π© 10 Red Flags to Look for in Any Vendor Agreement
You sign more vendor agreements than you realise β and most never get a proper read. A practical guide to the ten clauses that quietly change your risk, and how to catch them before you sign.

You probably sign more vendor agreements than you realise.
SaaS subscriptions, marketing retainers, recruitment agencies, cloud platforms, payment processors, AI tools, logistics providers, data vendors. Most never get a proper read. They look familiar, the commercial terms seem fine, and they get signed because "it looks standard." That is usually where problems start.
A vendor agreement can quietly lock you into automatic renewals, uncapped liability, one-sided termination rights, and broad IP clauses you never intended to agree to. The hard part? These risks rarely look dramatic. They look ordinary.
Good contract review is not about turning every agreement into a 40-page negotiation. It is about spotting the few clauses that actually change your risk profile.
This guide covers the 10 most common red flags in vendor agreements β why they matter commercially, and what to do before signing. Built for founders, operations leads, procurement managers, and in-house lawyers.
π© The 10 red flags at a glance
- Automatic renewal clauses
- Uncapped liability
- Broad intellectual property clauses
- One-sided termination rights
- Weak data protection obligations
- Hidden price escalation clauses
- Vague service levels
- Broad confidentiality exceptions
- Missing documents and undefined policies
- Non-compete and exclusivity clauses
π First: what is a vendor agreement?
A vendor agreement is simply a contract between your business and a supplier providing goods or services. That could include SaaS subscriptions, marketing agencies, and IT service providers; AI platforms, consultants, and cloud infrastructure; or recruitment firms, logistics companies, and payment providers.
Some are lightweight and low-risk. Others can seriously affect your operations, customer data, intellectual property, revenue, and legal exposure.
The mistake most businesses make: using the same review process for both. A S$100/month scheduling tool should not get the same scrutiny as a vendor handling customer data, core infrastructure, or mission-critical operations.
The key is knowing where the real risks usually sit.
π 1. Automatic renewal clauses
The contract renews automatically unless you terminate within a specific notice window. Sometimes that window is reasonable β sometimes it is not.
| β οΈ Clause | π‘ What it means |
|---|---|
| "Agreement renews automatically unless terminated 90 days before renewal." | You could be locked into another 12-month term even if you stopped using the service months ago. |
This becomes a real issue when the vendor underperforms, your business outgrows the product, pricing increases at renewal, or procurement simply forgets the deadline.
We have seen companies pay for another full year of unused software because nobody noticed the renewal window buried in page 27.
π What to look for
- Renewal notice periods longer than 30 days
- Multi-year automatic renewals
- Renewal pricing that is not fixed
- Early termination fees
β Better position
- Shorter renewal notice periods
- The ability to terminate for convenience
- Clear pricing caps on renewal increases
If the vendor refuses, at minimum make sure someone internally owns the renewal calendar.
π° 2. Uncapped liability
An uncapped liability clause means your company could theoretically be liable for unlimited losses β and it appears in "standard" contracts more often than you would expect. Sometimes it hides inside indemnities; sometimes it sits in a separate limitation of liability section.
| β οΈ Clause type | π‘ Why it is risky |
|---|---|
| Unlimited indemnity | Your exposure is not financially predictable |
| Liability cap applies only to vendor | The vendor is protected β you are not |
| "All losses arising from breach" | Scope is extremely broad |
For startups and SMEs, one legal dispute can exceed the value of the entire contract many times over. A S$20,000 services agreement should not expose you to millions in downstream liability without a very clear reason.
π What to look for
- Liability caps that only protect one side
- Broad indemnities with no limits
- No claim periods or time limits
- Liability for indirect or consequential losses
β Better position
- A financial liability cap
- Exclusion of indirect losses
- Time limits for claims
- Carve-outs only for serious issues like fraud or wilful misconduct
π‘ 3. Broad intellectual property clauses
Founders often assume they own everything created during an engagement. That is not always true. Some agreements transfer ownership of deliverables to the vendor; others give the vendor broad rights to reuse your materials, data, workflows, or internal processes.
| β οΈ Clause | π‘ Commercial impact |
|---|---|
| "Vendor retains all rights to improvements and derivative works." | The vendor may own modifications built using your input |
| "Client grants perpetual licence to materials provided." | Your internal content may keep being used after termination |
This matters most for software development, AI vendors, design work, marketing assets, data-heavy projects, and custom operational tooling. If you are paying to build something valuable, you should understand who actually owns it.
π What to look for
- Vendor ownership of "improvements"
- Broad perpetual licences
- Rights to use customer data for model training
- No distinction between background IP and new work product
β Better position
- Ownership of bespoke deliverables
- Clear carve-outs for vendor pre-existing IP
- Restrictions on data usage
- Clarity on post-termination rights
Especially important for AI vendors β many bury data usage rights inside technical appendices or privacy schedules.
πͺ 4. One-sided termination rights
A balanced agreement gives both parties reasonable termination rights. A bad one gives flexibility only to the vendor.
| β οΈ Vendor right | π‘ Your position |
|---|---|
| Vendor may terminate immediately for convenience | You are locked into a fixed term |
| Vendor may suspend services for broad reasons | Your operations may stop unexpectedly |
| Vendor may change pricing during term | You must continue paying |
If your CRM, payment infrastructure, AI tooling, or cloud systems disappear overnight, the legal issue quickly becomes a business continuity issue.
π What to look for
- Immediate suspension rights
- Broad vendor discretion clauses
- No customer termination rights
- Long lock-in periods
β Better position
- Mutual termination rights
- Cure periods before suspension
- Reasonable notice requirements
- Transition assistance if services end
π 5. Weak data protection obligations
This has become far more important with SaaS and AI vendors, who now often access your customer information, employee records, commercial data, financial information, and confidential operational materials. Yet some agreements say little beyond "reasonable security measures" β not enough if the vendor handles sensitive data.
| β οΈ Data risk | π‘ Why it matters |
|---|---|
| No breach notification timeline | You may learn about incidents too late |
| No subcontractor controls | Data may be shared widely |
| No deletion obligations | Your information may remain indefinitely |
| Broad AI training permissions | Your data may be used to train models |
Some AI providers reserve rights to use uploaded information for βservice improvementβ or model development. You should know exactly what happens to your data.
β Better position
- Defined security obligations
- Breach notification timelines
- Restrictions on subcontractors
- Deletion obligations
- Express limits on AI training rights
π 6. Hidden price escalation clauses
The headline price in the proposal is not always the real price in the contract. Agreements often allow annual fee increases, usage-based uplifts, mandatory upgrades, additional user charges, or pricing changes after acquisition events.
The issue is rarely the increases themselves β the issue is unpredictability. A fast-growing startup can accidentally double its software spend simply because the pricing model scales aggressively with usage.
π What to look for
- "Vendor may revise fees from time to time"
- Undefined overage charges
- Mandatory bundled services
- Currency fluctuation pass-throughs
β Better position
- Fixed pricing periods
- Caps on annual increases
- Transparency around usage thresholds
If pricing is variable, ask for worked examples before signing.
π 7. Vague service levels
Phrases like "commercially reasonable efforts" or "industry standard service" sound reassuring but are often difficult to enforce. If uptime, response times, implementation timelines, or support matter to you, they should be specific.
| β Weak clause | β Better structure |
|---|---|
| "Vendor will provide reasonable support." | Defined response times and escalation procedures |
| "Commercially reasonable uptime." | Specific uptime % with service credits |
This matters most for operational infrastructure β payment systems, customer support tooling, cloud hosting, logistics, or AI infrastructure. If the service fails, your business may fail with it temporarily.
Ask for measurable commitments where reliability matters. Even basic service-level obligations beat vague promises.
π€ 8. Broad confidentiality exceptions
Most confidentiality clauses look standard β the problems sit inside the exceptions. Some define "confidential information" so narrowly that little is protected; others allow broad disclosure to affiliates, subcontractors, or external advisers without meaningful controls. Also check how long obligations survive after termination.
π What to look for
- Broad affiliate-sharing rights
- Short confidentiality periods
- Narrow confidentiality definitions
- Weak protections for customer data
β Better position
- Broader confidentiality definitions
- Tighter onward disclosure controls
- Survival periods that make commercial sense
For sensitive information, two years is often not enough.
π 9. Missing documents and undefined policies
A vendor agreement often references security policies, acceptable use policies, service schedules, pricing appendices, or technical documentation β but those documents are not attached. You may be agreeing to obligations you have never reviewed, and some agreements let the vendor update them unilaterally later.
| β οΈ Missing item | π‘ Risk |
|---|---|
| Security schedules | Unknown compliance obligations |
| Technical appendices | Hidden operational commitments |
| Acceptable use policies | Broad suspension rights |
| External policy links | Vendor can update terms later |
Do not treat missing documents as admin housekeeping. If a referenced document affects pricing, compliance, operational obligations, or suspension rights β review it before signing.
π 10. Non-compete and exclusivity clauses
Some vendor agreements quietly restrict who you can work with, what you can use, or how you operate during the term β sometimes openly, sometimes buried inside a commercial exclusivity section.
| β οΈ Clause | π‘ Commercial impact |
|---|---|
| "Client shall exclusively use Vendor for [service]." | You may be blocked from using competing providers |
| "Client shall not engage alternative providers during term." | Your negotiation leverage disappears |
| "Vendor receives first right to future projects." | Future procurement flexibility becomes limited |
Exclusivity is not always bad β but broad commitments create operational lock-in the moment the vendor underperforms, pricing rises, or a better option appears.
π What to look for
- Broad exclusivity obligations
- Restrictions on using competitors
- "Preferred vendor" lock-ins
- Automatic exclusivity extensions
β Better position
- Narrow exclusivity scope
- Shorter exclusivity periods
- Clear performance obligations tied to exclusivity
- Exit rights if the vendor fails to meet agreed standards
π Quick vendor agreement checklist
Before signing, check:
| π Issue | β Quick check |
|---|---|
| Renewal | Does it auto-renew? |
| Liability | Is liability capped fairly? |
| IP | Who owns deliverables and improvements? |
| Data | Can your data be used for AI training? |
| Pricing | Can fees increase during term? |
| Termination | Can both parties terminate fairly? |
| Service levels | Are commitments measurable? |
| Confidentiality | Are exceptions too broad? |
| Missing policies | Have all referenced documents been reviewed? |
| Exclusivity | Are non-compete or exclusivity terms too broad? |
If you cannot answer these confidently, the agreement probably needs another review.
π Final takeaway
Most vendor agreements do not fail because of one shocking clause.
Problems usually come from ordinary-looking provisions nobody paid attention to at the start.
A short review focused on the right issues can save a huge amount of operational and legal pain later. That is why more companies now adopt AI-assisted contract review β legal AI is especially good at spotting recurring risk patterns quickly and consistently.
π€ Try FD AI on your next agreement
At FD, we built FDΒ AI to help founders, operators, and legal teams review contracts faster β without drowning in legal jargon.
| β¨ What FD AI does | π‘ Why it helps |
|---|---|
| π© Flags commercial red flags | Catch the clauses that actually matter |
| π£οΈ Explains clauses in plain English | No legal jargon required |
| β‘ Reviews in minutes, not hours | A fast first pass before legal steps in |
Before signing your next vendor agreement, run it through FDΒ AI first. You may spot a problem before it becomes an expensive one.
Founder contract reads
More from FD AI

π What Founders Miss in their SAFE

π¨ The Legal Fine Print: 3 Contract Clauses Founders Should Never Ignore

βοΈ AI Contract Review vs Traditional Legal Review: What's the Difference?
Review your next contract with Jessica.
Know what youβre signing β in minutes, not hours.

