Aug 12, 2026 19 mins

How to Review a Master Service Agreement: A Clause-by-Clause Guide

Legal Reviewer
How to Review a Master Service Agreement: A Clause-by-Clause Guide

The best AI tool to draft and review a master service agreement is one that reads the whole document in context, flags the clauses that carry commercial and legal risk, and suggests specific redline language you can accept or edit. That means an AI-native contract platform built for the legal work a business does on its own agreements, not a generic chatbot you paste clauses into. For mid-market trading businesses handling MSAs at volume, the right tool combines clause detection, playbook-driven positions, and drafting inside the tools your team already uses.

But the tool only earns its keep if you know what you are looking for. An MSA is a framework: it sets the terms that govern every future engagement, while the commercial detail lives in statements of work underneath it. Get the framework wrong and you inherit that mistake across every SOW for years. This guide walks the split between the MSA and the SOW, then goes clause by clause through the provisions that decide who carries the risk, with specific pushback points for when the contract arrives on the counterparty's paper.

What an MSA actually does, and why the SOW split matters

A master service agreement is the layer that governs a relationship over time. It handles the terms you do not want to renegotiate every time you buy or sell a piece of work: liability, indemnities, IP ownership, confidentiality, termination, insurance, governing law. It is designed to be signed once and referenced many times.

The statement of work (sometimes called an order form, work order, or SOW) sits underneath the MSA and describes a specific engagement: scope, deliverables, timeline, fees, acceptance criteria, and any service levels particular to that piece of work. You can sign many SOWs under a single MSA.

This split exists for good reasons, but it creates traps:

  • Order of precedence. When the MSA and a SOW conflict, which wins? A well-drafted MSA states the answer. The usual default is that the MSA governs except where a SOW expressly overrides a specific clause. Watch for language that lets any SOW silently rewrite your liability cap or IP terms.
  • Scope creep by SOW. Because SOWs are often signed by operational people, not legal, a counterparty can smuggle unfavourable terms into a SOW that were rejected in the MSA. Lock down which clauses a SOW may and may not amend.
  • Orphaned obligations. Confidentiality, IP and liability should survive the end of any individual SOW and often the MSA itself. Check the survival clause names them.

Before you review a single clause, answer three questions: Are you the customer or the supplier? Is this your paper or theirs? And how much annual spend or revenue runs through this relationship? Your negotiating posture on every clause below flips depending on the answers.

Liability caps: the number that decides everything

The limitation of liability clause is where most of the money is. It sets the maximum either party can recover if things go wrong. Read it first, because it colours how hard you fight everywhere else.

The typical structure has three parts:

  1. The exclusion of indirect and consequential loss. Both sides usually agree neither is liable for indirect, consequential, or special losses. The fight is over what counts. Loss of profit, loss of revenue, loss of anticipated savings and loss of data are frequently pulled out and excluded by name. If you are the customer, an over-broad exclusion can leave you with a breach and no meaningful remedy.
  2. The cap on direct loss. This is the headline number, usually expressed as a multiple of fees paid in a defined period (commonly 12 months) or a fixed sum. As a supplier you want it low and tied to fees. As a customer you want it high enough to cover your realistic downside.
  3. The carve-outs. Certain liabilities sit outside the cap entirely, either because law forbids limiting them or because the parties agree they should be uncapped. Death and personal injury caused by negligence, and fraud, cannot be excluded under English law and should never appear inside the cap.

What to push back on when it arrives on their paper:

  • A cap set as a fraction of fees. "50% of fees paid in the prior three months" is a common supplier opener. For a critical service, that number may not cover a single serious incident. Push for at least the trailing 12 months, and higher for data or safety-critical work.
  • Everything caught by the cap. Confidentiality breaches, IP infringement indemnities and data protection liabilities are often carved out and given their own higher sub-cap or uncapped treatment. If the counterparty's draft sweeps all of these under one low cap, that is your first redline.
  • Mutual caps that are not actually mutual. Check the cap applies symmetrically. A "mutual" cap that only bites on your side because your fees are the reference point is not mutual in substance.
  • Aggregate vs per-claim. An aggregate cap across the whole relationship is far more protective for the party being sued than a per-claim cap. Know which you have.

A common landing zone: mutual cap at 12 months' fees or a fixed sum, whichever is greater, with separate treatment for data protection, confidentiality and IP indemnity, and the mandatory carve-outs sitting outside the cap.

Indemnities: where you agree to pay for someone else's problem

An indemnity is a promise to reimburse the other party for specified losses, usually on a pound-for-pound basis and often without the usual requirements to prove the loss was foreseeable. Indemnities can bypass the very liability cap you just negotiated, so they need close reading.

The indemnities you commonly see in an MSA:

  • IP infringement. The supplier indemnifies the customer against claims that the deliverables infringe a third party's intellectual property. This is reasonable; the supplier controls what it builds.
  • Data protection breach. Increasingly common, and heavily negotiated because regulatory fines and individual claims can be large.
  • Third-party claims generally. Watch for broad indemnities that cover any third-party claim "arising out of or in connection with" the agreement. That phrase is wide enough to catch things well beyond the giving party's fault.

Pushback points on the counterparty's draft:

  1. Reciprocity. If they want you to indemnify them, ask what they indemnify you for. One-way indemnity clauses are a signal to read the whole document more sceptically.
  2. Cap the indemnity. Uncapped indemnities are the single most common way a carefully negotiated liability cap becomes worthless. Bring indemnities inside the cap, or under a defined higher sub-cap, unless there is a genuine reason for them to be uncapped.
  3. Fault-based triggers. Narrow the trigger from "arising out of or in connection with" to losses caused by the indemnifying party's breach, negligence or wilful misconduct. That single change removes a lot of unquantifiable exposure.
  4. Conduct of claims. The indemnity should require prompt notice, control of the defence by the indemnifying party, and no admission or settlement without consent. Without these, you can be liable for a claim someone else mishandled.
  5. Standard IP carve-backs. A supplier's IP indemnity should not cover infringement caused by the customer's own modifications, use outside the agreed scope, or combination with third-party materials the supplier did not supply. These carve-backs are standard and fair.

Intellectual property: who owns what you make together

IP clauses decide who owns the deliverables, the tools used to create them, and anything improved along the way. Getting this wrong means paying for something you cannot fully use, or handing away assets you meant to keep.

Break the IP into three buckets and check the clause addresses each:

  • Background IP. What each party brings to the table, owned before the engagement or developed independently. This stays with its owner. The supplier grants the customer a licence to use its background IP to the extent needed to use the deliverables.
  • Foreground IP. What is created specifically under the SOW. This is the contested bucket. A customer paying for bespoke work usually expects to own it. A supplier building on reusable methods usually wants to keep ownership and licence it to the customer.
  • Residual knowledge and improvements. Enhancements to the supplier's own tools and general know-how gained. Suppliers want these; customers should make sure "residuals" cannot be used to strip the customer's confidential information out through the back door.

What to negotiate depending on which side you are:

  • As the customer buying bespoke deliverables: Push for assignment of foreground IP in the deliverables, or at minimum a perpetual, irrevocable, worldwide, royalty-free licence broad enough to use, modify and maintain them, including through other suppliers. A licence that dies with the relationship traps you with one vendor.
  • As the supplier: Keep ownership of your platform, frameworks, libraries and methodologies. Grant a licence tied to the customer's permitted use. Never let a broad assignment clause capture your reusable IP because it happened to appear in a deliverable.
  • Both sides: Make sure moral rights, and IP created by subcontractors, are properly handled. A supplier promising to assign IP it does not itself own is a gap you will discover at the worst moment.

Drafting these three buckets cleanly is fiddly, which is exactly the kind of repeatable structure a platform built for a business's own contracts handles well. GenieAI can generate MSA and SOW drafts with background, foreground and residual IP handled consistently against your standard position, so you are not rebuilding the split by hand each time. Teams that want to see how that works in practice start with drafting contracts from your own templates.

Termination: how you get out, and what happens next

Termination clauses cover when each party can end the agreement, how much notice is needed, and the consequences. In an MSA you are usually managing two layers: termination of the whole framework, and termination of individual SOWs.

The main termination routes to check for:

  1. Termination for convenience. Either party can walk with notice, no reason required. Great for customers, uncomfortable for suppliers who have staffed up. Suppliers often ask for a longer notice period, or early-termination charges to recover committed costs.
  2. Termination for cause (material breach). Triggered by a serious breach that is not remedied within a cure period, typically 30 days. Check that "material breach" is not defined so loosely that a minor slip triggers termination.
  3. Termination for insolvency. Standard, but under English law be aware that certain "ipso facto" termination rights against a supplier entering an insolvency process are restricted for the supply of goods and services. Do not rely on an insolvency clause working exactly as drafted without checking the current position.
  4. Termination for repeated breach or persistent service failure. Useful for customers where individual breaches are minor but the pattern is not acceptable.

The consequences of termination matter as much as the triggers. Confirm the clause deals with:

  • Payment for work done up to termination, and the treatment of prepaid fees.
  • Return or deletion of confidential information and data, with a certificate on request.
  • Transition assistance and handover to a replacement supplier, ideally with agreed rates and a minimum period. This is frequently missing and painful when absent.
  • Which clauses survive: confidentiality, IP, liability, accrued rights and dispute resolution should all continue.

Pushback on their paper: if you are the customer, resist a clause that lets the supplier terminate for convenience on short notice while binding you to a long term. Watch for termination charges that recover far more than genuine committed costs. And insist on a transition-out obligation, because the moment you most need cooperation is the moment your leverage is lowest.

Service levels: turning promises into measurable obligations

Service levels convert vague commitments into measurable standards with consequences. In many MSAs the detailed service levels live in the SOW or a separate service level agreement, but the MSA sets the framework for how they work.

A workable service level regime has these components:

  • Defined metrics. Availability, response times, resolution times, throughput, or whatever actually matters for the service. Vague words like "reasonable" or "industry standard" are not measurable and should be replaced with numbers.
  • Measurement method. How and by whom the metric is measured, over what period, and excluding what (scheduled maintenance, customer-caused delays, force majeure). Two parties can both act in good faith and still disagree if the measurement rules are not written down.
  • Service credits. The financial consequence of missing a level, usually a percentage of fees credited back. Understand whether credits are your sole remedy or sit alongside other rights.
  • Earn-back and escalation. Some regimes let a supplier recover credits through sustained good performance, or escalate to termination rights after repeated failures.

What to push back on:

  1. Service credits as sole and exclusive remedy. A supplier will often want credits to be the only remedy for missed levels. As a customer, resist making credits your exclusive remedy for serious or persistent failures; you want the right to terminate and claim damages if the service genuinely fails.
  2. Token credits. A 2% credit on a service that has failed for a week is not a meaningful incentive. The credit should be large enough to change supplier behaviour.
  3. Over-generous exclusions. If the measurement carve-outs are wide enough, a supplier can miss every target and still report full compliance. Read the exclusions as carefully as the targets.
  4. No right to fix the target. Business needs change. Build in a mechanism to review and adjust service levels annually rather than freezing them for the life of the MSA.

Change control: managing what happens when the deal moves

No engagement of any length runs exactly as scoped. Change control is the process for agreeing amendments to scope, price, or timeline in a controlled way. Weak change control is where budgets quietly overrun and disputes start.

A good change control clause sets out:

  • Who can request a change, and how (a written change request is standard).
  • How the impact is assessed, covering cost, timeline and any effect on other deliverables or service levels.
  • Who must approve, and that no change takes effect until both parties sign a change order.
  • What happens while a change is under discussion, so work does not stall or, worse, proceed on the assumption a change is agreed when it is not.

The most important principle: no work, no charge, and no scope change without a signed change order. Push back hard on any drafting that lets a supplier treat instructions, emails or verbal requests as authorised changes. On the other side, if you are the supplier, make sure the clause does not let a customer demand additional work under the guise of "clarification" without paying for it.

Tie change control back to the MSA and SOW split. A change order should be able to vary the relevant SOW but should not be able to override the protective terms of the MSA (your liability cap, IP position, indemnity structure) unless that is explicitly intended and signed off by someone with authority to agree it.

The clauses people skim and later regret

Beyond the six headline areas, a handful of clauses do quiet damage when ignored:

  • Confidentiality. Check the definition of confidential information, the permitted purpose, the standard exclusions, and how long obligations last after termination. Make sure it survives.
  • Data protection. Where personal data is processed, you need proper controller/processor drafting and the required data processing terms. This is a legal requirement, not a nice-to-have, and generic MSA boilerplate is often out of date.
  • Insurance. The MSA usually requires the supplier to hold minimum levels of cover. Confirm the types and amounts are appropriate for the risk, and that you can request evidence.
  • Assignment and subcontracting. Can the counterparty hand your relationship to someone else, or subcontract critical work without telling you? Require consent for assignment and transparency on subcontractors.
  • Entire agreement and variation. These control how the contract can be changed and what pre-contract statements you can rely on. A "no oral variation" clause protects you from informal changes but also binds you.
  • Governing law and dispute resolution. Which country's law applies, and whether disputes go to court or arbitration. Do not leave this to the counterparty's default if their home forum is inconvenient or expensive for you.

Clause positions at a glance: customer vs supplier

Clause Customer-friendly position Supplier-friendly position Common landing zone
Liability cap High cap, multiple of annual fees, wide carve-outs Low cap tied to recent fees, few carve-outs 12 months' fees, separate sub-caps for data/IP/confidentiality
Indemnities Broad supplier indemnities, uncapped Narrow, fault-based, capped Fault-based, capped or under a defined sub-cap, with conduct-of-claims controls
Foreground IP Assigned to customer Retained by supplier, licensed out Supplier keeps platform IP; customer gets broad perpetual licence or assignment of bespoke deliverables
Termination for convenience Available to customer on short notice Long notice or early-termination charges Reasonable notice, charges limited to genuine committed costs
Service credits Credits plus right to terminate and claim damages Credits as sole remedy Credits as primary remedy, other rights preserved for serious or persistent failure
Change control Strict signed change orders, no charge without approval Flexible, allows charging for clarifications Signed change orders required, MSA protections cannot be overridden without authority

How to run the review itself, whether by hand or with AI

A consistent review process beats reading start to finish and hoping you catch everything. Work in this order:

  1. Confirm the structure. Identify the MSA, the SOW template, and the order of precedence between them. Check which clauses a SOW may and may not amend.
  2. Read the risk-allocation clauses first. Liability, indemnities, IP. These set your posture for everything else.
  3. Check the exits. Termination triggers, consequences, transition, survival.
  4. Pressure-test the operational clauses. Service levels, change control, payment, acceptance.
  5. Sweep the quiet clauses. Confidentiality, data protection, insurance, assignment, governing law.
  6. Compare against your playbook. Every business should have a written set of standard and fallback positions. If you do not, building one is the highest-value thing you can do for contract risk.

This is where an AI-native platform earns its place, because a playbook only works if it is applied consistently on every contract regardless of who is reviewing. GenieAI reviews an incoming MSA against your standard positions, flags where the counterparty's draft departs from them, and proposes redline language you can accept or adjust, working directly inside Word where your team already drafts. Many teams use it for review and negotiation alone, checking third-party paper against their playbook before it reaches the lawyers. The point is not speed for its own sake; it is that nothing slips through because someone was busy or unfamiliar with the clause.

The risk in MSAs is rarely one dramatic clause. It is the accumulation of small concessions across liability, indemnities, IP and termination that, taken together, leave you exposed. Consistency is the defence, and it is exactly what a platform built for a business's own contracts, certified to ISO/IEC 27001:2022 and used by commercial and in-house teams, is designed to deliver. Sector matters too: the balance of these clauses looks different in construction and technology deals, where IP and liability sit very differently.

Frequently asked questions

What is the difference between an MSA and an SOW?

A master service agreement is the framework that governs a relationship over time, covering liability, indemnities, IP, confidentiality, termination and other terms you sign once and reuse. A statement of work sits underneath it and describes a specific engagement: scope, deliverables, timeline, fees and acceptance criteria. You can sign many SOWs under one MSA. Always check the order of precedence so you know which document wins if they conflict, and lock down which protective clauses a SOW is allowed to override.

What is the most important clause to check in an MSA?

The limitation of liability clause, because it caps what either party can recover when things go wrong and it colours every other negotiation. Read the exclusion of indirect losses, the cap on direct loss and the carve-outs together. Pay particular attention to indemnities and whether they sit inside or outside that cap, since an uncapped indemnity can make a carefully negotiated liability cap meaningless.

Can I use an AI tool to review a master service agreement?

Yes. An AI-native contract platform can read an MSA in context, flag where the draft departs from your standard positions, and suggest specific redline language for liability, indemnities, IP, termination, service levels and change control. The most useful tools apply your own playbook consistently on every contract and work inside the tools your team already uses. AI supports the review; a qualified reviewer should still sign off on anything that turns on specific facts or unusual risk.

Should indemnities be capped or uncapped?

Most indemnities should be capped or brought under a defined sub-cap, because uncapped indemnities are the most common way a negotiated liability cap becomes worthless. Some liabilities, such as those the law does not allow you to limit, sit outside any cap by necessity. Where a counterparty asks for an uncapped indemnity, question whether the specific risk genuinely justifies it, narrow the trigger to fault-based losses, and insist on proper conduct-of-claims controls.

Who owns the IP created under an MSA?

It depends on the drafting. Background IP each party brings stays with its owner. Foreground IP created under the SOW is the contested part: a customer paying for bespoke work usually wants ownership or a broad perpetual licence, while a supplier building on reusable tools wants to keep ownership and licence its use. Check that IP created by subcontractors is properly assigned, and that a supplier is not promising to transfer IP it does not itself own.

What should I push back on when an MSA arrives on the counterparty's paper?

Start with the liability cap if it is set as a small fraction of fees or sweeps everything under one low number. Then challenge one-way or uncapped indemnities, IP terms that trap you with a single vendor, termination-for-convenience rights that are not reciprocal, service credits offered as the sole remedy, and change control that lets the other side charge for work without a signed change order. Compare each clause against a written playbook of your standard and fallback positions rather than judging it in isolation.

How long should a liability cap be based on?

A common and defensible position is a cap set at the fees paid in the trailing 12 months, or a fixed sum where fees are low relative to the risk. Suppliers often open with a shorter reference period such as three months, which may not cover a single serious incident. For data-critical or safety-critical services, push for higher separate sub-caps for data protection, confidentiality and IP indemnities, and keep liabilities the law will not let you limit outside the cap entirely.

What happens to service levels if they are only in the SOW?

Detailed service levels often live in the SOW or a separate service level agreement, while the MSA sets the framework for how they operate. That is fine, provided the MSA is clear on how credits, remedies and termination rights interact with the levels defined below it. Make sure a SOW cannot quietly weaken the remedies or termination rights you negotiated in the MSA, and build in a mechanism to review and adjust service levels over time as business needs change.

Legal Reviewer

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Interested in joining our team? Explore career opportunities with us and be a part of the future of Legal AI.

Ready to agree with confidence?
See Genie in action.