You have just received a draft service agreement from a new enterprise client — or you are about to send one to your own customer — and tucked at the back is a service level agreement schedule. Alternatively, you are a managed IT provider or SaaS founder preparing your first formal SLA and have found a template online. Either way, the same question presents itself: what should actually be in this thing, and why?
A service level agreement (SLA) is a contract, or more often a schedule to a broader contract such as a master services agreement (MSA), that sets out measurable performance standards and what happens if they are not met. It is an operational document, not a general legal framework. The MSA typically handles payment, intellectual property, liability and termination; the SLA handles uptime targets, response times, credits and reporting. The two must be read together — conflicts between them are a common source of disputes.
What the essential clauses do
Scope of services
Every SLA should open with a precise scope clause that defines what is — and what is not — covered. This clause identifies the specific services, systems or deliverables to which the performance standards apply. Without it, parties routinely disagree about whether a particular outage or delay was even within scope.
Drafting traps to watch for:
- Overly broad scope language that imports obligations you did not intend (for example, "all systems" when you only manage one layer of a stack)
- No mechanism to update scope when services change, which creates a mismatch between what you deliver and what the SLA measures
- Missing links to a service description or statement of work that spells out the detail
Service levels and metrics
This is the commercial heart of the SLA. The clause sets the measurable targets your business commits to — availability percentages, response times, resolution times, throughput or accuracy rates depending on your service type.
Key drafting choices:
- Availability is typically expressed as a percentage of total scheduled uptime in a measurement period (for example, 99.5% monthly availability). Define the denominator precisely — total calendar minutes, scheduled hours only, or something else — and specify which events count as downtime and which do not (see Exclusions below).
- Response and resolution times are often split by priority tier (commonly P1 through P4). Set the priority definitions clearly enough that both sides can categorise an incident consistently without calling a manager.
- Metrics must be measurable. If your tooling cannot produce the number, do not commit to it. A metric you cannot measure is unenforceable in practice and creates a false sense of security on both sides.
Avoid committing to figures you can reliably achieve only in ideal conditions. If your SLA promises 99.9% uptime but your infrastructure cannot sustain that during peak load or during a hardware refresh, you have an exposure. Under s 18 of the Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010 (Cth)), representations about service performance that you cannot substantiate — including figures stated in marketing materials or contracts — can constitute misleading or deceptive conduct.
Measurement, monitoring and reporting
Once you have set targets, you need a clause explaining how performance will be measured, who does the measuring, and what evidence is produced. This clause matters because the party who controls the data controls the credits.
Typical contents:
- The tooling, logs, probes or third-party platforms used to record uptime and incidents
- Who has access to reports — both sides should have visibility
- Reporting cadence (monthly is common for most services) and what each report must contain: aggregate metrics, incident counts, service credits issued, and root cause analysis for significant events
Where the customer disputes your measurement methodology, this clause is the first document they will look at. Vague language here frequently causes disagreements that a few extra sentences at drafting stage would have avoided.
Support tiers and contact channels
Spell out when support is available (business hours versus around-the-clock coverage), how customers log requests (a portal, phone, email), and whether different support plans attract different response commitments. If you offer tiered support plans, map each plan to its corresponding SLA targets in a table or schedule — do not leave clients guessing.
Service credits and remedies
Service credits are the standard remedy when a provider misses its SLA targets. The drafting choices here determine both the financial risk you are carrying and whether the regime is fair enough to survive scrutiny.
Define each of the following:
- How credits are calculated — typically a percentage of the monthly service fee attributable to the affected service, scaled to the severity of the breach
- Monthly cap — most providers cap credits at a percentage of monthly fees (for example, 10–20%), with an aggregate cap across the term
- Exclusivity — an exclusivity clause makes service credits the sole remedy for an SLA breach, preventing a customer from also claiming damages. This is a significant allocation of risk that the other side will often push back on.
- Claim process and time limit — require the customer to submit a claim within a defined period (commonly 30 days) after the relevant reporting period, or forfeit the credit
Be clear that credits are not available where the miss was caused by the customer's own failure to meet their obligations.
Customer obligations and dependencies
SLA targets rarely exist in a vacuum. Response and resolution times often depend on the customer providing system access, nominated contacts, timely sign-off, or maintaining their own network and infrastructure to a minimum standard.
Include a clause that:
- Lists the specific obligations the customer must meet for performance targets to apply
- States that targets are suspended ("stop the clock") while the provider is waiting on customer inputs
- Identifies a customer-side contact with authority to approve changes or accept resolutions
Without this clause, a provider who misses a target because a customer withheld access has no contractual basis to resist a credit claim.
Exclusions and force majeure
The exclusions clause defines what does not count as downtime or an SLA breach. Common exclusions include:
- Scheduled maintenance windows (provided adequate notice has been given)
- Emergency maintenance required to preserve security or prevent data loss
- Events caused by customer misuse, unauthorised modifications, or third-party services outside the provider's reasonable control
- Force majeure events
Tie the exclusions back to your uptime formula precisely — if scheduled maintenance is excluded from the denominator, say so. Inconsistency between your uptime calculation and your exclusions clause is a reliable source of disputes.
Liability and liability caps
The SLA's remedies framework must be consistent with the liability clause in the underlying MSA or service agreement. Most providers exclude liability for indirect, consequential or economic losses — including lost profits and reputational harm — and impose an aggregate cap on liability.
Key considerations:
- The service credits regime (exclusive remedy) and the broader liability cap should be aligned. If they are not, a claimant may argue that the cap does not limit claims that go beyond the SLA breach itself.
- Caps that are disproportionately low relative to the value of the services, or that exclude liability in ways that are one-sided, may be vulnerable to challenge under the unfair contract terms regime (discussed further below).
Term, renewal and exit
State when the SLA starts and ends (usually aligned with the underlying agreement), how it renews, and what happens on exit: data return or deletion obligations, transition-out assistance, and any survival provisions (such as an obligation to pay outstanding credits).
Optional clauses worth including in the right circumstances
- Change control procedure — if your service or the customer's requirements evolve, a formal change control clause allows metrics to be varied by mutual agreement. Essential for multi-year contracts.
- Governance and service reviews — quarterly review meetings, KPI dashboards and improvement plans keep the SLA relevant and signal a mature service relationship. Worth including for larger or longer-term contracts.
- Security and privacy schedule — where you handle the customer's personal information or sensitive data, a separate data processing agreement and security schedule keeps the operational SLA focused and ensures privacy obligations (under the Privacy Act 1988 (Cth)) are documented separately.
- Subcontracting — if you use hosting providers or other subcontractors to deliver any part of the service, confirm that you remain responsible for overall performance and that you will flow down the relevant obligations to subcontractors. Reserve the right to change providers on notice.
- Dispute escalation — a tiered escalation ladder (operational contact → senior manager → mediation) reduces the chance that a credit dispute turns into litigation.
Where Artificer Legal can help
SLAs involve several points where professional review is worth the investment.
Metrics and measurability. A practitioner can sense-check whether your targets are realistic and whether your definitions — particularly uptime formulas and priority classifications — are precise enough to be enforceable.
Unfair contract terms exposure. If you supply services using a standard form contract to small businesses (generally those with fewer than 100 employees or annual turnover below $10 million), your SLA terms must not be unfair under the Australian Consumer Law. Since November 2023, using or relying on unfair terms in standard form contracts is prohibited and attracts significant penalties. Clauses the ACCC has identified as potentially unfair in service contracts include: broad unilateral variation rights (for example, a right to change service levels without notice), disproportionate termination rights, and liability caps that are wholly one-sided. Artificer Legal can review your standard form SLA and flag terms that carry this risk.
MSA alignment. We routinely identify conflicts between SLA schedules and the liability, remedy and termination provisions of the underlying MSA. Resolving those conflicts before a dispute arises is considerably cheaper than resolving them after one.
Credit calibration and exclusivity. We can advise on whether your credit regime — caps, exclusions, the exclusive remedy carve-out — is commercially appropriate and balanced enough to hold up when challenged.
Negotiation. When you receive an SLA from a larger counterparty, it will typically reflect their interests. We can identify the clauses that carry the most risk for your business and prioritise what to push back on.
The clause that makes the difference
The single SLA provision that most often determines whether a dispute is resolved quickly or ends up in litigation is the measurement and reporting clause — not the service credits clause, which tends to get all the attention. Credit disputes almost always come down to a disagreement about whether a particular outage occurred, how long it lasted, and whether an exclusion applied. A well-drafted measurement clause — specifying the tooling, the evidence each side can access, and how exclusions are recorded — closes most of those arguments before they start. If your SLA describes targets in detail but is vague about how performance is measured, it is unfinished work.
In summary: an SLA turns performance promises into enforceable obligations, but only if its clauses are precise, internally consistent and matched by your operational capability. The essential building blocks are scope, metrics, measurement, customer obligations, service credits and exclusions. Those clauses should be drafted together, not assembled from templates that were not designed to work with each other. The SLA should then be reviewed alongside the MSA it sits under to confirm that the remedies, liability and termination provisions are aligned across both documents.