Contract clause

Audit rights clause

An audit rights clause gives one party the right to inspect the other's records, systems or premises to check that the contract is being performed as promised. It sets how often an audit may happen, how much notice is given, who may carry it out, what they may see, and who pays for it.

Every promise about data handling, pricing or security is only as good as the ability to check it. Audit rights are rarely used, but a supplier that knows they exist behaves differently from one that knows they do not.

· Co-founder

4 min read · Published

Sample clause

a claims data services agreement between Yarrabee Health Fund, a fictional member owned health insurer, and Wilga Data Services, which processes its claims records

18. Audit 18.1 Yarrabee may audit Wilga's compliance with clauses 9 (Personal Information) and 10 (Security) once in any 12 month period, on at least 20 business days written notice. 18.2 An audit may be carried out by Yarrabee's personnel or by an independent auditor bound by confidentiality obligations no less protective than clause 11, and may include inspection of relevant records, policies, access logs and, during business hours, premises where Customer Data is processed. 18.3 Wilga must give reasonable assistance and access to relevant personnel, but need not disclose information about its other customers. 18.4 Yarrabee bears its own audit costs. If an audit reveals a material breach of clause 9 or 10, Wilga must reimburse Yarrabee's reasonable audit costs and must fix the breach within the period Yarrabee reasonably specifies. 18.5 Yarrabee may carry out an additional audit, on 5 business days notice, after a Security Incident or a written request from a regulator.

Sample wording, not legal advice.

Variants

Records only

The concern is financial or reporting accuracy, and nothing needs to be seen on site.

The Supplier must keep complete and accurate records of all fees charged, hours worked and expenses claimed under this agreement for 7 years after they are created. On 15 business days written notice, not more than once in any financial year, the Supplier must make those records available to the Customer or its accountant, electronically or at the Supplier's office, and must answer reasonable questions about them within 10 business days.

On site inspection

The customer needs to see physical security, storage or working practices for itself.

The Customer may, on at least 10 business days notice and during normal business hours, attend any site where the Services are performed or Customer Data is stored, to inspect the physical and technical controls required by this agreement. The Customer must comply with the Supplier's reasonable site safety and security rules, and must not attend for more than two consecutive business days unless the Supplier agrees.

Third party auditor

The supplier will not let a customer, and possibly a competitor, see its systems directly.

The Supplier must engage an independent auditor, approved by the Customer acting reasonably, to assess the Supplier's compliance with its obligations under Schedule 3 each year. The Supplier must give the Customer a copy of the auditor's report within 20 business days of receiving it, together with a remediation plan for every finding rated high. The Supplier bears the cost of the audit and the remediation.

What to negotiate

The risk of leaving it out

Without an audit right the customer must take the supplier's word for how data is handled and fees are calculated. It has no contractual way to look behind a report, and after an incident it may be unable to show a regulator it did anything to verify the supplier's controls. Any report the supplier chooses to share is then the only evidence available.

Why regulators expect an audit right

Article 28 of the UK GDPR requires a processor to make available all information needed to demonstrate compliance and to allow for and contribute to audits, including inspections, by the controller or an auditor it mandates. An Australian business covered by the Privacy Act must take reasonable steps under APP 11 to protect personal information, and being able to verify a supplier's controls is part of what makes those steps reasonable. In both systems the audit right is less about catching a supplier out and more about being able to show that the customer did not simply trust and hope.

Running an audit that is useful

Audits go badly when nobody agrees what is being tested. The clause, or a schedule to it, should tie the audit to specific obligations, such as the security controls or the fee calculation, so the auditor has a checklist and the supplier knows what to prepare. The notice should state the scope and the documents requested. Findings should be written up, shared with the supplier for comment, and followed by a remediation plan with dates. A clause that ends at inspection, with no obligation to fix what the audit finds, gives the customer knowledge but no remedy.

Where it sits in a generated document

In a generated services agreement the audit clause follows the obligations it tests, so it can cross refer to them by number. The numbered structure keeps routine audits and incident audits in separate sub clauses, which makes the shorter notice period for an incident easy to find. Values such as 20 business days and the cost rule are written as content, because documents carry no input fields. The generated text cites nothing, so any reference to Article 28 or the privacy principles should be checked against the source before the agreement is signed.

Documents that carry this clause

Questions people ask

How often can a customer audit a supplier?

As often as the contract allows. Once a year is the common routine limit, with extra audits permitted after a security incident, a material breach or a request from a regulator. Unlimited audit rights are hard for suppliers with many customers to accept, and a limit with sensible exceptions is usually agreed quickly.

Can a supplier refuse an audit?

Not if the contract gives the right and the customer follows the notice and scope rules. Refusing would be a breach. A supplier can insist that the auditor sign confidentiality terms, keep to the agreed scope, follow site safety rules and avoid disrupting operations, provided the clause says so.

Is an independent report as good as an audit?

Often good enough for routine years, if it is current, unqualified and covers the systems that hold the customer's data. It is not a full substitute, because its scope was set for many customers rather than one. Keeping a fallback right to audit directly where the report falls short is the usual approach.

Who pays for an audit?

Normally the party carrying it out, with each side bearing its own staff time. Many clauses shift the cost to the supplier if a material breach is found, and some let the supplier charge for time beyond a set number of hours. Stating the position avoids an invoice dispute after the audit ends.

Does a UK processor contract need an audit right?

Yes. Article 28 of the UK GDPR requires the processor to make available the information needed to demonstrate compliance and to allow for and contribute to audits, including inspections, by the controller or an auditor it mandates. A processing contract without that term does not meet the requirement.

What happens after an audit finds a problem?

That depends on the clause. Good versions require a written report, a remediation plan with dates, and a follow up check, and link a serious or unremedied finding to the termination clause. Without those steps the customer knows about the problem but has to rely on general breach remedies to make the supplier act.

Put the clause in a finished document

The button opens the document generator with a starting description already filled in. Change it to match your own agreement before you run it.

Create a document with OneCraft

Related clauses

For everything the document generator can do, see the document maker.

Step by step in the builder: Create a document with AI, then Document builder components.

Sources

Written and checked by the OneCraft team. Last checked .