Skip to content
Advanced11 min readUpdated September 2026

Agile Contracts And Procurement

Fixed-price fixed-scope contracts reliably produce the behaviours both sides claim to hate. A practical look at the structures that work, what procurement is genuinely protecting, and how to write a statement of work for iterative delivery.

Almost every failed supplier relationship in software has the same autopsy. The contract fixed the scope, the price and the date. Requirements were written before anybody understood the problem. Within a few months reality diverged from the specification, and from that point both parties behaved exactly as the contract instructed them to: the supplier defended the scope line and monetised every change, the client stopped raising improvements because each one cost money and took six weeks to agree, and both sides spent an increasing share of their capacity on contract administration rather than delivery.

What is striking is that everyone involved usually knows this is happening and continues anyway, typically while complaining about the other party's attitude. Attitude is not the variable. The contract is a behavioural specification, and it was followed precisely.

The problem is not that procurement is unreasonable or that suppliers are predatory. The standard instrument was designed for buying a defined thing — a building, a quantity of components, a service with stable characteristics — and software development is not a defined thing until you have partly built it. A fixed-scope contract for work whose scope is not yet knowable is a bet both sides lose: the supplier prices the uncertainty as risk, and the client pays that premium while receiving less flexibility.

What fixed price actually buys

It is worth being precise about the mechanism, because "fixed price is bad for agile" is an assertion that persuades nobody in a procurement function.

It buys a risk premium, not certainty. A supplier asked to commit to a fixed price for uncertain work prices the uncertainty. They must, or they go out of business on the bad ones. The client therefore pays a premium in every engagement to insure against overrun in some of them, and pays it whether or not the risk materialises. It is insurance with a poor loss ratio, purchased for the feeling of a fixed number.

It fixes the scope at the point of maximum ignorance. The specification is written before anybody has built anything, seen a user react to it or discovered what the integration actually does. The single most valuable thing the engagement produces — learning — is contractually classified as change, and change is penalised.

It makes the change control process the main commercial event. Once the scope is the boundary of obligation, every conversation about improvement becomes a commercial negotiation. Change requests become the supplier's margin recovery mechanism, which is a rational response to having priced the base aggressively to win the bid. The client's own people learn not to suggest better ideas, because raising one costs money and weeks.

It rewards defending scope over delivering value. The supplier's obligation is to deliver what the document says. If the document specifies something everyone now knows is useless, the safest commercial behaviour is to build it, deliver it and invoice for it. A supplier who says "you should not build this" is performing a service they cannot bill for and may be penalised for.

It drives quality down where quality is invisible. Under fixed price, the supplier's margin is whatever is left after delivery. Internal quality — testing, structure, documentation, the things a client cannot easily inspect at handover — is the only variable the supplier can compress without breaching the specification. The client inherits the consequences after the warranty period has expired.

None of this requires bad faith. Give competent, honest people this instrument and you will get these behaviours, because they are the rational strategies it defines.

What procurement is genuinely protecting

Delivery practitioners tend to treat procurement as an obstacle. That framing loses every argument it enters. Procurement functions exist to protect a small set of legitimate interests, and any proposal that does not address them will be refused, correctly.

Budget certainty. Someone has committed a number to a finance process and is accountable for it. This is real and it is not negotiable away, though it can be met by a cap rather than by fixing scope.

Protection against runaway spend. The nightmare is an open-ended engagement with no mechanism to stop. Time and materials without governance genuinely does create that risk, and procurement is right to be wary of it.

Comparability between bidders. A competitive process needs a basis on which to compare. Fixed-price bids for identical scope are comparable, which is their chief attraction — even though what is actually being compared is willingness to underprice.

Recourse if the supplier fails. Something must be enforceable if delivery does not happen.

Defensibility of the decision. In public sector and regulated procurement especially, the decision must withstand challenge and audit. A buyer will not adopt a structure they cannot defend, whatever its delivery merits.

Every one of these can be satisfied without fixing scope. Budget certainty comes from a cap. Runaway protection comes from short commitment increments and an unconditional exit. Comparability comes from scoring the team and the approach rather than a price for a fictional specification. Recourse comes from clear acceptance criteria per increment and the right to stop paying. Defensibility comes from documenting the evaluation method properly, which iterative structures support perfectly well.

Name these five interests before proposing anything. A procurement lead who hears their own concerns articulated accurately will engage with an alternative. One who hears an argument about agility will not.

The structures, compared

StructureHow it worksProtects the buyer byBest suited toPrincipal failure mode
Fixed price, fixed scopeDefined deliverables for a defined sumApparent price certaintyGenuinely well-understood, stable, repeatable workRisk premium, change-request warfare, hidden quality compression
Time and materialsPay for effort suppliedNothing inherently; relies on trustMature relationships with strong internal governanceOpen-ended spend and weak supplier accountability
Time and materials with governanceEffort-based, with fixed team shape, published flow metrics, regular demonstrable increments and a short notice periodVisibility and the ability to stop quicklyMost product development with a capable client organisationRequires an engaged client; fails if the buyer cannot make decisions
Capped time and materialsEffort-based up to a ceiling the supplier cannot exceed without agreementAbsolute budget certaintyBuyers who need a number for a finance processCap becomes a de facto target; margin pressure near the ceiling
Incremental or phase-gatedSmall funded increment first, continuation decided on evidenceLimiting exposure to one increment at a timeNew relationships and uncertain problemsRe-procurement overhead if gates are heavy
Money for nothing, change for freeScope may be exchanged at equal size at no cost; buyer may terminate early and pay a defined share of remaining valueBoth flexibility and a strong incentive to finish earlyPrioritised backlogs with an engaged product ownerNeeds credible sizing and genuine trust on both sides
Outcome-basedPayment linked to agreed measures of resultAligning payment with valueCases where the outcome is measurable and largely supplier-influencedMeasurement disputes; supplier cannot control outcomes they do not own

Two of these deserve elaboration because they are the least familiar.

The money-for-nothing, change-for-free construction, associated with Jeff Sutherland's work on agile contracting, does something clever. Change for free means the buyer may swap items out of the remaining backlog for items of equivalent size at no charge, provided total size is unchanged — which removes the commercial penalty on learning. Money for nothing means the buyer may terminate at any point once they judge that the remaining backlog is no longer worth building, paying the supplier a defined share of the remaining contract value. The supplier is therefore rewarded for delivering the valuable items first and for helping the buyer stop early, which inverts the usual incentive to consume the whole budget. It requires a workable sizing mechanism and a buyer capable of prioritising, and it is not suitable everywhere, but it is the cleanest available answer to the incentive problem.

Outcome-based contracting is attractive in principle and difficult in execution. The supplier must be able to influence the outcome materially, the measure must be agreed precisely before work starts, and both parties must accept that external factors will move it. Where the supplier controls only delivery and the buyer controls adoption, pricing and organisational change, the contract transfers risk the supplier cannot manage, and they will price accordingly or decline. Used narrowly — on measures the supplier genuinely drives — it works well.

Scoring vendors on the right things

If the specification is not the basis of comparison, something else must be. The most common mistake is running an iterative engagement model through an evaluation designed for fixed-scope bids, which selects suppliers who are good at writing proposals.

Score the things that predict delivery.

The actual team. Not a corporate capability statement and not named individuals who will be reassigned after signature. Name the people, contract the right to interview them, and write in a consent requirement for substitution. The single largest determinant of the outcome is who turns up.

Demonstrated engineering practice. Ask how often they deploy on their current engagements, what their pipeline does, how they handle testing and how they manage trunk hygiene. Ask to see it working rather than described. A supplier who cannot demonstrate continuous integration will not become able to during your engagement.

A working exercise. A short, paid, real piece of work is worth more than any amount of proposal evaluation. It reveals communication, technical judgement, question-asking and how the team behaves under ambiguity, all of which the document conceals.

How they handle being wrong. Ask for an engagement that went badly and what they changed. The answer distinguishes suppliers who learn from suppliers who present.

Transition and exit. How the work would come back in-house, what documentation and access you hold throughout, and what happens on termination. A supplier confident about exit is usually confident about delivery.

Rate transparency by role. Under effort-based structures the comparable number is the blended rate against the shape of the team. This is straightforwardly comparable across bidders and is defensible in an audited process.

Writing a statement of work for iterative delivery

The statement of work is where good intentions usually revert to type, because the template asks for a deliverables schedule and someone fills it in. Write it around obligations that are real and verifiable without pretending to know the scope.

Describe the problem, the business objective and the constraints, rather than a feature list. Where a list is required for governance, label it explicitly as the current best understanding of priority and state that it is expected to change — that single sentence prevents a great deal of later argument.

Fix the things that genuinely can be fixed: the team composition and seniority, the cadence, the duration of the increment, the rate card, the definition of done that governs acceptance, the quality obligations that survive handover, and the intellectual property and licensing position.

Define acceptance at the increment rather than at the end. Acceptance means working software meeting the agreed definition of done, demonstrated in a real environment, and it is the payment trigger. This is the mechanism that replaces the end-of-project inspection, and it is stronger because it happens repeatedly while there is still time to act.

State the governance explicitly: what is reviewed, how often, which metrics are published, and who on the buyer's side is empowered to make prioritisation decisions. That last item is the most frequently omitted and the most frequently fatal. An iterative contract with no empowered decision-maker on the buying side degrades into effort-based work with no direction, and the supplier will be blamed for it.

Set out the change mechanism as reprioritisation rather than as a commercial event, and write the exit provisions so that termination is orderly and cheap. Where the work sits inside a regulated estate, align the acceptance evidence with the control objectives from the outset; the regulated delivery article covers why generating that evidence continuously is easier than assembling it later. And if the buying organisation is still funding work as discrete projects, expect friction, because the commercial model and the funding model have to move together — which is the subject of from project funding to product funding.

What to do on Monday

Take your current supplier contract and find the change control clause. Count the change requests raised in the last twelve months, the average time to agree one, and the total effort consumed on both sides in administering them. That figure is the cost of the structure, it is usually startling, and it is the most effective opening to a conversation with procurement because it is your own data rather than an argument.

Then arrange a conversation with your procurement lead in which you do not mention agility. Ask what they are accountable for protecting, write the answers down, and bring back a proposed structure that addresses each one explicitly — a cap for budget certainty, short increments and a short notice period for runaway protection, per-increment acceptance for recourse, a documented evaluation method for defensibility.

For the next engagement that is genuinely small, propose a capped time-and-materials arrangement with a first increment of a few weeks, a demonstrable output, and an unconditional right to stop. One completed example inside your own organisation does more to change procurement policy than any amount of external evidence, and it gives your procurement lead something they can defend.