Statement of work: learning platform and content services
Written by a person. Last read by a person on 2026-09-07, 1 day ago. Its facts were checked by the eval suite on 2026-09-07.
You are judging procurement judgment, or you want to see what a real out-of-scope section looks like.
Scenario-based sample. Halden Systems is invented, and so is every figure about it.
Between Halden Systems and the selected supplier.
Bottom line. 4 deliverables, each with acceptance criteria a third party could apply without us in the room. Payment follows acceptance, never a date. What is out of scope is listed at the same length as what is in, because that is the half every dispute turns on.
Deliverables and acceptance criteria
Acceptance is a test somebody outside both organizations could run. Where a criterion needs judgment, it names who exercises it and against what.
| # | Deliverable | Accepted when |
|---|---|---|
| D1 | Platform configured for 9 sites | 3 named staff at each site complete a scripted task list unaided, in their own timezone, on their own device |
| D2 | Content migration of 140 existing units | 100% render without manual repair, and a random sample of 20 passes our accessibility standard |
| D3 | Assessment engine wired to our identity provider | A revoked account loses access within 15 minutes, verified by our security team |
| D4 | Reporting against the 4 measurement levels | Every figure in the strategy document can be produced from the platform without a spreadsheet |
D4 is the one vendors negotiate hardest and the one we hold. A platform that cannot report level 2 leaves us measuring completion again, which is the failure the program exists to correct.
Out of scope
Listed at length on purpose. A vendor who has read this and signed cannot later present any of it as a change order, and we cannot later expect it for free.
Content authoring. The vendor migrates what exists and builds none of it. Our staff write the material, because the material is the capability and outsourcing it defeats the program.
Anything touching production engineering systems. The platform reads our identity provider and nothing else. No repository access, no pipeline integration, no write path into an engineering tool. This is a security boundary rather than a preference.
Translation and localization. 4 continents and we are still delivering in English. That is a known gap, it is recorded in the strategy, and it is not being solved by this contract.
Change management and internal communications. The vendor does not talk to our staff. Adoption is our problem and buying it produces a rollout with no owner inside the company.
Success metrics beyond the 4 levels. No engagement scores, no leaderboards, no completion dashboards presented as outcomes. We already have too much of that number.
Data migration out. Export is in scope. Anything the vendor would do to help a successor is not, and we have priced our own exit accordingly.
Payment against acceptance
| Milestone | Share | Released on |
|---|---|---|
| Contract signature | 10% | Signature |
| D1 accepted | 25% | Acceptance test passed at all 9 sites |
| D2 and D3 accepted | 30% | Both, not either |
| D4 accepted | 25% | Acceptance, plus 30 days of reporting we did not have to correct |
| Retention | 10% | 90 days after D4, held against defects |
No milestone is released on a date. A vendor who is late is late, and a vendor who is late and paid has been told that the schedule is ours to worry about.
The 30-day tail on D4 exists because reporting is the deliverable most likely to pass a demo and fail in use.
When acceptance fails
First failure. The vendor has 15 working days to remedy, at their cost. The clock on dependent milestones stops. This is expected at least once and is not a dispute.
Second failure on the same deliverable. We take a 15% reduction on that milestone and either accept the remedy or move the deliverable out of scope with a matching reduction. Which of those happens is our choice, not theirs.
Third failure, or a failure on D3. Termination for cause, retention forfeit, and the export obligation triggers immediately. D3 is singled out because a security boundary that fails twice is not a quality problem.
If we cause the failure. Where acceptance fails because we did not supply access, data or people on time, the remedy period pauses and the vendor is entitled to a schedule extension of the same length. Stating this protects the relationship: a buyer who never admits a cause is a buyer vendors price defensively.
Governance after signature
Monthly against the scorecard in the budget and vendor document. The relationship after signature is where most of the money is actually lost, and a statement of work that ends at acceptance has described the cheapest part of the contract.