FAR and DFARS › FAR Part 39: Acquisition of Information Technology › Subpart 39.1

FAR 39.102 Management of risk.

The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.

In plain English

This section requires agencies to analyze risks, benefits, and costs before entering into an information technology contract. It also lists types of risk and suggests techniques to manage and mitigate risk during the acquisition. Contractors should be aware that risk management is a shared responsibility and may affect how projects are planned and contracted.

Applies to: Agencies acquiring information technology and contracting/program office officials

What it requires

  • Analyze risks, benefits, and costs prior to entering into a contract for information technology.
  • Assess, monitor, and control risk when selecting projects for investment and during program implementation.

Key terms: schedule risk · technical obsolescence · cost risk · modular contracting · prototyping

Written by AI from this section's text. A guide, not legal advice: the text below rules.

The text

(a) Prior to entering into a contract for information technology, an agency should analyze risks, benefits, and costs. (See part 7 for additional information regarding requirements definition.) Reasonable risk taking is appropriate as long as risks are controlled and mitigated. Contracting and program office officials are jointly responsible for assessing, monitoring and controlling risk when selecting projects for investment and during program implementation.

(b) Types of risk may include schedule risk, risk of technical obsolescence, cost risk, risk implicit in a particular contract type, technical feasibility, dependencies between a new project and other projects or systems, the number of simultaneous high risk projects to be monitored, funding availability, and program management risk.

(c) Appropriate techniques should be applied to manage and mitigate risk during the acquisition of information technology. Techniques include, but are not limited to: prudent project management; use of modular contracting; thorough acquisition planning tied to budget planning by the program, finance and contracting offices; continuous collection and evaluation of risk-based assessment data; prototyping prior to implementation; post implementation reviews to determine actual project cost, benefits and returns; and focusing on risks and returns using quantifiable measures.

← 39.101 Policy. · 39.103 Modular contracting. →

Rule changes for FAR Part 39

Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Plain words for the terms: glossary.

FAR 39.102 Management of risk · SpendQuery