s Trading Platform
- Risk: "Cyberattack during market hours."
- Response: Transfer (bought cyber insurance) + Mitigate (24/7 security audits).
3. Contract Management Process
A well-managed contract ensures deliverables meet expectations and disputes are minimized. The process includes:
flowchart TD
A["1. Contract Creation"] --> B["2. Negotiation & Signing"]
B --> C["3. Execution"]
C --> D["4. Monitoring & Control"]
D --> E["5. Closure & Handover"]
E -->|"Audit"| F["Lessons Learned"]Key Contract Clauses
| Clause | Purpose | Example |
|---|---|---|
| Scope of Work | Defines deliverables | "Vendor shall develop a mobile app with X features." |
| Payment Terms | When/how payments are made | "50% upfront, 30% on milestone, 20% on delivery." |
| Penalties | Consequences for delays/defects | "Late delivery: 5% of contract value per week." |
| Termination | Conditions to end the contract | "Either party can terminate with 30 days’ notice for breach." |
| Confidentiality | Protects sensitive data | "Client’s data shall not be shared with third parties." |
Worked Example: Bank’s Loan Management System
- Clause: "Vendor shall provide 24/7 support for 1 year post-launch."
- Why? Critical for Nepal Rastra Bank’s compliance with financial regulations.
4. Agile Contracts: Bridging Fixed and Flexible Scope
Traditional contracts struggle with Agile’s iterative nature. Agile contracts blend:
- Fixed milestones (e.g., "Sprint 1: Login screen").
- Variable scope (e.g., "Additional features approved via backlog").
Example: Pathao’s Ride-Hailing Updates
- Contract Type: Hybrid Agile
- Fixed: Core features (ride booking, payment).
- Flexible: New features (e.g., "electric vehicle routing") added via sprint planning.
Advantages of Agile Contracts:
- Client: Pays only for delivered value.
- Vendor: Reduced risk of scope creep.
- Example: Khalti’s time-boxed sprints for UPI integration.
5. Real-World Applications in Nepal
| Company/Product | Contract Type | Risk Managed | Outcome |
|---|---|---|---|
| eSewa | Time-and-Material | Vendor delays in API testing | Iterative testing with weekly demos. |
| NTC | Fixed-Price | Scope creep in billing system | Strict change-order process. |
| Daraz | Hybrid | Third-party logistics failures | Backup warehouses in multiple cities. |
| Ncell | Hybrid Agile | Rapidly changing 5G requirements | Flexible sprints for network updates. |
| NEPSE | Fixed + Insurance | Cybersecurity threats | 24/7 monitoring + cyber insurance. |
Case Study: Kathmandu Traffic Disrupting On-Site Testing
- Risk: "Field testing for a smart traffic system delayed by protests."
- Response:
- Mitigation: Scheduled testing during off-peak hours.
- Contingency: Simulated traffic data for lab testing.
- Result: Only a 2-week delay (vs. 4 weeks if unplanned).
6. Common Pitfalls and How to Avoid Them
| Pitfall | Cause | Solution |
|---|---|---|
| Unclear scope | Vague requirements | Use user stories and acceptance criteria. |
| Scope creep | Client adds features mid-project | Change-order process with approval gates. |
| Vendor delays | Poor estimation | Buffer time (e.g., 20% extra for risks). |
| Payment disputes | Ambiguous milestones | Define clear deliverables per payment. |
| Cultural mismatches | Different expectations (e.g., Nepali vs. foreign clients) | Cultural training and regular check-ins. |
Exam Tip
Contract Questions:
- Always compare fixed-price vs. T&M with a real-world example (e.g., "Why did Daraz use a hybrid contract?").
- Memorize key clauses: Scope, payment, penalties, termination.
- Example Answer:
"A time-and-material contract is beneficial when requirements are unclear, as seen in Pathao’s dynamic pricing feature. Here, the client pays for actual hours spent, allowing flexibility to adapt to user feedback."
Risk Management Questions:
- Structure answers using the 4-phase framework (identify → assess → prioritize → monitor).
- Use the risk matrix in examples:
*"For NEPSE’s trading platform, a cyberattack has high likelihood (0.7) and high impact (0.9), placing it in the mitigate first quadrant. Responses include 24/7 monitoring and cyber insurance."*
Agile Contracts:
- Link to sprints and backlog refinement:
"Agile contracts work well for Khalti’s UPI integration because they align with 2-week sprints, allowing the client to prioritize features like ‘fingerprint authentication’ in Sprint 3."
- Link to sprints and backlog refinement:
Past Exam Patterns:
- Short Questions: Define terms (e.g., "What is a risk matrix?").
- Long Questions: Case-based. Always tie to a Nepalese company (e.g., "How would you manage risks in eSewa’s digital wallet upgrade?").
A labeled 3x3 grid showing high/medium/low risk quadrants. (Image: U.S. DEPARTMENT OF TRANSPORTATION FEDERAL AVIATION ADMINISTR, Public domain, via Wikimedia Commons)
Based on the TU BIT syllabus for Software Project Management (BIT402), unit 5.
Discussion
Loading…