Last month I read an MSP's master services agreement where the indemnification clause ran only one way. Indemnification is the part of your contract that settles who pays when a third party, someone outside the deal between you and your client, brings a claim. This one said the MSP would cover the client for the MSP's own mistakes. It said nothing about the client covering the MSP for anything, no promise on data privacy, none on intellectual property, none anywhere.
The problem with a one-way clause shows up when a third party sues over something that happened on an engagement. Indemnification is the provision that decides whose money funds the defense and the loss. A clause that carries only your obligations means that when the trouble starts on the client's side, you can still be the one writing the checks, a defense paid out of your operating account, for a claim you could have shifted to the party that caused it.
This piece walks through what a balanced indemnification clause actually covers, the client-side promises worth adding, and how to line the whole thing up with your errors and omissions insurance. That is the coverage that pays when your own mistake costs a client money. The goal is simple: the protection you think you have is the protection you actually wrote. It assumes you already operate under a master services agreement. If you want the plain-language version of what that document is, start with the key components of an MSA.
What an indemnification clause actually does
Start with the situation the clause is built for. Something goes wrong on an engagement, and a third party, not your client but a customer of your client, a regulator, or a vendor, brings a lawsuit. Someone has to pay to defend it, and someone has to pay if the claim lands. Your indemnification clause is where you and your client agree, ahead of time, which of you that someone is.
That is the whole job. It does not decide who was right. It decides who funds the fight and the outcome when a third party pulls one of you into court. Get the language right and the cost falls on the party that caused the problem. Leave it vague or one-sided and the cost can fall on you by default, whether or not the underlying mistake was yours.
A good indemnity runs both ways
A properly built indemnification clause runs in both directions. You indemnify the client for your own negligence, errors, omissions, and breach of the terms you agreed to. The client indemnifies you for issues tied to the client's own services and conduct. A clause that carries only your obligations, and asks nothing of the client in return, is incomplete.
The direction that gets left out is the client's. In the agreements we review for MSPs, we see clauses that name everything the MSP owes and leave the client's side blank. That is the gap to close, because a third-party claim can trace back to something the client did just as easily as to something you did.
Naming your own negligence or breach of the service agreement in the clause can feel like handing the client ammunition. It is not. Those are among the core professional risks technology errors and omissions insurance is designed to address. The contract should track the scope of the technology E&O coverage, including covered acts, errors, omissions, negligence, and breaches arising from the performance of technology services, subject to the policy's terms and exclusions. More serious conduct, such as gross negligence or willful misconduct, may be treated differently. Depending on the governing law, courts may refuse to enforce a waiver or limitation of liability for such conduct on public-policy grounds. Addressing ordinary performance failures expressly does not create a new obligation or increase the underlying risk. It aligns the contractual allocation of risk with the services being performed and the insurance maintained to protect against those risks.
The client-side indemnities worth adding
When the client's side of the clause is thin, three protections are the ones worth checking for. Each one covers a loss that starts with the client, and each one belongs in the client's column, not yours.
Data privacy When a client mishandles the personal data in its own systems, or hands you instructions that cause a privacy violation, a client-side data-privacy indemnity puts that loss where it began. Confirm your contract names it. For how the underlying privacy duties get allocated in the first place, see the data processing agreement for MSPs.
Intellectual property infringement If a client directs you to deploy software it lacks the rights to, or builds on your work in a way that infringes someone else's intellectual property, the resulting claim is the client's to cover. Check that your indemnity says so, rather than leaving you to defend a choice you did not make.
The client's licensing gaps When a client runs software it has under-licensed or licensed wrong, the exposure can land on whoever the rights-holder can reach. Check that the client indemnifies you for its own licensing shortfalls, so a gap in the client's paperwork does not become a claim against you.
None of these are exotic. They are the ordinary ways a client's own decisions turn into a third-party claim, and the balanced version of the clause simply says the client, not the MSP, answers for them.
Tie the indemnity to your E&O insurance
An indemnification clause is a promise to pay. The question that follows is whether you can actually pay it, and that answer lives in your insurance. So the clause has to line up with your E&O policy, your errors and omissions coverage, the policy that pays out when your own professional mistake costs a client money. If your contract promises more than the policy will cover, the difference between the two is a number you fund yourself.
There is a second reason to tie the two together, and it protects the coverage you already pay for. When the indemnity is written to match the policy, it is harder for an insurer to point at the contract language as a reason to pay less than the policy limits after you have caused actual damages. The clause can expressly give the client the right to recover from the E&O coverage you maintain, which turns your policy into part of the protection your client is counting on rather than a document the two of you argue about later.
An indemnity your insurance cannot cover is not a safety net. It is a bill with your name on it, sitting behind language that reads like protection.
Alignment runs both ways here too. A balanced agreement asks the client to carry its own insurance, including first-party cyber liability coverage, so that when a loss starts on the client's side there is a policy standing behind the client's promise, not just words. When we take on a new MSP, one of the first things we do is read your E&O policy and align the indemnity provision in your contract to what that policy actually covers, on both sides. It is a short exercise, and it closes a gap that is easy to miss until a claim finds it.
Indemnification vs. limitation of liability: who pays vs. how much
Indemnification gets confused with your limitation of liability clause, and the two do different jobs. It is worth separating them once, clearly, because a contract needs both and neither one covers for the other.
Your limitation of liability clause sets a ceiling, the most a client can recover from you when a claim lands. Indemnification sets direction, which party pays when a third party sues. One controls how much. The other controls who. A strong cap does nothing to help you if the clause never shifted the claim to the client in the first place, and a balanced indemnity does not save you if your cap is set wrong or tied to the wrong number.
Indemnification is one of the provisions I put real weight on when I review an MSP's contract, alongside the cap, because together they answer the two questions your exposure comes down to, who pays and how much. For the depth on how to set the cap itself, the amount, what to tie it to, and where a fee-only cap leaves you short, see limitation of liability for MSPs. This guide stays on the who-pays question. That one covers how much.
What to check in your indemnification clause
If you pull up your own agreement today, this is the short version to check it against.
- Indemnification decides who funds a third-party claim. Read yours to see which way it runs.
- A balanced clause has you cover the client for your own negligence, errors, and omissions, and has the client cover you for issues that start on the client's side.
- Add the client-side indemnities worth having: data privacy, intellectual property infringement, and the client's licensing gaps.
- Line the indemnity up to your E&O policy, so you are not promising more than your insurance can pay, and have the client carry its own coverage too.
- Indemnification and your liability cap do different jobs. Keep both, and keep them consistent with each other.
If you are not sure which way your clause runs, or whether it matches the policy you carry, that is exactly the kind of thing a second set of eyes should catch before a claim does. An attorney can check whether your indemnification clause is balanced, whether it covers the client-side obligations above, and whether it aligns with your E&O coverage.
Not sure which way your indemnification clause runs? Get a free MSA review →
Indemnification is one piece of a larger picture. For the full set of provisions that decide how protected an MSP actually is, and how they fit together, see what belongs in an MSP Master Services Agreement.
An indemnification clause that runs only one way, or one your insurance cannot cover, is not protection. It is exposure you have not priced yet.
By Rob Scott, CEO and attorney, Monjur. 25-plus years advising MSPs.