Vendor MSA Red Flags: What a Buyer's Lawyer Flags First
This is the buyer's-side view. As the lawyer enterprise companies hire to vet a vendor's master services agreement (MSA) before they sign, I stall deals over a predictable short list: the limitation of liability cap, indemnification, security and data-protection commitments, data and AI usage rights, termination and auto-renewal, blanket liability disclaimers, and the procurement mechanics behind the signature. Almost none of it is about price — it is about who carries the risk if the vendor fails.
I want to be clear about the seat I'm writing from: I vet deals from the buyer's side. I'm the counsel enterprise SaaS buyers bring in to review a vendor's MSA, and I'm the one whose redline lands on your desk and holds up your close. Across both sides of the table I've worked more than $280M in enterprise contracts over the last three months — and I know exactly what a buyer's legal team is trained to push on, because pushing on it is my job.
If you sell enterprise SaaS, read this as reconnaissance. These are the seven things that make me stall your deal, and what the vendors who clear my desk in days — not weeks — do differently. (I've also written the seller's playbook version of this list; this piece is the same battlefield from the reviewer's chair.)
This is general information from my experience, not legal advice for your specific deal.
What a sloppy MSA signals to a buyer's counsel
A poorly drafted, one-sided, or amateurish MSA signals that the vendor hasn't yet sold to a sophisticated customer with a competent legal team — and to a buyer's counsel, that lowers confidence in the product itself, not just the paper. The MSA is often the first artifact I read closely, and I read it as evidence of how mature the company actually is.
Here is the logic my client and I run, usually without saying it out loud. If your MSA is full of internal inconsistencies, obviously copied boilerplate, wildly off-market terms, or is missing basics like a DPA, I infer that no demanding buyer's legal team has ever pressure-tested you. And if no one sophisticated has vetted you, my client starts asking what else hasn't been tested — your security, your reliability, your support, your staying power. The contract becomes a proxy for the company.
That is the expensive part. A weak MSA doesn't just add redline cycles; it shifts the conversation from "how do we paper this deal" to "are these the right people to depend on." That second question kills more deals than any single clause, and it is a far harder hole to climb out of.
How to clear it: treat your MSA as a credibility surface, not a legal formality. A clean, well-organized, market-standard MSA — with a DPA and security documentation ready to hand over — signals that you have done this before and that a competent lawyer stands behind your paper. It de-risks you in my client's eyes before we argue a single term.
1. A liability cap that doesn't match the risk
A limitation of liability clause caps the maximum dollar amount the vendor can be forced to pay if something goes wrong. It is the first thing I turn to, and the single most contested term in commercial contracting — limitation of liability has ranked at or near the top of World Commerce & Contracting's Most Negotiated Terms survey for over a decade, alongside indemnification and price.
What I flag: a flat cap set at a small multiple of fees on a deal where the vendor is touching sensitive data or sitting in a critical workflow. If your product can cause my client a seven-figure problem and your cap is one year of fees with no exception for a data breach, I can't sign it — my job is to make the cap bear some relationship to the actual exposure.
How to clear it: come in at a shape I recognize as market. A general cap at 1x the fees paid in the prior 12 months, a higher "super-cap" (for example 2x fees) for a data breach, and a short list of uncapped carve-outs like the IP infringement indemnity is a structure a16z documents and one I'll usually accept without a fight. Offer that up front and you've removed my biggest objection before I raise it.
2. Indemnities that quietly carve out the risk I care about
An indemnification clause is the vendor's promise to cover my client's losses if a specified bad thing happens — most often a claim that the product infringes someone's IP, or that the vendor mishandled data. Indemnities are consistently a top-three most-negotiated term because they decide who pays when a third party comes after us.
What I flag: an indemnity that covers IP infringement but goes silent on data. If you process my client's data and your MSA has no data-incident indemnity — or folds it under a low liability cap so it's effectively worthless — that's a redline. I'm also watching for indemnities limited so tightly that they wouldn't actually respond to the claims we're realistically exposed to.
How to clear it: give a clean IP infringement indemnity and a defined data-breach indemnity (even a capped one) rather than making me ask for it. Limiting your exposure to direct losses and excluding indirect or consequential damages is reasonable and I'll accept it — what stalls the deal is discovering the coverage isn't there at all.
3. A security posture that can't survive the review
The security review is where my client's security team vets whether you're safe to plug into their systems — security questionnaires, a SOC 2 report, penetration-test summaries, and a negotiated data processing agreement (DPA). It's the step that goes quiet for weeks after the commercial terms are done, and it's usually the vendor's fault it's slow.
What I flag: an MSA that references a privacy policy or security standard the vendor can't evidence, an expired or missing SOC 2, or no DPA on offer when the deal clearly involves personal data. A DPA is required under privacy laws like the GDPR and CCPA whenever you process personal data on my client's behalf; a healthcare buyer will also need a HIPAA business associate agreement, and an Ontario health customer a PHIPA service-provider agreement. If I have to chase you for any of this, we're now weeks behind — industry estimates put enterprise security reviews at roughly four to six weeks per deal (Cyberbase).
How to clear it: treat your security artifacts as sales collateral. Hand me a current SOC 2, a completed standard security questionnaire, and a vendor-ready DPA at the same time as the MSA. When the review starts with my team redlining your prepared DPA instead of waiting on your engineers, you've cut the single longest delay out of the deal.
4. Data and AI usage rights written for the vendor, not the buyer
Data usage rights govern what you're allowed to do with my client's data — in particular whether you can use it to train or improve machine-learning models, and reuse those models across your other customers. This is now one of the first clauses I read, and it wasn't even a fight a few years ago.
What I flag: broad language letting the vendor "use, analyze, or improve" using customer data with no limits, or any right to train AI models on my client's data without a clear boundary. Sensitive or competitively meaningful data being fed into a shared model is a hard stop for most sophisticated buyers, and vague drafting here turns a two-day review into a two-week one while I nail down what you actually mean.
How to clear it: pick a clear position and write it plainly. Customer owns its data; the vendor may use it only to provide and improve the service for that customer; model training is either excluded or limited to de-identified, aggregated data that can't be traced back. State the boundary explicitly and you take away my reason to interrogate it.
5. Auto-renewal and termination terms that only protect you
Termination and auto-renewal decide how my client gets out and what happens at renewal. Termination for convenience lets a customer exit without cause; auto-renewal extends the term unless someone opts out. Both sit right at the intersection of legal and deal economics, which is why procurement and I both care.
What I flag: auto-renewal paired with a one-sided price increase — the clause that lets the vendor raise price "at its discretion" on renewal — plus notice windows so short they're designed to be missed. On the other side, blanket disclaimers that strip my client of any meaningful remedy if you underperform. These are the terms that get an MSA sent back from procurement even after the substance is agreed.
How to clear it: keep any renewal price-increase mechanism reasonable and capped, give a fair notice window, and pair your SLA with a real (if limited) remedy such as service credits. You keep your revenue predictability and I lose the reason to escalate.
6. Blanket disclaimers that read as "we're never responsible"
A disclaimer of warranties and liability is where a vendor limits what it promises and what it will answer for. Some disclaiming is standard and I expect it. The problem is the version that overreaches.
What I flag: broad disclaimers that, read together with a low cap and thin warranties, amount to "no matter what happens, we're not responsible." When a warranty is offered with no specific remedy attached, or the MSA disclaims essentially everything, my client is buying something with no accountability behind it — and I can't recommend signing that.
How to clear it: offer a narrow, specific warranty (the service will perform materially as documented) with a specific, bounded remedy. Specific and limited beats sweeping-and-disclaimed every time — it gives me something real to point to when my client asks "what happens if this breaks," which is the question that actually unlocks the signature.
7. The unglamorous mechanics that die in procurement
The last stall isn't a clause — it's the operational layer behind the signature: correct legal entity names, signing authority, insurance requirements, and whether the MSA, DPA, order form, and SOW actually line up. A deal that's legally "done" still sits here.
What I flag: the wrong entity on the signature block, a missing certificate of insurance for a coverage level your own MSA requires, a signer who turns out to lack authority, or documents that reference each other inconsistently. Any one of these bounces the contract back into a queue, and none of it is a disagreement — it's just not-ready.
How to clear it: run a pre-signature checklist before you send. Confirm the exact legal entities on both sides, verify your signer's authority, have your insurance certificates ready for the levels your MSA commits to, and make sure the MSA, DPA, order form, and any SOW cross-reference cleanly. It's the easiest week you'll ever save.
What this looks like from the seller's side
Here's the pattern behind all seven: I don't stall deals because I enjoy it — I stall them because the vendor arrived without a decided position on a term I'm required to fix. The vendors who clear my review fast aren't the ones with the most generous paper. They're the ones who've already decided their liability cap, their indemnity position, their data boundary, and their renewal terms, and who show up with the DPA and SOC 2 in hand. The negotiation still happens. It just doesn't start from a blank page every time, and it doesn't wait on documents you could have had ready.
Frequently asked questions
What do buyers' lawyers look for when reviewing a vendor MSA?
A buyer's counsel reviewing a vendor's MSA focuses on risk allocation: the limitation of liability cap, the indemnities (especially IP infringement and data breach), data protection and security commitments, what the vendor may do with the buyer's data, termination and auto-renewal terms, and whether the vendor's paper, insurance, and entity details are clean enough to sign. Price is rarely what stalls the deal — who carries the risk if something goes wrong is.
What are the biggest red flags in a SaaS vendor MSA?
The biggest red flags are a liability cap far below the deal's risk with no data-breach super-cap, indemnities that exclude data incidents, broad rights for the vendor to use or train AI on customer data, one-sided auto-renewal with uncapped price increases, blanket liability disclaimers, and missing or expired security documentation. Each one predictably triggers a redline.
Why do enterprise deals stall in legal review?
Enterprise deals stall in legal review when the vendor's MSA pushes too much risk onto the buyer — an unrealistic liability cap, broad disclaimers, self-serving data-use rights — or when the vendor can't survive the security review because its SOC 2, security questionnaire, or DPA isn't ready. Most delays come from the vendor arriving without decided positions on the terms the buyer's counsel is required to fix.
What limitation of liability cap will a buyer's counsel accept?
A common market position is a general cap at 1x the fees paid in the prior 12 months, with a higher super-cap (for example 2x fees) for a data breach and a short list of uncapped carve-outs such as the IP infringement indemnity. A buyer's counsel will usually accept a cap in that shape; a flat low cap with no breach super-cap, on a deal handling sensitive data, is what draws the pushback.
How can a SaaS vendor get through enterprise legal review faster?
Arrive with decided positions and prepared documents. Bring a current SOC 2 report, a completed security questionnaire, and a ready DPA so the security review doesn't stall; use a redline playbook with your pre-approved position, fallback, and hard line on liability, indemnity, data, and termination; and confirm entity names, signing authority, and insurance before signature. Vendors who do this clear a buyer's counsel in days, not weeks.
Does the quality of a vendor's MSA affect the buying decision?
Yes. To a buyer's counsel, a sloppy or one-sided MSA signals that the vendor hasn't sold to a sophisticated customer with a competent legal team — which lowers the buyer's confidence in the vendor's overall maturity, including its security, reliability, and staying power. A clean, market-standard MSA with a ready DPA signals the opposite and de-risks the vendor before negotiation even starts.
This article is general information from my experience reviewing enterprise deals, not legal advice. The right position on any of these terms depends on your specific deal, leverage, and risk tolerance — consult a qualified attorney for your situation.
If you sell enterprise SaaS, the way to never land on my desk with a problem is to have your positions decided before the redline comes. LegalLayer, the premium tier of LegalBooks, gives growth-stage sellers a lawyer-designed MSA plus a system of agents that draft, negotiate, and review enterprise deals fast — inside the exact limits a licensed lawyer set (green to flex, yellow to escalate, red as a hard line), with every concession logged. It's how sell-side teams walk into a buyer's legal review already ready for the seven things their counsel is about to flag.