Blog
Choosing a Custom Software Vendor: 7 Questions to Ask Before You Sign
Before signing with a custom software vendor, ask these 7 questions to avoid budget overruns, IP disputes, and failed deliveries.
- bottom
Only about 30% of large-scale software projects meet their time, budget, and scope targets. The other 70% end up delayed, over budget, or abandoned — and post-mortem analysis consistently points to the same root cause: buyers did not ask hard enough questions before signing. If you are evaluating a custom software vendor right now, this article gives you the seven questions that separate credible firms from expensive disappointments.
Why the Stakes Are Higher Than They Look
Budget overruns are not rare edge cases. Large IT initiatives exceed their budgets by roughly 45% on average, and scope creep affects more than half of all projects. A $150,000 engagement can quietly become $220,000 by month four — not because the vendor is dishonest, but because both sides failed to define accountability upfront. The seven questions below create that accountability before a single line of code is written.
The 7 Questions
1. Can you show on-time and on-budget delivery rates for comparable projects?
Any vendor can supply a polished portfolio. What you want is delivery metrics: percentage of projects completed within 10% of the original budget, percentage delivered within the agreed timeframe, and defect rates post-launch. Ask for data from at least ten comparable engagements. If the answer is vague, treat it as a red flag.
What to watch for: A vendor that bids 10% or more below the competition is almost certainly misunderstanding your scope or planning to recover margin through change orders later.
2. Who owns the code — and can I see that in the contract right now?
This question trips up more buyers than any other. Without explicit “work-for-hire” or “present assignment” language in the contract, intellectual property may legally remain with the developer under US and EU copyright law. “We agree to assign” is weaker than “we hereby assign” — the former requires a follow-on action; the latter transfers ownership immediately on creation.
Also ask about source-code escrow. A neutral third party holds your build documentation, database schemas, configuration files, and deployment assets, and releases them if the vendor goes insolvent, is acquired, or stops providing support. This is not paranoia — it is standard practice for any system your business depends on.
3. What certifications and compliance posture do you hold?
For most US and EU clients the minimum bar is SOC 2 Type II and, if you process European personal data, a signed Data Processing Agreement covering GDPR obligations. If your product touches healthcare, ask for a HIPAA Business Associate Agreement. Financial services firms should ask about DORA readiness.
Request the actual certificate, not a marketing claim. Also ask for a penetration test conducted within the last twelve months and a full list of sub-processors — the third parties the vendor will use to build or host your product. Vendors who treat this list as confidential create compliance exposure that flows back to you.
4. Who will actually work on my project?
The classic bait-and-switch is presenting senior architects in the sales process and assigning junior staff after the contract is signed. Ask for the names and LinkedIn profiles of the people who will be on your account. Ask directly: “Will any of the people in this meeting work on my project?” Get the team composition confirmed in the contract.
Also ask about annual team turnover. Rates above 20% are a material risk — institutional knowledge leaves with each departure, and you pay for the re-onboarding.
5. How do you handle scope changes, and what are the change-order limits?
Most projects evolve. The question is not whether scope will change — it will — but what authorization is required before additional spend is committed. A well-run vendor will define a written change-request process with dollar thresholds: below $X, a project manager can approve; above $X, your sign-off is required. Time-and-materials contracts with no caps or authorization limits are open-ended cost exposure. If your vendor proposes T&M, negotiate a not-to-exceed ceiling.
6. What do your SLAs actually say — and what happens when you miss them?
Service-level agreements are only meaningful if the penalties are real. Ask two specific questions. First, what are the exact uptime, response-time, and defect-rate targets? Second, what are the consequences of missing them — and do those consequences include earnback provisions that allow the vendor to offset credits through future performance? Earnback clauses are common and can render an SLA effectively unenforceable. Require liquidated damages tied to specific metrics, not service credits that the vendor can earn back.
7. Can I speak to three current clients and two who left?
References from happy, long-running clients tell you the vendor is good at sustaining relationships. References from clients who left — or who recently went through implementation — tell you how the vendor behaves under pressure. Ask former clients why they switched, whether the final cost matched the proposal, and whether they received full code and data on exit. Ask recent-implementation clients how often the timeline slipped and how disputes were handled.
A vendor who provides only glowing multi-year testimonials is curating the narrative. A vendor who offers you a churned client’s contact number is confident in what that client will say.
The Threshold That Saves You Money
A weighted evaluation across technical capability, security posture, process maturity, team quality, cost transparency, IP protection, communication, and long-term fit will surface whether a vendor is genuinely strong or merely well-presented. One framework suggests scoring vendors 0–10 across these dimensions and rejecting any composite score below 55 out of 100 outright, regardless of price. That threshold is not arbitrary — it correlates with the projects that actually ship.
Before You Sign
The seven questions above are not a negotiating tactic. They are the minimum standard of due diligence for any custom software engagement. Vendors who find them unreasonable are telling you something important about how they will behave once the contract is signed.
If you are currently evaluating vendors and would like a second opinion on what you have been told — or on a proposal you have received — we are happy to talk through it with you at no charge. No pitch, just a candid conversation.
Sources: Vervali — How to Choose a Software Development Company in 2026; Gitnux — Software Project Failure Statistics; Escode — What Is Software Escrow?. Figures current as of mid-2026; verify against primary sources before acting.