Third-party contract clauses are where a risk assessment turns into enforceable obligations. Due diligence may show that a supplier is strong today, but only the contract gives you a right to insist that it stays that way, tells you when something goes wrong and lets you leave without losing your data or your service. A weak contract leaves you carrying risks you cannot control.
This guide explains the clauses that matter most in a third-party risk programme, why each one exists, how to scale them to the risk of the relationship and how to keep them consistent across suppliers. It is general information, not legal advice, and contracts should be reviewed by counsel.
Free gap assessment
Where do you actually stand against ISO 27001?
Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.
Run the free ISO 27001 gap assessment → or View premium report sample
Why third-party contract clauses matter
A questionnaire records what a supplier says today. A contract records what it must do tomorrow. Without the right clauses, you may have no right to see audit reports, no guarantee of notice after a breach and no route to retrieve your data if the relationship ends badly.
Regulators increasingly expect firms to negotiate specific terms with important suppliers. In the EU financial sector, for example, the EU Digital Operational Resilience Act, including its Article 30 on contract terms lists the key provisions that contracts for ICT services must contain. Even outside regulated sectors, good third-party contract clauses are one of the strongest controls in the third-party risk management framework.
Match third-party contract clauses to the risk tier
Not every supplier needs the full set. Use your tiering to decide which clauses are mandatory. A low-risk stationery supplier needs standard terms. A critical cloud provider needs detailed service levels, audit rights, resilience commitments and exit assistance. Our guide to vendor risk tiering explains how to set tiers.
Create a clause library with approved wording for each tier. That speeds up negotiation, gives buyers a clear standard and makes it easier to spot deviations. Record any accepted deviation with the risk and the approver.
Security and control requirements
Specify the security standards the supplier must meet: relevant certifications, control frameworks, access management, encryption, vulnerability management, logging and staff screening. Tie the requirements to the data or systems involved, so they are proportionate.
Require the supplier to keep its controls in place for the life of the contract, to tell you of material changes and to remediate findings within agreed times. Refer to a schedule or annex so requirements can be updated without renegotiating the whole agreement. See the vendor security questionnaire for how to check them.
| Clause area | What it should achieve | Applies most to |
|---|---|---|
| Security and controls | Sets minimum standards and certifications | Suppliers handling data or systems |
| Data protection | Defines roles, purposes, sub-processors and transfers | Suppliers handling personal data |
| Audit and information rights | Lets you verify compliance | Critical and high-risk suppliers |
| Incident notification | Sets time limits and cooperation duties | All suppliers with access to data or services |
| Subcontracting | Controls onward delegation | Suppliers using fourth parties |
| Resilience and exit | Ensures continuity and orderly termination | Critical and important services |
- Named standards or equivalent controls
- Right to receive current certificates and audit reports
- Duty to remediate findings within set timelines
- Notification of material control changes
Data protection and confidentiality
Where personal data is involved, the contract must contain the terms required by data protection law: subject matter, duration, nature and purpose of processing, categories of data, the processor’s duties, assistance with rights requests and breaches, sub-processor controls, deletion or return at the end and audit rights. Add confidentiality obligations for other sensitive information.
Address international transfers explicitly: where data may be stored and accessed, which transfer mechanism applies and what happens if the legal position changes. Our international data transfers guide explains the mechanisms.
Audit, information and reporting rights
A right to audit is the clause that lets you verify what the supplier says. It may include on-site audits, remote reviews, receipt of independent reports and access to relevant staff. For critical suppliers, ask for the right to audit on reasonable notice, and after incidents or regulatory requests.
Suppliers with many customers may resist individual audits and offer pooled or third-party reports instead. That can be acceptable if the reports are recent, cover the relevant services and you retain a right to further information. Record the approach and any gaps in your monitoring plan; see third-party continuous monitoring.
Incident notification and cooperation
Set clear time limits for notifying you of incidents that affect your data or services, such as within twenty-four or forty-eight hours of becoming aware, and specify what information must be provided. The time limit should allow you to meet your own legal deadlines, for example for reporting personal data breaches.
Require cooperation: access to logs, forensic reports, help with communications and remediation. Add duties to investigate root causes and to share lessons. Without these clauses, you may learn about a breach from the newspaper.
Subcontractors and fourth parties in third-party contract clauses
Suppliers often rely on others. Require notice of, and where appropriate approval for, material subcontractors, and make the supplier responsible for their performance. Flow down the key security, data and audit obligations. Ask for a list of subcontractors that support your service.
Consider concentration and dependency. If a critical subcontractor fails, your service may fail with it. See fourth-party risk and vendor concentration risk for how to assess it.
Resilience, service levels and exit
For important services, include service levels with meaningful remedies, recovery time and data loss commitments, continuity plan requirements and participation in tests. Specify what happens on termination: return or secure deletion of data in a usable format, transition assistance, continued service for a period and access to documentation.
Plan the exit before you sign. Exit clauses are hardest to negotiate when you are already leaving. Our vendor offboarding checklist shows what an orderly exit requires.
Common mistakes with third-party contract clauses
Frequent problems include relying on the supplier’s standard terms without review, omitting audit rights, accepting vague notification wording such as “promptly”, ignoring subcontractors, giving no exit assistance, allowing liability caps that make remedies meaningless and never checking that the supplier complies. Another is leaving contracts on autopilot: terms agreed years ago may no longer fit the risk.
Avoid these by using a clause library, involving security, privacy and legal early, and reviewing key contracts at renewal against current requirements.
Negotiating and tracking exceptions
Negotiation rarely delivers every clause. Agree in advance which clauses are essential for each tier and which can be traded. Where a supplier refuses a required clause, record the exception, the risk it creates, the compensating control and the person who accepted it. Review exceptions at renewal and report the number of open exceptions to your governance forum. Patterns tell you where the standard terms need work or where a supplier is consistently difficult.
Keep a contract register showing key dates, notice periods, clause coverage and owners. It makes reviews at renewal far easier and gives you an early warning when a critical contract is close to expiry.
Liability, insurance and remedies
Clauses are only as good as the remedies behind them. Check that liability caps are not so low that a breach costs the supplier nothing, and consider carve-outs for data breaches, confidentiality and regulatory fines where the law permits. Require suitable insurance, such as cyber and professional liability cover, with evidence of the policy. Service credits are useful for availability failures, but they rarely compensate for a serious incident, so keep termination rights for repeated or severe breaches.
Ask legal counsel to explain the practical effect of each remedy, and make sure the business owner understands what the contract does and does not protect. A clear view of residual risk helps them decide whether extra controls or a different supplier are needed.
A short worked example
A company plans to use a cloud platform for customer data. Its tiering rates the platform critical. The contract team uses the critical-tier clause set: security standards and certificates, data processing terms with transfer safeguards, forty-eight hour incident notice, audit rights including through independent reports, subcontractor notice and flow-down, recovery targets and a twelve-month exit assistance period.
The supplier objects to on-site audits, so the parties agree to annual independent reports plus a right to on-site audit after a serious incident. The residual gap is documented, and monitoring is planned accordingly. The company signs with clear obligations and a record of its reasoning.
Structuring the assessment and clause checks
If you want a report and workbook that connect the risk assessment, findings and required contractual protections, the Third-Party Risk Assessment Report and Workbook provides a structured layout for third-party assessments. Whatever the tool, strong third-party contract clauses turn what you learn in due diligence into rights you can enforce.
Free third-party risk assessment
How much risk does this vendor bring?
Tier the vendor, check the evidence, rate the risks from 30 third-party scenarios and choose controls referenced to ISO 27001, NIST CSF 2.0 and DORA. You get a tier, a heat map and the findings an auditor would raise, free.
Start the free vendor risk assessment → or View premium report sample
Third-party contract clauses FAQ
Which contract clauses matter most for third-party risk?
Security requirements, data protection terms, audit and information rights, incident notification, subcontractor controls, resilience commitments and exit assistance.
Should every supplier have the same clauses?
No. Scale clauses to the risk tier. Low-risk suppliers need standard terms, while critical suppliers need detailed protections.
What if a supplier refuses audit rights?
Seek alternatives such as independent reports, questionnaires and a right to audit after incidents, and record any remaining gap and the approver of the residual risk.
How fast should incident notification be?
Set a short, specific time limit that lets you meet your own legal deadlines, such as within twenty-four to forty-eight hours of awareness.
When should we review contracts?
At renewal, after significant incidents or changes in the service, and when regulations or your risk tolerance change.