Contract review guide
How to Review a Master Services Agreement (MSA)
A master services agreement (MSA) is the umbrella contract that governs an ongoing commercial relationship between a customer and a supplier. It sets the legal terms once (liability, indemnities, intellectual property, confidentiality, termination) so that each new piece of work can be ordered through a short statement of work (SOW) without renegotiating the whole deal. Because the MSA is signed early and rarely reopened, the terms you accept on day one tend to govern every project that follows for years. That is exactly why a careful review matters: a weak liability cap or a badly drafted IP clause does not hurt in the demo, it hurts in the dispute.
This guide walks through an MSA the way an experienced commercial lawyer reads one, section by section, explaining what each clause does, what to check and why, what "good" looks like versus what should make you push back, and the red flags that signal a one-sided draft. It is general legal information for building your commercial literacy, not legal advice, and specific outcomes depend on your jurisdiction and facts, so treat the jurisdiction-sensitive points as prompts to confirm with a qualified lawyer rather than settled rules.
Structure: how an MSA fits together with SOWs
The single most important structural idea in an MSA is the split between the master terms and the individual orders. The MSA holds the standing legal terms; each SOW (sometimes called an order form, work order, or schedule) describes a specific engagement, its deliverables, timeline, fees, and any project-specific variations. Read them as one instrument, because a term buried in a SOW can quietly override the master document.
MSA vs SOW and order of precedence
When the master terms and a SOW conflict, which one wins? A well-drafted MSA answers this with an order-of-precedence clause. The conventional default is that the MSA controls except where a SOW expressly states it is amending a specific numbered clause of the MSA for that engagement only. This protects both sides from a salesperson slipping a liability waiver into a SOW that nobody's legal team reviewed.
Watch the direction of precedence carefully. A clause reading "in the event of conflict, the terms of the applicable SOW shall prevail over this Agreement" flips the usual protection and means every SOW can silently rewrite your negotiated master terms. Prefer language such as "the MSA governs unless a SOW expressly references and amends a specific section, in which case the amendment applies only to that SOW."
- Good: MSA prevails; SOWs may vary only by express, section-specific reference.
- Push back: blanket "SOW prevails" language, or silence on precedence altogether.
- Check whether purchase orders, click-through terms, or online policies referenced by URL are incorporated, and whether they can change unilaterally.
Scope and change control
The MSA should define how scope is set and how it changes. Loose scope language ("and related services as reasonably required") invites scope creep that the supplier bills for or the customer expects for free. A change-control procedure fixes this: changes to scope, fees, or timeline must be documented in a signed written change order before work proceeds. Confirm that neither party can unilaterally expand or vary the work, and that pricing for changes is either pre-agreed or tied to a rate card in a schedule.
Money: fees, invoicing, and pricing terms
Commercial terms are where reviews are often too quick. Check the fee model (fixed fee, time and materials, subscription, or milestone-based), what triggers an invoice, and the payment window. A 30-day term is common; watch for shorter windows or terms that start on "invoice date" rather than "receipt of a valid, undisputed invoice."
Invoicing, expenses, and late interest
Confirm whether fees are exclusive of tax and whether expenses are billable. If expenses are billable, require pre-approval above a threshold and reasonable, receipted, actually-incurred costs, not a percentage uplift. Late-payment interest is normal, but check the rate and note that in some jurisdictions statutory interest applies by default; an unusually high contractual rate may be challengeable as a penalty in some legal systems, so treat the number as jurisdiction-sensitive.
Price increases and most-favoured pricing
For multi-year deals, look at how prices can rise on renewal. "Good" is a cap tied to an inflation index or a fixed percentage with prior notice; "push back" is an uncapped right to increase fees at the supplier's discretion. Customers sometimes seek a most-favoured-customer clause (a promise that pricing is no worse than comparable customers get), but these are hard to police and suppliers resist them; if included, define the comparator narrowly so it is actually verifiable.
The liability cap and its carve-outs
The limitation of liability clause is usually the most heavily negotiated part of an MSA, because it decides how much either side can actually recover when something goes wrong. Read it as two questions: what is the cap, and what escapes the cap.
The cap is a ceiling on damages, most commonly tied to the fees paid or payable under the relevant SOW over a defined lookback (often the trailing 12 months). A fees-based cap is conventional, but a cap set at "fees paid in the prior 12 months" can be tiny early in a contract, so consider a floor (a minimum dollar figure) or a multiple of annual fees for high-risk engagements. Also confirm the clause excludes indirect and consequential losses and, separately, whether it excludes loss of profit, data, or goodwill, since those exclusions can gut a genuine claim.
What should sit outside the cap
Certain liabilities are conventionally carved out of the cap so they are either uncapped or subject to a much higher super-cap. Confirm the carve-outs are mutual and complete.
- Breach of confidentiality obligations.
- IP infringement (typically the supplier's indemnity for third-party IP claims).
- Data protection and security breaches, or a separately negotiated data-breach super-cap.
- Death or personal injury caused by negligence, and fraud or fraudulent misrepresentation, which most legal systems will not let a party exclude anyway.
- Gross negligence and wilful misconduct, and a party's indemnification obligations.
- Push back if the supplier caps its indemnities at the fee level, which makes the indemnity close to worthless; carve indemnities out of, or give them a much higher, cap.
Indemnities
An indemnity is a promise to cover another party's losses from defined events, and it usually gives a cleaner, faster route to recovery than a breach-of-contract claim. Read who indemnifies whom, for what, and subject to what cap.
The core supplier indemnity is for third-party claims that the deliverables or services infringe a third party's IP; a strong version also covers the supplier's obligation to procure a licence, modify, or replace the infringing item, and excludes claims arising from the customer's own modifications or misuse. Expect mutual indemnities for third-party claims caused by a party's negligence or breach, and, where personal data is processed, a data-breach indemnity. Check the procedure: prompt notice, control of the defence, a duty to cooperate, and no settlement that admits fault or binds the other party without consent. Push back on one-way indemnities running only in the supplier's favour, or indemnities that are capped down to the general liability cap.
Intellectual property
IP is where services deals are won or lost, and the drafting distinction that matters is between newly created deliverables and pre-existing (background) IP.
Deliverables vs background IP and licences
For custom work, customers usually expect to own the deliverables created specifically for them, with assignment taking effect on creation or on payment. Suppliers usually retain their pre-existing tools, templates, know-how, and any generic components (their "background IP") and grant the customer a licence to use them to the extent embedded in the deliverables. Confirm three things: that ownership of bespoke deliverables actually transfers (and is not merely licensed), that any licence to background IP is broad enough to actually use and maintain the deliverable (perpetual, irrevocable, and sublicensable where needed), and that the supplier keeps a fair licence back to reuse its own generic know-how so it is not accidentally handing you its whole toolkit. Watch for "supplier owns everything, customer gets a licence" drafting where a customer paid for bespoke development, and for silence on residual rights to general skills and knowledge.
Warranties, disclaimers, and service levels
Warranties are promises about quality; the disclaimer is the supplier limiting them.
Warranties and disclaimers
Expect a workmanlike-services warranty ("Services will be performed in a professional and workmanlike manner in accordance with the SOW and applicable industry standards"), an authority warranty, and, for software, a warranty that deliverables will materially conform to the agreed specification for a stated period. Suppliers then disclaim implied warranties such as merchantability and fitness for a particular purpose. That disclaimer is normal, but check the express warranty still has teeth and a real remedy (re-perform, repair, or refund), rather than being disclaimed into nothing.
SLAs and service credits
For managed or hosted services, service levels (uptime, response and resolution times) sit in an SLA schedule, and breach triggers service credits, a defined discount on the fees. The single most important question is whether service credits are the sole and exclusive remedy for missed service levels. If they are, and the credits are small, the customer effectively has no meaningful recourse for chronic underperformance. "Good" makes credits a first remedy but preserves a right to terminate for persistent or material SLA failure and to claim other remedies for serious breach; "push back" where credits are capped low and declared the only remedy. Also check how uptime is measured, what maintenance windows are excluded, and how a customer actually claims a credit, since credits that must be requested within a short window often go unclaimed.
Confidentiality, data protection, and security
The confidentiality clause should be mutual, define confidential information sensibly, permit disclosure only on a need-to-know basis, and survive termination (trade secrets often indefinitely, other confidential information for a fixed tail of several years). Check that residual-knowledge clauses (allowing use of information retained in memory) are not so broad they swallow the obligation.
Where personal data is involved, the MSA should attach or reference a data processing agreement or addendum (DPA) allocating controller and processor roles, permitted purposes, security measures, breach-notification timelines, sub-processor controls, cross-border transfer mechanisms, and audit rights. Data protection law is highly jurisdiction-specific, so confirm the addendum matches the regimes that actually apply to your data. A separate security schedule setting minimum technical and organisational measures is a strong sign of a mature supplier; its absence on a data-heavy deal is a red flag.
Term, termination, and what survives
How the relationship ends deserves as much attention as how it begins.
Term and renewal traps
Check the initial term and, critically, the renewal mechanism. Auto-renewal is the classic trap: a clause that renews the term automatically unless a party gives notice a long way out (say 90 days before expiry) can lock a customer into another full term simply because a diary date slipped. "Good" is a short, clearly stated non-renewal notice window, ideally with a reminder obligation; "push back" on long lookbacks combined with automatic multi-year renewals and uncapped price increases on renewal.
Termination for cause vs convenience
Expect a right to terminate for material breach that is uncured after a cure period (commonly 30 days), and for insolvency events. Termination for convenience (ending without cause on notice) is valuable but often one-sided; check whether both parties have it, the notice length, and any early-termination or wind-down fees. Also confirm the effect of termination: fees for work done, return or deletion of confidential information and data, handover and transition assistance, and the fate of licences granted.
Survival
A survival clause lists the obligations that continue after the contract ends. At minimum it should include confidentiality, IP ownership and assignments, accrued payment obligations, limitation of liability, indemnities, dispute resolution and governing law, and any data-return or deletion duties. Check that survival is not accidentally narrow, because a liability cap or confidentiality duty that dies at termination offers little protection when disputes usually surface afterwards.
Assignment, subcontracting, insurance, and boilerplate that bites
The clauses near the back of an MSA look like standard form, but several of them decide real outcomes.
Assignment and change of control
Assignment clauses govern who can transfer the contract. A common position is no assignment without consent, with a carve-out allowing assignment to an affiliate or to a buyer of substantially all the business. Consider whether a change of control of the other party should trigger a right to consent or terminate, especially if you would not want the contract, or your data, ending up with a competitor.
Subcontracting and insurance
Check whether the supplier can subcontract freely and, if so, that it remains fully liable for subcontractors' acts and omissions and binds them to equivalent confidentiality and data terms. On insurance, confirm the supplier carries appropriate cover (professional indemnity, cyber, and general liability as relevant) at levels proportionate to the risk, and that the requirement is a real covenant, not aspirational.
Dispute resolution, governing law, and boilerplate
Governing law and jurisdiction (or an arbitration clause with seat and rules) determine where and how disputes are resolved, and litigating far from home is costly, so treat these as commercial terms, not afterthoughts. Then read the quiet boilerplate that bites: entire-agreement clauses (which can exclude reliance on pre-contract promises), notice provisions (which decide whether an email counts), "time is of the essence," force majeure scope, no-waiver, severability, and any unilateral right to amend terms by posting an updated policy. Non-solicitation and exclusivity clauses also hide here and can restrict your business well beyond the deal itself.
How to review an MSA in Weave
A first pass on an MSA is mostly navigation: jumping between the liability cap, its carve-outs, the indemnities, the IP clause, and the definitions that tie them together, then keeping notes on what to negotiate. Weave is a free, no-login tool to read, mark up, and connect any contract in your browser. Open the MSA, highlight the cap and each carve-out, link the indemnity clause to the IP and confidentiality provisions it depends on, and keep your negotiation points attached to the exact language they refer to, so nothing gets lost between the read and the redline.
Red flags in an MSA
- "SOW prevails over the MSA" precedence language, letting unreviewed orders rewrite negotiated terms.
- A liability cap that also caps indemnities, IP infringement, confidentiality, and data-breach liability at the fee level.
- A fees-paid cap with no floor early in the term, and exclusions that remove loss of profit, data, and goodwill.
- One-way indemnities, one-way termination for convenience, or one-way price-increase rights.
- Service credits declared the sole and exclusive remedy for SLA failures, with no right to terminate for chronic breach.
- Supplier retains ownership of bespoke deliverables the customer paid to develop, granting only a narrow licence.
- Auto-renewal with a long non-renewal notice window plus uncapped renewal price increases.
- A unilateral right to amend terms, policies, or fees by posting an updated version.
- No data processing addendum or security schedule on a deal involving personal or sensitive data.
- Narrow survival that lets confidentiality or the liability cap expire at termination.
What to check in an MSA
- Order of precedence — so a SOW cannot silently override negotiated master terms.
- Scope and change control — to stop scope creep and unpriced variations.
- Fees, invoicing, expenses, and late interest — to know what triggers payment and at what rate.
- Price increases and renewal pricing — capped to an index or fixed percentage, not discretionary.
- Liability cap level and structure — fees-based with a floor or super-cap for high-risk work.
- Cap carve-outs — confidentiality, IP, data breach, gross negligence, fraud, and indemnities.
- Indemnities — mutual, IP and data covered, with a workable defence procedure.
- IP ownership — bespoke deliverables assigned; background IP licensed broadly enough to use.
- Warranties and remedy — an express services warranty with real re-perform, repair, or refund rights.
- SLAs and service credits — whether credits are the sole remedy and how they are claimed.
- Confidentiality and data — mutual duties, a DPA, and a security schedule where data is processed.
- Term and auto-renewal — a short, clear non-renewal notice window.
- Termination — for cause with cure, insolvency, and whether convenience is mutual.
- Effect of termination and survival — data return, transition help, and which clauses live on.
- Assignment, change of control, subcontracting, and insurance — who can transfer and who stays liable.
- Dispute resolution, governing law, and boilerplate — where you would litigate and what quietly binds you.
Questions
- What is the difference between an MSA and an SOW?
- An MSA sets the standing legal terms for an ongoing relationship (liability, IP, confidentiality, termination), while a statement of work (SOW) describes one specific engagement: its deliverables, timeline, and fees. You sign the MSA once and add a short SOW for each project. Read them together, because a well-drafted MSA says which document prevails when they conflict.
- What is a reasonable liability cap in an MSA?
- There is no universal number, but a common structure ties the general cap to the fees paid or payable over the trailing 12 months, with higher-risk deals adding a floor or a multiple of annual fees. What matters as much as the figure is what escapes the cap: confidentiality breaches, IP infringement, data breaches, gross negligence, and fraud are conventionally carved out and should not be squeezed down to the fee-level cap.
- What should survive termination of an MSA?
- At a minimum: confidentiality, IP ownership and assignments, accrued payment obligations, the limitation of liability, indemnities, dispute resolution and governing law, and any obligation to return or delete data. Because most disputes surface after a contract ends, a survival clause that lets the liability cap or confidentiality duties expire at termination leaves a real gap.
- Are service credits the only remedy for missed SLAs?
- Only if the contract says so. Many SLAs declare service credits the "sole and exclusive remedy" for missed service levels, which can leave a customer with little recourse for chronic underperformance if the credits are small. A balanced clause treats credits as a first remedy but preserves the right to terminate for persistent or material SLA failure and to claim other remedies for serious breach.
- Who owns the IP created under an MSA?
- It depends on the drafting. For bespoke deliverables a customer paid to have built, customers usually expect ownership to be assigned to them. Suppliers usually keep their pre-existing tools and know-how (background IP) and license the customer to use them as embedded in the deliverables. Check that bespoke work is actually assigned rather than merely licensed, and that any background-IP licence is broad enough to use and maintain the deliverable.
- What is an order-of-precedence clause and why does it matter?
- It states which document wins when the MSA and a SOW (or an order form or online policy) conflict. The safer default is that the MSA governs unless a SOW expressly amends a specific numbered clause for that engagement. Without this, a term slipped into a SOW that legal never reviewed can quietly override your negotiated master terms.
- What is the auto-renewal trap in an MSA?
- Many MSAs renew automatically for a further term unless a party gives notice well before expiry, sometimes 60 to 90 days out. Miss that window and you can be locked into another full term, occasionally at increased prices. Look for a short, clearly stated non-renewal notice period and ideally a reminder obligation, and diarise the deadline as soon as you sign.
- Is reviewing an MSA yourself a substitute for legal advice?
- No. This kind of guide builds commercial literacy and helps you spot issues and ask better questions, but it is not legal advice, and many clauses (limitation of liability, indemnities, data protection, penalties, and governing law) turn on jurisdiction-specific rules. For a material contract, have a qualified lawyer in the relevant jurisdiction review the final terms.
Mark up your next MSA in Weave
Free, no account, in your browser. Sign up only to save or share.
Not legal advice. Weave is an informational tool to help you read and mark up a contract. It does not provide legal advice, and using it does not create a lawyer–client relationship. For advice on your specific situation, consult a qualified lawyer.
Your document, kept private. When you open a document in Weave, it is sent to Adira to build your workspace and kept private to your session. We do not train AI models on your documents. Nothing is shared. Create a free account to save your work; otherwise it stays with your temporary session.