39.102 Management of risk
Source: FAR 39.102 on acquisition.gov
Effective risk management is mandatory for all federal IT acquisitions, requiring joint responsibility and proactive mitigation strategies throughout the project lifecycle.
Overview
FAR 39.102 emphasizes the importance of risk management in the acquisition of information technology (IT) by federal agencies. Before entering into IT contracts, agencies must analyze the associated risks, benefits, and costs, ensuring that reasonable risks are taken only when they are controlled and mitigated. Both contracting and program office officials share responsibility for assessing, monitoring, and controlling risk throughout the project lifecycle, from selection to implementation. The regulation identifies various types of risks, such as schedule, technical obsolescence, cost, contract type, technical feasibility, interdependencies, project volume, funding, and program management. To manage these risks, agencies are encouraged to use techniques like prudent project management, modular contracting, comprehensive acquisition and budget planning, continuous risk assessment, prototyping, post-implementation reviews, and quantifiable risk-return analysis.
Key Rules
- Pre-Contract Risk Analysis
- Agencies must analyze risks, benefits, and costs before entering into IT contracts.
- Joint Risk Responsibility
- Contracting and program office officials are jointly responsible for risk management throughout the project.
- Types of Risk
- Risks include schedule, technical obsolescence, cost, contract type, technical feasibility, dependencies, project volume, funding, and program management.
- Risk Management Techniques
- Agencies should use techniques such as modular contracting, acquisition planning, continuous risk assessment, prototyping, and post-implementation reviews.
Responsibilities
- Contracting Officers: Ensure risk analysis and mitigation strategies are in place before and during IT acquisitions.
- Contractors: Comply with agency risk management requirements and participate in risk mitigation activities as required.
- Agencies: Oversee risk assessment, monitoring, and control throughout the IT project lifecycle.
Practical Implications
- This section exists to ensure IT acquisitions are managed with a focus on minimizing and controlling risk, improving project outcomes, and safeguarding government investments.
- It impacts daily contracting by requiring structured risk analysis and ongoing risk management.
- Common pitfalls include inadequate risk assessment, failure to use appropriate mitigation techniques, and lack of coordination between contracting and program offices.
(a) Prior to entering into a contract for information technology, an agency should analyze risks, benefits, and costs. (See part 7 for additional information regarding requirements definition.) Reasonable risk taking is appropriate as long as risks are controlled and mitigated. Contracting and program office officials are jointly responsible for assessing, monitoring and controlling risk when selecting projects for investment and during program implementation.
(b) Types of risk may include schedule risk, risk of technical obsolescence, cost risk, risk implicit in a particular contract type, technical feasibility, dependencies between a new project and other projects or systems, the number of simultaneous high risk projects to be monitored, funding availability, and program management risk.
(c) Appropriate techniques should be applied to manage and mitigate risk during the acquisition of information technology. Techniques include, but are not limited to: prudent project management; use of modular contracting; thorough acquisition planning tied to budget planning by the program, finance and contracting offices; continuous collection and evaluation of risk-based assessment data; prototyping prior to implementation; post implementation reviews to determine actual project cost, benefits and returns; and focusing on risks and returns using quantifiable measures.
