Summary. Most organizations do not know how many vendors they have, which of them hold personal data, or what any of the contracts say about notification and audit. That gap is the reason a growing share of security incidents, regulatory findings, and operational failures originate outside the company entirely. A workable program has four parts that reinforce each other: an inventory that is current, a tiering method that concentrates effort where the risk is, diligence proportionate to the tier, and contract terms that give the company information rights and remedies it can actually use. This guide covers building each part, the provisions worth negotiating and the ones that are not, ongoing monitoring, and the offboarding step that companies most often skip and most often regret.
Ask a general counsel how many vendors the company uses and the answer is a guess. Ask which of them hold customer personal data and the answer is a smaller guess. Ask what the contract with the third-largest of those says about breach notification timing, and there is no answer at all, because nobody has read it since it was signed six years ago by a department that no longer exists.
That is the ordinary state of affairs, and it is why a substantial share of breaches, regulatory findings, and operational failures now originate with a third party. The company bears the consequence and frequently has no contractual leverage, because the leverage had to be negotiated before the vendor was needed.
A program that addresses this is not complicated. It is four things done consistently.
Part one: the inventory
You cannot manage what you have not listed.
Build a register of every third party that: processes or stores company or customer data; connects to company systems or networks; performs a function the company depends on operationally; has physical access to facilities; or acts on the company's behalf with customers or regulators.
For each: the legal entity name, the business owner, the service provided, the contract and its term and renewal mechanics, the data categories involved and their locations, the systems accessed, the annual spend, and the tier.
Where to find them. Accounts payable is the single best source — anyone being paid is a vendor, whether or not procurement knows. Then: the contract repository, the identity and access management system for accounts issued to third parties, network logs for external connections, expense reports for shadow purchases, and the security team's list of integrations.
Expect the count to be two to five times the estimate. Cloud services purchased on a corporate card by a department manager are the largest category, and they are frequently the ones holding data.
Then keep it current. An inventory that is accurate once is a project; one that stays accurate is a process, and it requires a procurement intake that no new vendor can bypass.
Part two: tiering
Effort must be proportionate. Applying enterprise diligence to a landscaping contractor wastes resources that a payroll processor deserves.
Tier on impact, not on spend. The relevant questions:
- Data. Does the vendor access, process, or store personal data, protected health information, cardholder data, or the company's material confidential information? At what volume and sensitivity?
- System access. Does the vendor connect to the network, hold privileged credentials, or push code into the company's environment?
- Operational dependency. If this vendor failed tomorrow, how long until the company's operations are materially impaired? A vendor with no data and no access can still be critical.
- Regulatory. Does the vendor perform a regulated function, or one for which a regulator holds the company responsible?
- Reputational and customer-facing. Does the vendor interact with customers under the company's name?
- Concentration. Do many functions depend on this vendor, or on a fourth party it depends on?
Three or four tiers is enough. Critical, high, moderate, low. Publish the criteria so business owners can predict where a vendor will land, and require the tier to be assigned before diligence begins.
Re-tier on change — a new service, a new data flow, a new integration, or a change in the vendor's own risk profile.
Part three: diligence
Proportionate to the tier, and completed before the contract is signed, when the company still has leverage.
For all tiers: confirm the legal entity and its good standing, screen against sanctions and debarment lists, and confirm insurance.
For moderate and above:
- Financial condition. A vendor that fails mid-term is an operational problem regardless of its security.
- A security questionnaire, proportionate in length. A three-hundred-question questionnaire sent to a ten-person vendor produces answers nobody verified.
- Attestations and certifications: SOC 2 Type II, ISO/IEC 27001, PCI DSS attestation of compliance, HITRUST where relevant.
- Insurance certificates: cyber, technology errors and omissions, general liability, and where applicable crime and fidelity.
For high and critical:
- Read the SOC 2 report rather than checking that one exists. What is in scope and what is excluded? What is the report period, and does it cover the current term? What exceptions did the auditor note, and what did management say about them? Most importantly, what are the complementary user entity controls — the things the report assumes the company is doing, which are frequently things the company is not doing.
- A security assessment, by the company's own team or an assessor, covering access control, encryption, logging and monitoring, vulnerability management, secure development, and incident response.
- Subcontractor and fourth-party disclosure. Who does the vendor depend on, where is the data actually hosted, and what happens if that party fails.
- Business continuity and disaster recovery plans, with tested recovery objectives.
- Data location and transfer analysis, including whether personal data leaves the jurisdiction and under what mechanism.
- A reference conversation with an existing customer of similar size, which surfaces operational reality that a questionnaire does not.
Document the diligence and the decision, including where a gap was accepted and why. A regulator or a plaintiff will ask what the company knew and what it did about it.
Part four: the contract
Diligence tells the company what the vendor does today. The contract is what the company can do about it tomorrow.
Security and data
A security exhibit referencing a named framework — NIST CSF, NIST SP 800-53, ISO 27001, or CIS Controls — rather than "commercially reasonable security measures," which means whatever the vendor was already doing. Specify the controls that matter: encryption in transit and at rest, multi-factor authentication on all administrative and remote access, logging with a defined retention, vulnerability remediation timelines by severity, and background checks on personnel with access.
A data processing addendum allocating controller and processor roles under GDPR Article 28 and the analogous state law provisions, with purpose limitation, confidentiality obligations, assistance with data subject requests, deletion or return on termination, and audit rights. Where personal data leaves the EEA or the UK, the standard contractual clauses plus a transfer impact assessment.
A business associate agreement where protected health information is involved, satisfying 45 C.F.R. § 164.504(e).
Subprocessor provisions: a current list, notice before adding one, a right to object, and flow-down of the same obligations. Fourth-party risk is real and it is contractual, because the company has no privity with the vendor's vendor.
Data location commitments, and restrictions on offshoring without consent.
Prohibition on use of company data for the vendor's own purposes, including training machine learning models — a provision that has become essential and that many vendor forms now expressly reserve.
Notification
Shorter than the company's own obligations. If the company owes a regulator notice within seventy-two hours of discovery, a vendor notification obligation of "without undue delay" is useless. Specify twenty-four or forty-eight hours from the vendor's discovery of a suspected incident — suspected, not confirmed, because confirmation takes weeks.
Content: what happened, what data, whose, when discovered, what is being done, and a named contact.
Cooperation: an obligation to provide forensic findings, to preserve evidence, to permit the company to participate in or conduct its own investigation, and not to notify affected individuals or regulators about the company's data without coordination.
Cost allocation for investigation, notification, credit monitoring, and regulatory response.
Audit and assurance
A right to audit, on notice, at the company's expense, no more than annually absent cause — and without the annual limitation following a security incident. Vendors resist unlimited audit rights and reasonably so; the compromise is an audit right plus an obligation to provide the annual SOC 2 and to remediate exceptions.
A right to require remediation of identified deficiencies within a stated period, with termination if not cured.
Liability
This is where the negotiation actually happens, and where most companies concede the provision that matters.
The standard vendor form caps liability at fees paid in the preceding twelve months and excludes consequential damages. For a vendor charging $80,000 a year and holding two million customer records, that cap is worth nothing against a notification cost of several million.
Carve out from the cap: breach of confidentiality and data security obligations, indemnification obligations, gross negligence and willful misconduct, and violations of law. Or negotiate a supercap — a higher, separate cap for data-related liability, commonly a multiple of fees or a fixed amount tied to the record count.
Indemnification for third-party claims arising from the vendor's breach of its security or data obligations, and for regulatory proceedings.
Insurance requirements: cyber and technology E&O at limits proportionate to the exposure, with the company as additional insured where the coverage permits, and certificates delivered annually.
Operational
Service levels with meaningful remedies. Service credits are usually the sole remedy and are usually trivial; negotiate a termination right for chronic failure, which is the remedy with teeth.
Business continuity commitments with tested recovery time and recovery point objectives.
Change control, so the vendor cannot materially change the service or its subprocessors unilaterally.
Assignment and change of control, so the company is not bound to an acquirer it never diligenced.
Exit
The provision companies most often omit and most often need.
- Transition assistance for a defined period after termination, at defined rates, including cooperation with a successor vendor.
- Data return in a specified, usable format, on a specified timeline.
- Certified deletion of all copies, including backups, within a stated period, with written certification.
- Survival of confidentiality, indemnity, and audit provisions.
- No hostage clause. Some vendors condition data return on payment of disputed amounts. Prohibit it expressly.
- Escrow for critical software, with release conditions that include vendor insolvency and failure to support.
Ongoing monitoring
A program that assesses at onboarding and never again is a point-in-time exercise, and risk changes.
Reassess on a cycle keyed to tier — annually for critical, every two years for high, on renewal for the rest.
Collect the annual assurance: the current SOC 2, updated insurance certificates, and confirmation that certifications remain in force.
Monitor externally. Security ratings services, breach notification databases, sanctions and debarment lists, litigation, and financial distress signals. Automated monitoring is imperfect and it surfaces changes a questionnaire will not.
Track performance: service levels, incidents, and escalations, reported to the business owner.
Watch for scope creep. A vendor onboarded for one purpose that now holds three additional data types and connects to two more systems needs re-tiering and re-diligence.
Report to governance. A quarterly report to a risk committee covering the population by tier, diligence completion, open findings, and concentration — including which vendors, if they failed, would materially impair operations.
Offboarding
The step nearly every organization skips.
When a relationship ends: terminate the vendor's access credentials and network connections on the last day, not eventually; obtain the data return and the deletion certification; confirm the vendor's subprocessors have deleted as well; retrieve or destroy company equipment and materials; remove the vendor from the inventory and from any list of authorized parties; and confirm no auto-renewal has quietly extended the term.
Orphaned access is the recurring failure. Companies routinely discover, during an incident, that a vendor terminated three years earlier still has an active VPN account. Run an access review against the vendor inventory quarterly and reconcile the two.
And confirm the data is actually gone. A deletion certification is a contractual commitment, not a technical fact, and for a high-tier vendor holding sensitive data it is worth verifying — through the audit right, through the next SOC 2, or by asking the vendor to describe the deletion process.
Regulatory expectations
Several regimes now expect a program rather than merely good outcomes.
Financial services. The Interagency Guidance on Third-Party Relationships: Risk Management (2023), issued jointly by the Federal Reserve, FDIC, and OCC, sets out a lifecycle framework — planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination — with governance and documentation expectations. NYDFS at 23 N.Y.C.R.R. § 500.11 requires a written third-party service provider security policy with minimum contractual protections.
Healthcare. HIPAA requires a business associate agreement with any party creating, receiving, maintaining, or transmitting protected health information on the covered entity's behalf, under 45 C.F.R. § 164.502(e) and § 164.504(e), with flow-down to subcontractors.
Privacy. GDPR Article 28 requires specific processor contract terms and prohibits engaging a subprocessor without authorization; the CCPA as amended imposes analogous requirements on service providers and contractors at Cal. Civ. Code § 1798.100(d) and § 1798.140, and the CPPA regulations specify required contract provisions.
GLBA. The FTC Safeguards Rule at 16 C.F.R. § 314.4(f) requires selecting service providers capable of maintaining appropriate safeguards, requiring those safeguards by contract, and periodically assessing them.
Government contracting. FAR and DFARS flow-down clauses, including DFARS 252.204-7012 and the CMMC framework, and supply chain prohibitions under Section 889 of the 2019 NDAA.
EU financial entities are subject to DORA, which imposes detailed ICT third-party requirements including a register of information, mandatory contractual provisions, and oversight of critical providers — relevant to any company serving EU financial institutions, because the requirements flow down.
Making it work
Route it through procurement, and make procurement mandatory. A program that business units can bypass by expensing a subscription is not a program. Enforce it at the payment layer: no purchase order and no card approval without an intake.
Make the intake short. A ten-question form that classifies the vendor and routes it to the right diligence path will be used; a forty-page onboarding packet will be evaded.
Standardize. A pre-approved contract template, a security exhibit, a DPA, and a BAA, with a documented fallback position for each negotiable term, lets most transactions close without legal review. Reserve counsel's time for the tier-one negotiations where it matters.
Set a risk acceptance process. Some vendors will not meet the standard and the business needs them anyway. Document the gap, the compensating control, the business justification, and the approver — at a level of seniority proportionate to the risk. A documented accepted risk is defensible; an undocumented one is a finding.
Start with the critical tier. An organization with eleven hundred vendors and no program should not begin by assessing eleven hundred vendors. Identify the twenty that hold the most sensitive data or on which operations most depend, do those properly, and expand.
Measure and report. Coverage, cycle time, open findings, and concentration. A program that cannot report on itself will not survive a budget cycle.
Primary authority
- Interagency Guidance on Third-Party Relationships: Risk Management, 88 Fed. Reg. 37920 (June 6, 2023) — the banking agencies' lifecycle framework.
- 23 N.Y.C.R.R. § 500.11 — the NYDFS third-party service provider policy requirement.
- 45 C.F.R. § 164.502(e) and § 164.504(e) — HIPAA business associate agreements and subcontractor flow-down.
- GDPR Articles 28, 32, 33, and 44–49 — processor contracts, security, notification, and transfers; the standard contractual clauses; Schrems II, C-311/18 (CJEU 2020) — transfer impact assessments.
- Cal. Civ. Code § 1798.100(d) and § 1798.140 — CCPA service provider and contractor contract requirements, and the CPPA regulations.
- 16 C.F.R. § 314.4(f) — the FTC Safeguards Rule service provider oversight requirement; 15 U.S.C. § 45 — Section 5 of the FTC Act.
- DFARS 252.204-7012 and NIST SP 800-171; Section 889 of the FY2019 NDAA; FAR Part 52 flow-down clauses.
- Regulation (EU) 2022/2554 (DORA) — ICT third-party risk requirements for EU financial entities.
- NIST Cybersecurity Framework 2.0, including the Supply Chain Risk Management category, and NIST SP 800-161 — the practical control frameworks a security exhibit should reference.
- SSAE 18 / SOC 2 — the attestation standard, including complementary user entity controls.
A worked build: ninety days from nothing
A four-hundred-person company with no program, an unknown vendor population, and a board that asked the question after reading about a peer's breach.
Weeks one to three: find them. Pull twenty-four months of accounts payable and dedupe by legal entity. The result: 640 payees, of which roughly 380 are genuine vendors and the rest are utilities, taxes, and reimbursements. Cross-reference against the contract repository, which holds 110 agreements — meaning 270 vendors have no contract on file, some because none exists and some because it was signed by a department and never centralized.
Pull the identity system for external accounts: 47 vendor accounts, of which nine belong to vendors nobody recognizes, two of which were terminated in prior years.
Weeks three to five: tier. Applying the criteria: 14 critical, 38 high, 96 moderate, and the balance low. The critical list is short and mostly unsurprising — payroll, the ERP host, the customer data platform, the managed security provider, the primary logistics partner — plus two nobody expected: a small marketing automation vendor holding the entire customer email list, and a document conversion service that had been receiving files containing employee records.
Weeks five to nine: diligence the critical fourteen. Request SOC 2 reports; eleven produce one. Two of those eleven have scopes that exclude the service the company actually uses. One report contains three exceptions in access provisioning with a management response that does not commit to a remediation date. Three vendors cannot produce any attestation, and two of those are the ones nobody had thought about.
Insurance certificates: four vendors carry cyber limits below the company's exposure to them.
Weeks seven to eleven: the contracts. Of the fourteen, six have no security exhibit, nine have notification obligations of "promptly" or nothing at all, and eleven cap liability at twelve months of fees. Three are on evergreen auto-renewal with notice periods the company has already missed twice.
Weeks nine to twelve: remediate. Terminate the nine orphaned accounts on day one — this is free and it is the largest immediate risk reduction available. Open renegotiations with the four vendors whose renewal windows are approaching, leading with notification timing and the liability carve-out, which are the two that matter. Accept documented risk for two small vendors where renegotiation is not realistic, with compensating controls and a senior approver.
Then build the process: a procurement intake nobody can bypass, enforced at the payment layer; a standard security exhibit and DPA; a fallback position sheet so most deals close without counsel; and a quarterly access review reconciled against the inventory.
Report to the board at ninety days: the population, the tiering, the fourteen critical vendors and their status, the two accepted risks, and the plan for the high tier over the following two quarters. Not "we have a program" — a number for each of those.
Negotiating with a vendor that will not negotiate
The program described above assumes leverage. Frequently there is none — the vendor is a hyperscale cloud provider, a dominant SaaS platform, or a payment network whose terms are published and non-negotiable, and the company is one of two hundred thousand customers.
What is actually available:
Read what you are getting. Large providers publish substantial commitments — a data processing addendum incorporating the standard contractual clauses, a security addendum, a subprocessor list with notice of changes, uptime commitments, and audit reports available under NDA. These are frequently better than what a mid-sized vendor will negotiate, and companies treat them as non-existent because they were not negotiated.
Use the configuration. Where the contract cannot change, the deployment can. Encryption with customer-managed keys, regional data residency settings, tenant isolation options, logging exports, access controls, and retention configuration are all in the company's hands, and most of them are unused defaults. A well-configured deployment on a standard contract is safer than a badly configured one on a negotiated contract.
Read the shared responsibility model. Every major provider publishes one, and it defines what the provider secures and what the customer must. The gap is where breaches occur, and it maps directly onto the complementary user entity controls in the SOC 2.
Buy the enterprise agreement where volume permits. The commitments available at an enterprise tier — contractual SLAs, dedicated support, negotiated liability, and additional compliance attestations — differ materially from the click-through terms.
Escalate through the account team on the two or three provisions that matter most, rather than redlining forty. Even non-negotiating vendors have an exceptions process, and a specific, justified request for a shortened notification period sometimes succeeds where a full markup does not.
Insure the residual. Where liability cannot be shifted contractually, the company's own cyber policy is the allocation mechanism, and the limits should reflect the concentration.
Document the acceptance. A memorandum recording that the terms were reviewed, that specific provisions were requested and refused, that compensating controls were implemented, and that a named executive accepted the residual risk. This is the difference between an informed business decision and a finding.
And reconsider concentration. Where a single non-negotiating provider holds a company-ending dependency, the mitigation is architectural — portability, exportable data, and a documented alternative — rather than contractual.
AI vendors and the new diligence questions
Generative AI services and AI-enabled features inside ordinary vendors have introduced a set of questions that standard questionnaires do not ask.
Does the vendor use company data to train models? The single most important question. Many vendor forms reserve broad rights to use customer data to "improve the service," which historically meant analytics and now means training. Prohibit training on company data expressly, including by subprocessors and model providers, and require deletion of any derived artifacts on termination.
Where does the inference happen, and who is the model provider? A vendor that appears to be a single company is frequently routing prompts to a third-party model API — a fourth party the company never diligenced, in a jurisdiction it did not approve, under terms it has not seen. Require disclosure of model providers as subprocessors.
What is the retention on prompts and outputs? Prompts frequently contain the most sensitive information the company holds, entered by employees who did not think of a chat box as a data transfer. Ask for zero-retention or short-retention configurations, which most enterprise offerings now provide.
Confidentiality and privilege. Employees pasting draft agreements, board materials, or client information into a vendor's AI feature may be disclosing to a third party in a way that affects confidentiality obligations and, for a law department, privilege. Address it in policy as well as in contract.
Output ownership and IP risk. Who owns the output, what indemnity does the vendor offer for third-party IP claims arising from it, and is that indemnity conditioned on the customer using specified guardrails? Several providers now offer such indemnities, with conditions.
Accuracy, and the human in the loop. Where the vendor's output feeds a decision affecting individuals — hiring, credit, insurance, housing, or benefits — the company may be subject to state AI and automated decision-making rules, the EU AI Act if it operates there, and existing antidiscrimination law regardless. Diligence should establish what the model does, what testing exists for disparate impact, and what documentation the vendor will provide to support the company's own compliance obligations.
Change control. Models change without notice, and behavior changes with them. Require notice of material model changes for any use that matters.
And inventory the shadow deployments. AI features are being switched on inside vendors the company already uses, without a new contract or a new purchase order. The inventory has to capture capability, not merely vendor identity.
When a vendor fails
Programs are built for security incidents and tested by something more mundane: a vendor that goes out of business, gets acquired, is breached, or simply stops performing.
Insolvency. A vendor in bankruptcy may reject the contract under 11 U.S.C. § 365, leaving the company with a claim and no service. Where the vendor licensed intellectual property, § 365(n) permits the licensee to elect to retain its rights — a provision that applies to software licenses and that does not guarantee continued support or hosting. Data held by an insolvent vendor is the acute problem: it is an asset of the estate, access frequently ends abruptly, and recovering it may require a motion. The protections that work are technical and prospective: current exports in the company's possession, source code escrow with insolvency as a release condition, and a documented migration path.
Acquisition. The vendor is bought by a competitor, by a private equity sponsor that will cut support, or by a foreign entity that changes the data location analysis. An assignment and change of control provision requiring consent — or at minimum a termination right — is the protection, and it must be negotiated before it is needed.
A vendor breach. Covered above, and the contract terms governing notification timing, cooperation, and cost allocation are the whole of the company's leverage.
Performance failure. Service credits are almost always the sole remedy and almost always trivial. The remedy with teeth is a termination right for chronic failure, defined objectively — three consecutive months below the SLA, or four in twelve.
Sanctions or debarment. A vendor added to a sanctions list must be terminated immediately, and payments to it must stop. Screening at onboarding is insufficient; screening must be periodic.
Concentration failure. The most consequential and least planned for. Where many functions depend on one vendor, or where several vendors depend on the same fourth party, a single failure cascades. Map the dependencies, including the ones the company does not contract with directly, and identify what has no alternative.
The exit plan is the answer to all of it. For every critical vendor: what would we do, how long would it take, what would it cost, and what do we need to hold today to make it possible. Written down, reviewed annually, and — for the two or three most critical — actually tested.
Answering someone else's questionnaire
Every company is also a vendor, and the diligence runs both directions. Handling inbound assessments well is a commercial advantage and handling them badly delays revenue.
Build the artifacts once. A current SOC 2 Type II with a scope covering what customers actually buy; a security whitepaper describing the architecture and controls; a completed CAIQ or SIG questionnaire maintained as a living document; insurance certificates; the DPA and subprocessor list; and a public trust page. Most inbound questionnaires can then be answered by mapping to existing content rather than by starting over.
Answer honestly. A "yes" that is not true becomes a contractual representation, a misrepresentation claim, and — in an insurance context — the basis for a coverage denial. Where a control is partially implemented, say so and describe the compensating control and the roadmap. Sophisticated customers respect that answer; they do not respect discovering the truth later.
Push back on scope proportionately. A three-hundred-question assessment for a low-risk service is a negotiation, not a requirement. Offer the SOC 2 and the standard questionnaire, and reserve custom responses for the customers whose business justifies it.
Track what you commit to. Questionnaire answers and security exhibits create obligations that the engineering organization frequently does not know about. Maintain a register of customer-specific commitments — encryption requirements, data residency, notification timing, audit rights, retention limits — and make sure operations can meet them.
Anticipate the flow-down. Regulated customers must impose their obligations on you: banking guidance, HIPAA, GDPR Article 28, DORA. Prepare positions in advance on notification timing, audit rights, subprocessor consent, and liability, and know which are genuinely unacceptable rather than negotiating each one from scratch.
Watch the liability asks. Customers increasingly demand uncapped liability for data breach. A vendor cannot rationally accept unlimited exposure at any price; the workable answers are a supercap, an insurance-backed limit, or a carve-out limited to breach caused by the vendor's failure to meet the specified security standard.
And use it. A company that can produce a current SOC 2, a completed SIG, and a clean subprocessor list within a day closes deals faster than one that treats each assessment as a fire drill. The program that protects the company is the same program that sells it.
Related articles
- Data Breach Response and Notification: The Fifty-State Patchwork, Regulators, and Litigation — what happens when a vendor's incident becomes yours.
- Responding to a Data Breach: The First Seventy-Two Hours — the operational response, including the vendor-origin variation.
- Cloud and SaaS Agreements: Service Levels, Data Rights, Security, and Exit — the contract type most vendors present.
- Negotiating a Master Services Agreement and Statement of Work — the commercial framework.
- Indemnification and Limitation of Liability: The Risk Allocation Engine of Every Contract — the cap and the carve-outs.
- HIPAA Business Associates and Cloud Computing — the healthcare flow-down.
- International Data Transfers After Schrems II: Standard Contractual Clauses and Transfer Impact Assessments — cross-border data in the vendor chain.
- State Consumer Privacy Laws: The CCPA, the CPRA, and the Multi-State Patchwork — service provider and contractor requirements.
- Preparing a Business Continuity and Crisis Management Plan — dependency on a critical vendor.
- Open Source Software: Licenses, Compliance, and Risk — the supply chain inside the vendor's product.
This guide is provided for general informational purposes and does not constitute legal advice. Third-party risk requirements differ by sector and jurisdiction, and financial services, healthcare, government contracting, and EU-regulated entities are subject to specific and detailed obligations. Contract terms described here are negotiating positions rather than requirements, and what is achievable depends on relative leverage. Consult qualified counsel when building a program or negotiating a material vendor agreement.