Docy Child

CUST-17 Master Services Agreement (MSA)

Estimated reading: 2 minutes 725 views

What is this control about?

The MSA’s objective is to communicate a company’s responsibilities and agreed to commitments with its customers. It also includes the customer’s responsibilities and other relevant information about the contract in place, such as the term, provisions, SLA, etc..Nowadays, mostly software-based companies have a Terms of Use instead of a signed MSA with each customer. A great example is Amazon Web Services (AWS), its customer agreement online is typically agreed to by the customer and there isn’t a signed MSA unless it was specifically requested.

Available tools in the marketplace

The following listing is “crowdsourced” from our customer base or from external research. TrustCloud does not personally recommend any of the tools below, because we haven’t personally used them. 


Available templates

TrustCloud has a curated list of templates internally or externally sourced to help you get started. Click on the link for a downloadable version:

  • N/A – no templates recommendation

Control implementation

Work with legal counsel to draft an MSA template.

Work with legal counsel to draft and publish a terms of use or user agreement on the website

What evidence do auditors look for?

Most auditors, at a minimum are looking for the below suggested action:

  • Provide the MSA template or most recent signed MSA with a customer
  • Provide link to the terms of use or user agreement on the website

Evidence example

From the suggested action above, an example is provided below.

1.    Provide the MSA template or most recently signed MSA with a customer.

MSA Template example

2.  Provide links to the terms of use or user agreement on the website.

AWS customer agreement

Join the conversation

Twitter Facebook LinkedIn

❤️  Joyfully crafted by a 100% distributed team.