Before signing an enterprise customer's master services agreement, check what you must deliver, when you get paid, who owns the work and how liability is allocated. Read the order form, statement of work and incorporated policies alongside the MSA. A manageable contract should reflect what your startup can actually deliver and support.

The first large customer can justify negotiation effort. It can also expose a small business to obligations far beyond the value of the contract if nobody reads the documents together.

Understand which document controls

An MSA commonly sets the general commercial and legal terms. A statement of work, or SOW, describes a particular project or service. An order form often specifies the subscription, quantities, price and period. The documents may use these labels differently.

Check the order of precedence. If the order form promises a fixed annual subscription but a purchase order introduces a cancellation right, identify which wording governs. Also check policies incorporated through website links and whether the customer can change them unilaterally.

Maintain a complete signing set. It should be possible to establish exactly which documents and policy versions the parties accepted.

Tie the scope to acceptance and payment

Describe deliverables, dependencies and exclusions. If the customer must supply data, approvals or system access, record those dependencies and what happens to the schedule when they are late.

For project work, define acceptance criteria, the review period and the handling of defects. For a subscription service, avoid inadvertently making all fees dependent on acceptance of unrelated custom development.

Consider a hypothetical six-week implementation. The agreement says payment follows “customer satisfaction”, but the customer supplies required data three weeks late and asks for new features. Without an agreed change process or measurable acceptance criteria, the startup may carry both extra work and an uncertain payment date.

Set out invoicing prerequisites, payment timing, disputed-invoice handling and whether undisputed amounts remain payable. Treat purchase-order requirements as an operational task with an owner.

Protect the product you need for other customers

Distinguish your existing platform and reusable tools from customer data and any specifically commissioned deliverables. Explain the customer's licence and permitted users or usage, including restrictions that matter to your model.

Avoid assigning broadly defined “all work product” without checking whether it captures your platform, future improvements or material reused across customers. Where a customer needs ownership of a bespoke output, define that output and the rights needed to use any embedded background material.

Check that your contractor and employee arrangements support the commitments you make. A sales agreement should not promise ownership the company has never obtained.

Read the liability provisions as one system

Identify the general liability cap, exclusions, indemnities, service credits and any separate caps. Then check the carve-outs. A seemingly modest cap may offer limited protection if most realistic claims sit outside it.

An indemnity typically allocates specified risks and claim handling between the parties. Discuss what triggers it, who controls the defence, settlement consent and whether the obligation sits inside or outside an agreed cap.

The Indian Contract Act contains rules on compensation for breach and stipulated sums. A penalty or stated damages amount is not a guarantee of automatic recovery in every case. [Source 1] Have the actual drafting assessed alongside the commercial exposure.

Promise security and service levels you can evidence

Check availability commitments, support hours, response categories, security questionnaires and audit rights against current capability. Do not sign a statement that the startup holds a certification it does not have.

If personal data is involved, map which party decides the purposes of processing and which acts on instructions for the relevant activity. Agree the actual permitted uses, security responsibilities, incident cooperation and deletion or return arrangements. A generic promise to comply with “all privacy laws worldwide” needs a realistic applicability review.

Plan for the contract ending

Review renewal, price changes, termination rights, cure periods, refunds and transition assistance. Specify how long a customer can export its data and what assistance is included or separately priced.

For an early-stage supplier, unlimited free transition work can create an obligation after revenue stops. Agree a proportionate process the company can deliver.

Frequently asked questions

Can I sign the customer's standard template unchanged?

You can decide to accept commercial risks, but first identify them. “Standard” describes whose template it is, not whether it suits your product or capacity.

Does an NDA cover the customer relationship?

It usually addresses confidentiality. Delivery, payment, licensing, liability and termination need the relevant commercial terms.

Which clauses should I negotiate first?

Start with delivery and payment feasibility, core IP, material liability and promises you cannot meet. Keep the negotiation focused on risks that affect the business.

Corpernicus offers commercial contract support. For the ownership evidence behind those promises, see our diligence checklist. Book an introductory call before committing to a significant customer contract.

Sources checked 29 September 2026

General information. The negotiation should reflect the service, customer, applicable law and actual commercial exposure.