CUST-17 Master Services Agreement (MSA)

What is this control about?

The MSA’s objective is to communicate a company’s responsibilities and agreed to commitments with its customers. It also includes the customer’s responsibilities and other relevant information about the contract in place, such as the term, provisions, SLA, etc..Nowadays, mostly software-based companies have a Terms of Use instead of a signed MSA with each customer. A great example is Amazon Web Services (AWS), its customer agreement online is typically agreed to by the customer and there isn’t a signed MSA unless it was specifically requested.

Control implementation

Work with legal counsel to draft an MSA template.

Work with legal counsel to draft and publish a terms of use or user agreement on the website

What evidence do auditors look for?

Most auditors, at a minimum are looking for the below suggested action:

  • Provide the MSA template or most recent signed MSA with a customer
  • Provide link to the terms of use or user agreement on the website

Evidence example

From the suggested action above, an example is provided below.

1.    Provide the MSA template or most recently signed MSA with a customer.

MSA Template example

2.  Provide links to the terms of use or user agreement on the website.

AWS customer agreement

