All posts
Operations

8 Questions to Ask Before Renewing (or Walking Away From) Your Vietnam Software Team Contract

Published on 7 Sept 2026

8-questions-to-ask-before-renewing-or-walking-away-from-your-vietnam-software-team-contract

A contract renewal with an offshore software team is a decision that requires testing against actual performance data, not a formality defaulted to on inertia. Before signing the next term, run your current Vietnam software team through eight specific questions covering delivery data, security posture, cost structure, and technical direction. If the team cannot answer these with numbers rather than reassurances, that gap is the real signal, not the sales pitch either side gives you at renewal time.

TL;DR

  • Renewal decisions should be based on delivery metrics your team can produce on request, not general satisfaction.

  • Security certifications (ISO 27001:2022, SOC 2 Type II) need to be checked against your current data handling needs, not just the sales deck from year one.

  • Billing transparency, incident response time, and scaling speed are contractual terms that should be tested against actual performance, not stated intentions.

  • AI adoption inside the SDLC is now a legitimate differentiator worth asking about directly, since throughput gains change what a fair rate looks like.

  • Walking away is sometimes the correct answer, but only after these questions surface a specific, documented gap.

About the Author: 724SOFTWARE has operated dedicated engineering teams and offshore development centres for clients across fintech, healthcare, and enterprise software since its founding. The company currently supports 200+ professionals with a 95% client retention rate across engagements in 10+ countries.

What Should You Actually Measure Before a Renewal Conversation?

A renewal conversation without data is just a feeling dressed up as a decision. Before the meeting, pull three numbers from the last contract term: sprint velocity trend (not a single sprint, the trend across the last two or three quarters), defect escape rate (bugs found in production versus caught in QA), and attrition on your specific team (not company-wide attrition, which can mask a rotating door on your account).

If your vendor cannot produce these numbers within a few days, that is itself informative. A team that has been tracking its own performance will have this ready; a team that has been coasting will need to reconstruct it. Ask for the data before you ask for the renewal terms.

Is the Team's Security Posture Still Matched to What You Actually Handle Today?

Certifications answer a narrower question than most buyers assume: they confirm a management system exists, not that it covers what you need covered right now. ISO 9001 certifies a Quality Management System for consistent delivery; ISO 27001 certifies an Information Security Management System for managing data risk. Critically, the certification scope defines which specific products, services, and locations are covered, so a vendor can be legitimately ISO 27001 certified for one business unit while your engagement sits outside that scope entirely.

If your product has expanded into handling payment data, health records, or EU personal data since the original contract was signed, ask for the current certificate and check the stated scope against your actual data flows. A vendor holding ISO 27001:2022 and SOC 2 Type II with a scope that matches your product represents a different risk position than one holding certificates that predate your current architecture.

How Fast Can the Team Actually Scale, and Does That Match Your Roadmap?

Scaling speed is a contractual variable, not a marketing claim, and it should be tested against your next 12 months of roadmap before renewal. Standard roles in a Vietnam-based team typically scale up in 2 to 4 weeks; specialized senior roles, particularly niche stacks or domain-specific expertise, can take 8 to 14 weeks. Scaling down usually carries a notice period of 30 to 60 days written into the SLA.

If your roadmap includes a major feature push, a new product line, or a compliance-driven build-out, map that against these windows now, not when you need the engineers. A vendor that scaled you from 3 to 8 people in three weeks last year has already demonstrated the capability; one that has never been tested at scale is an unknown quantity regardless of what the contract promises.

Is Your Billing Actually Transparent, or Just Itemized?

An itemized invoice is not the same thing as a transparent one. Itemization tells you what was billed; transparency lets you verify that what was billed matches what was worked. Before renewal, ask whether you have direct visibility into time tracking, sprint boards, and team health indicators, or whether you are relying entirely on monthly summaries produced by the vendor.

The distinction matters most when disputes happen. A vendor billing on actual working hours with client-visible tracking gives you the ability to audit a disputed invoice yourself. A vendor billing on estimated or bundled hours with no client-side visibility leaves you negotiating from a position where you cannot independently verify the claim either way.

Has the Team Adopted AI Tools in a Way That Shows Up in Output, or Just in Conversation?

This is now a fair question to put to any software vendor in 2026, and the answer separates teams that have integrated generative AI into daily delivery from teams that mention it in sales meetings. Claude is built for instruction following and complex reasoning with a 200K context window, for code review, refactoring logic, and multi-step engineering tasks, while Gemini's native multimodal capabilities and 1-million-token context window make it stronger for ingesting large documents, specs, or codebases at once.

Ask specifically which tools your engineers use day to day, for what tasks, and whether that shows up in cycle time. 724SOFTWARE is a selected Anthropic partner in Vietnam and trains its engineering teams to use Claude Code as a normal part of delivery, which is the kind of concrete detail a vendor should be able to describe rather than gesture at. If your current team cannot name the tool, the workflow, or a specific task it accelerates, treat "we use AI" as an unverified claim until proven otherwise.

What Happens When Something Breaks at 2 AM Your Time?

Incident response is a timezone problem disguised as a technical one, and it is worth testing rather than assuming. Ask for the actual SLA number in the contract, not a general description. A stated incident response time under 10 minutes, backed by a follow-the-sun coverage model, is a specific commitment you can hold a vendor to; "we're always available" is not.

Pull your incident log from the last term and check how often the stated response time was actually met. A vendor that quotes a specific SLA on paper but has missed it repeatedly in practice is a bigger renewal risk than one with a more modest SLA that has never slipped.

Does the Team Still Fit Your Product's Current Technical Direction?

A team hired for one architecture doesn't automatically fit the next one. If your product has moved from a monolith toward microservices, added a mobile layer, or shifted from batch processing toward real-time data pipelines, check whether your current team's skill composition reflects that shift, or whether they've been stretching into unfamiliar territory without you fully realizing it.

This is less about competence and more about fit. A senior engineer experienced in legacy enterprise systems is not automatically the right person to lead a real-time trading feature or a mobile-first rebuild. Ask directly what percentage of the team has hands-on experience in your current stack versus your original stack.

When Is Walking Away the Right Call?

Walking away is justified when the previous seven questions surface a specific, documented gap that the vendor cannot close within a reasonable window, not because a competitor's pitch sounded better. The distinction matters because switching vendors carries real transition cost: ramp-up time, knowledge transfer, and a reduction in velocity that a renewal avoids entirely.

The right test is whether the gap is structural or fixable. A missing security certification that covers your current data scope is structural and often not fixable on short notice. A team that hasn't yet adopted Claude or Gemini into its workflow but is willing to commit to a defined ramp-up is fixable. Separate the two before deciding.

Frequently Asked Questions

How long before contract renewal should this review start?

Start 60 to 90 days out. This gives enough runway to pull historical data, test SLA compliance, and, if needed, begin a transition without a service gap.

Is it normal for a vendor to push back on providing delivery metrics?

Some pushback on format is normal; outright refusal to share velocity, defect, or attrition data specific to your team is a red flag worth raising directly.

Does switching vendors always mean starting from zero on domain knowledge?

Not if handled correctly. A structured knowledge transfer period, typically 4 to 8 weeks depending on system complexity, should be a contractual deliverable from an outgoing vendor.

Should AI tool adoption change what I'm willing to pay?

It should change what you expect for the price you're already paying. Integrating generative AI into your SDLC is an argument about throughput, not simply a discount lever.

What's a reasonable notice period if I decide to walk away?

Standard practice is 30 to 60 days, matching the scale-down notice period typically written into offshore development SLAs.

Can I ask for a security scope review without it being adversarial?

Yes. Framing it as a routine compliance check ahead of contract renewal is standard practice and shouldn't be read as an accusation.

About 724SOFTWARE

724SOFTWARE operates as a long-term technology partner for companies building and operating digital products, not a one-off project vendor. The company runs dedicated teams and offshore development centres from Vietnam, scaling from 1 to 50+ pre-vetted engineers within 2 to 4 weeks, backed by ISO 9001, ISO 27001:2022, SOC 2 Type II, and GDPR compliance. As a selected Anthropic partner, 724SOFTWARE trains its engineers to use Claude Code as part of standard delivery, supported by a follow-the-sun model with sub-10-minute incident response and transparent billing on actual working hours.

If your current contract renewal conversation is missing hard data on any of the questions above, that's worth a direct conversation. Visit 724SOFTWARE to talk through what a renewal review, or a transition plan, would look like for your team.

Share this article

Operations

Shrimpie Tran

AI Engineer

Keep Reading

Explore more from our experts.

View all

Stay ahead with our insights.

Get the latest on software design, strategy, and what's working in the field.

We respect your inbox. Unsubscribe anytime from any email.