> For the complete documentation index, see [llms.txt](https://davidjosearaujo.gitbook.io/online-courses/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidjosearaujo.gitbook.io/online-courses/is-auditing-controls-and-assurance/business-application-development-and-the-roles-of-is-auditors/risks-associate-with-application-development.md).

# Risks Associate with Application Development

When we develop software, **the most important people we need to consider are the users**. If the users are not happy with the system, it won't last long. **The highest risk in software development is when users don't feel comfortable or don't like the system.**

To address this risk, **we need to communicate with the users during the requirement phase and get their feedback**. We should also do a final user acceptance test to make sure the users feel comfortable with the system. This is important because even if we put a lot of time and effort into developing a system with many features, it won't matter if the users don't like it.

There are other risks associated with software development as well. One risk is called **"scope creep"**, which **happens when users or management keep adding new features or modules to the system during the development phase**. This can make the system more complex and increase the risk of failure.

There are also **risks within the project**, with suppliers, within the organization, and in the external environment. For example, if we **don't follow proper system development guidelines** or do good project management, it can be a risk within the project. **If suppliers don't provide the modules we need in a timely manner or with good quality**, it can be a risk with suppliers. **If there are changes in senior management during the development process**, it can be a risk within the organization. And if **competitors develop a better system** or there are **changes in economic conditions or regulations**, it can be a risk in the external environment.

**To reduce these risks, we should spend a lot of time on the requirement phase, communicate with all the users and stakeholders, and do feasibility studies.** It's also important to review and learn from past system implementations to improve future development processes.
