BLOG POST

Tech & Sourcing @ Morgan Lewis

TECHNOLOGY TRANSACTIONS, OUTSOURCING, AND COMMERCIAL CONTRACTS NEWS FOR LAWYERS AND SOURCING PROFESSIONALS

A (Pro)Curated List of Contractual Provisions Sourcing Teams Should Not Ignore (Part 2)

Contract Corner

As a follow-up to Part 1, in which we discussed increased reliability on sourcing teams’ input for commercial negotiations, this Part 2 discusses additional common provisions sourcing teams should consider in their oversight and management of the contracting process.

See our blog post A (Pro)Curated List of Contractual Provisions Sourcing Teams Should Not Ignore (Part 1) for more information.

Service Levels: What Is Your Vendor’s Commitment?

As we’ve previously noted, including a service level agreement (SLA) is key for many agreements, particularly in the software as a service (SaaS) or technology space. While vendors often default to their off-the-shelf SLA, it may not address the particularities of the customer’s needs or may only provide vague targets as opposed to enforceable commitments.

Sourcing teams should pay careful attention to:

  • Whether the SLA measures the performance that matters to the business;
  • Whether SLA exclusions (e.g., scheduled maintenance, force majeure events, or customer- or third party-triggered incidents) substantially undermine the SLA’s value;
  • What escalation procedures and remediation plans exist for SLA failures;
  • Whether the SLA provides a firm commitment to meet the service levels or simply an efforts-based obligation;
  • What service level credits exist and whether they are sufficient to drive compliance;
  • What termination rights exist (e.g., for individual substantial failures or chronic failures); and
  • Whether the service level credits and termination rights are the customer’s sole and exclusive remedy for SLA failures.

Understanding these intricacies can help the sourcing group and the business push for an SLA that not only measures performance but also promotes vendor accountability.

Service Descriptions and Assumptions: What Are You Buying?

As operations and technical specialists discuss a project, it is easy to assume a shared understanding of scope, roles, and responsibilities. But any shared understanding will be of little benefit when challenges arise if the ordering document does not clearly and accurately reflect that understanding.

Sourcing groups should confirm that ordering documents clearly identify:

  • Scope of services and deliverables (with proper identification of work product to be owned by the customer);
  • Vendor and customer responsibilities (including clarification that those items not specifically categorized as customer responsibilities are vendor responsibilities);
  • Project timelines (with attention to any critical deadlines);
  • Assumptions (carefully reviewed to ensure that they are not more properly structured as one of a party’s responsibilities or a scope limitation, and do not undermine performance obligations);
  • Acceptance criteria (in sufficient detail to permit the parties to assess their satisfaction); and
  • Change-order procedures (e.g., how changes are requested, who is authorized to approve changes, and impact on pricing).

Regardless of the specific product or service, sourcing personnel should read the ordering document through the lens of an otherwise competent individual who is unfamiliar with the project. If that person cannot readily identify what is being purchased, on what timeline, at what cost, and with what division of roles and responsibilities, the agreement needs clarification.

Audit Rights: How Do You Verify (or Prove) Compliance?

Audit provisions can involve review of either a customer’s or a vendor’s obligations and compliance, and sourcing teams should assess audit terms from both perspectives.

Customer-Initiated Audit Concerns

Where customers are heavily regulated, rely on vendors to comply with regulatory obligations, or grant vendors access to sensitive data or operate critical systems, verifying vendor compliance becomes particularly important.

Sourcing departments should carefully consider:

  • Whether the customer has the right to audit the vendor’s compliance with contractual obligations, and if so, which obligations (e.g., invoicing, security provisions, privacy terms, or financial controls);
  • Whether the vendor may satisfy audit provisions by providing third-party audit reports or whether on-site audits are permitted;
  • Whether the customer’s regulatory oversight may require certain vendor audits (e.g., by the customer, the regulator, or both);
  • How frequently audits may occur;
  • Who bears the cost of the audit and in what circumstances; and
  • What happens if the audit identifies material deficiencies (e.g., whether the vendor must remediate issues within a specific timeframe or whether there are termination rights).

Vendor-Initiated Audit Concerns

Audit provisions may also be sought by the vendor, particularly technology providers with an interest in verifying compliance with terms such as licensing restrictions and user limits.

Sourcing teams should understand:

  • What triggers permit the vendor to conduct an audit (e.g., passage of time or vendor’s reasonable concern);
  • What records the customer must maintain and what access the customer must provide in an audit (e.g., systems access and self-verification reports);
  • Timing constraints on the vendor’s audit rights (e.g., how frequently, how much notice, or whether audits must occur during normal business hours);
  • Who bears the cost of the audit and in what circumstances; and
  • What happens if the audit identifies material deficiencies (e.g., whether payment for licensing shortfalls is based upon rates in the agreement or the vendor’s then-current rates, or whether there are termination rights).

Sourcing personnel should pay particular attention to the operational impact of vendor audits, as broad audit rights can require significant internal resources, disrupt business operations, and create data-security concerns where the vendor seeks system access.

Subcontractors: Who Is Providing the Service?

Many vendors rely extensively on subcontractors, whether for cloud infrastructure, offshore support in a follow-the-sun model, or through a network of specialized affiliates. Subcontracting is not necessarily a negative, but, as previously noted, customers (particularly those subject to regulatory oversight) need to understand who is providing the services.

Sourcing managers should closely evaluate:

  • What subcontracting restrictions exist (e.g., prior customer approval, notice to customer, or carveouts for affiliates);
  • Whether subcontractors have access to sensitive information (e.g., client information, personally identifiable information, or information subject to special legal protection, such as HIPAA);
  • Whether any subcontractors will be performing critical functions;
  • Whether the vendor remains responsible for subcontractors’ compliance and liable for their breaches (as if the vendor were directly performing the service); and
  • How subcontractor substitutions are addressed.

Understanding the full vendor ecosystem is critical to the sourcing team’s ability to assist the business in evaluating operational resilience and third-party risk as well as for demonstrating compliance by regulated entities.

Contract Governance: How Will Issues Be Identified and Resolved?

While sourcing teams understandably focus on the negotiation and execution phases of contracting, the success of the vendor relationship depends not only on the contract’s provisions around pricing, confidentiality, and indemnification but also on how the parties recognize, escalate, and manage issues that arise throughout the contract’s lifecycle.

Sourcing teams should confirm that the agreement or ordering document addresses:

  • Whether periodic performance reviews or other regular check-ins are required, and at what cadence;
  • Whether relationship managers (either overall or for a specific service) are identified;
  • What process is used to escalate issues (e.g., to whom, whether multiple levels of escalation are required, or timeframes for resolution);
  • Whether and at what point executive stakeholders become involved for persistent issues; and
  • Whether there is a process for key stakeholders to hold strategic planning sessions to review changing business needs, evolving technological and regulatory landscapes, and other issues over time.

By establishing a framework for clear communication channels, points of contact, decision-making flows, and regular touchpoints, sourcing teams can assist the business by proactively identifying and resolving issues, avoiding prolonged operational headaches and costly disputes.

Conclusion

Most contractual disputes arise not from heavily negotiated legal provisions but rather from overlooked or ambiguous commercial terms. Sourcing departments, increasingly tasked with responsibilities beyond pricing negotiation, frequently serve as a company’s first line of defense in identifying contractual risks before those risks bloom into full-blown problems.

By expanding their review beyond pricing and payment, sourcing teams can recognize potential issues earlier, aid in more constructive negotiations, and lower the likelihood of time-consuming and expensive surprises down the road.