The indemnity clause in a master services agreement (MSA) under the United States law
US MSA indemnity clause guidance: IP vs. operational risk, causation standards, liability cap interaction, state-specific limits, and negotiation strategies.
Standard Position
In US master services agreements, the indemnity clause allocates risk between service provider and client for third-party claims arising from the engagement. The vendor typically indemnifies the client against claims that the services infringe intellectual property rights or breach law, while the client indemnifies the vendor against claims related to client-supplied materials or instructions. Indemnification is a core risk allocation mechanism distinct from limitation of liability; it often sits outside or alongside caps on direct damages, making it one of the highest-stakes clauses in negotiation.
Legal Basis
US common law recognizes contractual indemnification agreements, provided they are clear and unambiguous about the scope of risk transfer. The UCC (applicable to goods but relevant to interpretation principles) treats indemnity as a risk allocation device. Courts enforce indemnity clauses strictly: ambiguity is construed against the indemnitee (the party being indemnified) in many jurisdictions, though this varies by state. Some states (e.g., California, New York) impose specific statutory limits on indemnification: California Civil Code Section 2782 voids indemnity for the indemnitee's own gross negligence or willful misconduct in construction contracts, and similar public policy limits exist in other contexts. Federal contracts and heavily regulated industries (healthcare, energy) often have statutory caps or exclusions on indemnity scope.
Drafting and Negotiation
The three most contested points are: (1) scope (does indemnity cover the indemnitee's own negligence, or only third-party negligence?), (2) causation (sole cause, comparative fault, or contributory negligence standard?), and (3) exclusions (does it apply to IP claims only, or breach of contract, breach of law, and data breaches?).
Vendors should resist indemnifying the client for claims arising solely from client negligence or breach. Standard market language limits vendor indemnity to claims that the services or deliverables infringe a third party's IP rights or violate law. Clients should push back on carve-outs and insist on a sole-cause or comparative-fault standard so indemnity is not triggered if client's own actions contributed materially to the harm. Many agreements now split IP indemnity from operational/compliance indemnity (e.g., data breach, breach of SLA) because they involve different risk profiles.
A critical issue is whether indemnity is subject to the damages cap elsewhere in the MSA. Market practice splits: some agreements carve indemnity out of the cap entirely (unlimited exposure); others apply the cap to all claims including indemnity. Service providers strongly prefer the latter; sophisticated clients negotiate that IP indemnity is uncapped (because infringement can trigger large awards) but operational indemnity is capped. The indemnifying party's duty to mitigate and the indemnified party's right to control defense and settlement should also be explicit to avoid disputes.
Common Pitfalls
The most frequent trap is ambiguous causation language: "arising out of" is broader than "caused by" and has invited expensive litigation over whether vendor indemnity applies when both parties contributed to harm. Vendors often miss that indemnity for "breach of law" or "violation of applicable law" is dangerously broad because it can cover vendor's strict-liability exposure (e.g., export control violations without intent). Clients sometimes forget that an uncapped IP indemnity can outweigh liability caps by multiples. Finally, many MSAs fail to specify whether the indemnifying party controls the defense and settlement or merely reimburses; this gap can lead to the indemnitee incurring defense costs without the indemnifier's input, then demanding reimbursement, creating conflict.
Sample language
Vendor shall defend, indemnify, and hold harmless Client from any third-party claim alleging that the Services or Deliverables infringe any US patent, copyright, or trade secret, provided that: (a) Client promptly notifies Vendor in writing; (b) Vendor controls all defense and settlement; and (c) Client provides reasonable cooperation. Vendor's obligation shall not apply to claims arising from Client's use of the Services in combination with non-Vendor products, or use in a manner expressly prohibited by this Agreement.
This is general drafting guidance, not legal advice, and not a substitute for advice on your specific facts and jurisdiction. Sample language is a starting point to adapt, not a finished clause.
Frequently asked questions
- What is the difference between indemnity and limitation of liability in a US MSA?
- Indemnity is a promise to defend and reimburse for third-party claims; limitation of liability caps direct damages the indemnitee can recover from the indemnifier for breaches. They serve different purposes: indemnity shifts third-party risk; liability caps control direct losses. Negotiating whether indemnity is subject to the damages cap is critical because uncapped indemnity can exceed the overall liability ceiling.
- Can a service vendor be required to indemnify a client for the client's own negligence?
- It depends on state law and contract language. Many states have public policy limits: some void indemnity for the indemnitee's sole negligence, while others allow it if clearly stated. Vendors should include explicit carve-outs excluding indemnity for claims arising solely from client negligence, gross negligence, or willful misconduct, using clear causation language like 'caused solely by.'
- Should IP indemnity be carved out of the liability cap?
- Yes, in most negotiated agreements. IP infringement claims can result in statutory damages (up to USD 150,000 per work under copyright law) or broad injunctions that far exceed typical service contract liability caps. Market practice increasingly uncaps IP indemnity while capping operational indemnity (data breach, SLA breach) at a fixed multiple of fees paid.
- Who controls the defense and settlement of an indemnified claim?
- Standard language grants the indemnifying party (usually the vendor) sole control of defense and settlement, provided they act reasonably and consult the indemnitee. Without this term, the client may hire counsel and settle without the vendor's input, then demand reimbursement, creating disputes. Always specify approval rights and settlement caps in writing.
Related in the library
- What is indemnity under India law?
- The indemnity clause in a employment agreement under the United States law
- The indemnity clause in a SaaS agreement under the United States law
- The indemnity clause in a non-disclosure agreement (NDA) under the United States law
- The indemnity clause in a SaaS agreement under the UAE law
- The indemnity clause in a master services agreement (MSA) under Singapore law
Adira drafts and reviews contracts under the law of the jurisdiction they work in.
See Adira