CIOPages
All RFP question modules

Commercial & Legal

Legal, contracting & IP questions to ask a software vendor

Questions on the contract terms that outlast the deal: ownership of your data, the vendor's IP and AI-generated output, indemnities, use of your data for training, liability, governing law and dispute resolution.

99
questions
32
RFI
36
RFP
31
deep-dive

8 questions from the RFI stage, free

These come from the module as sold. The workbook adds follow-ups, a response format, a weight and a score column to each.

1. Describe how your standard agreement allocates ownership of customer-provided input data, including any licenses you require to that data and the scope and duration of those licenses.

Why it matters. Customer input data (prompts, documents, embeddings) can be the buyer's confidential or copyrighted material. Vendor licenses that are broader than necessary, perpetual, or sublicensable create unacceptable IP and confidentiality exposure. This question surfaces the baseline allocation before negotiation.

Good answer
  • Customer retains ownership of all input data.
  • Vendor license is limited to providing the service and is narrowly scoped.
  • License terminates upon contract expiration, with clear data deletion commitments.
Red flags
  • Vendor claims broad or perpetual rights to customer input data.
  • License survives contract termination without a compelling justification.
  • Sublicensable to unnamed or a broad category of third parties.

2. Describe the scope of your general third-party IP infringement indemnification, including covered IP types (e.g., patent, copyright, trademark, trade secret) and any geographic limitations.

Why it matters. General IP indemnification is the buyer's primary protection against third-party infringement claims arising from use of the vendor's service. Gaps in covered IP types or geographic scope can leave the buyer exposed to litigation in jurisdictions where they operate.

Good answer
  • Indemnity covers patent, copyright, trademark, and trade secret claims.
  • Coverage is worldwide or at least covers all jurisdictions where the customer operates.
  • Indemnity explicitly covers costs of defense, settlement, and final judgments.
Red flags
  • Excludes patent infringement claims.
  • Limited to the vendor's home jurisdiction only.
  • Requires the customer to indemnify the vendor for the customer's ordinary use of the service.

3. State whether customer prompts, inputs, outputs, or any derived data are used to train or improve any model (your own, an upstream provider's, or a third party's) and identify the default setting for enterprise contracts.

Why it matters. Use of customer data for model training is a major confidentiality and IP risk. Buyers must know if their confidential data could be incorporated into model weights, and what the vendor's default posture is. 'Opt-out by default' is materially different and far riskier than a 'never used by default' commitment for enterprise customers.

Good answer
  • Confirms customer data is never used for training by default for enterprise customers.
  • The no-training default applies to the vendor, all upstream providers, and any other third parties.
  • The commitment is documented in the MSA, not a less-binding privacy policy or ToS.
Red flags
  • Training on customer data is opt-out only, especially with a high-friction process.
  • The no-training setting can be changed unilaterally by the vendor.
  • Makes a semantic distinction between 'training' and 'improving' or 'fine-tuning' to obscure data use.

4. State the governing law and exclusive venue proposed in your standard agreement, and confirm whether you will negotiate these terms for enterprise customers.

Why it matters. Governing law and venue determine the practical cost and feasibility of enforcing contractual rights. A unilateral choice of the vendor's home jurisdiction can make disputes economically impractical for the buyer to pursue.

Good answer
  • Confirms willingness to negotiate governing law and venue for enterprise contracts.
  • Proposes a recognized neutral jurisdiction (e.g., New York, England & Wales).
  • Supports floating jurisdiction based on the customer's location.
Red flags
  • Governing law and venue are non-negotiable.
  • Proposes a foreign domicile with a less-established or less-predictable rule of law.
  • Exclusive venue clause has no exception for seeking injunctive relief in other jurisdictions.

5. State who owns the output generated by your service in response to customer inputs, including any retained rights or licenses the vendor or upstream model providers claim in that output.

Why it matters. Default SaaS templates can leave output rights ambiguous, and upstream model providers may impose their own terms that flow down. Buyers need absolute clarity on whether they can use, modify, and commercialize outputs without restriction.

Good answer
  • Customer is assigned full ownership of or granted an unrestricted, worldwide, perpetual license to outputs.
  • Explicitly states which upstream model provider terms flow through to the customer.
  • Vendor retains no rights to output content beyond transient use for service delivery.
Red flags
  • Output ownership is assigned to the vendor by default.
  • Ambiguity or silence on the flow-down terms from upstream model providers.
  • Vendor retains rights to use customer outputs for marketing, benchmarking, or any other purpose.

6. State whether your IP indemnification expressly covers third-party claims that AI-generated outputs infringe copyright, including claims based on the provenance of training data.

Why it matters. Generic SaaS IP indemnities can carve out user-generated content, which vendors may argue includes AI outputs. This leaves buyers exposed to lawsuits over reproduced training data. Several major providers offer specific AI-output indemnities (e.g., Microsoft's Customer Copyright Commitment, Google Cloud's generative AI indemnification, OpenAI's Copyright Shield).

Good answer
  • Explicitly confirms that outputs are covered by the IP indemnity.
  • No carve-out for claims based on training data provenance.
  • Coverage applies when the customer uses the service and its outputs as delivered, without material modification.
Red flags
  • AI-generated outputs are explicitly excluded from IP indemnity.
  • Silence on output coverage, treating it as 'customer content' for which the customer is responsible.
  • Coverage is conditioned on undefined 'appropriate use' policies.

7. Describe any non-training secondary uses of customer data (e.g., abuse detection, safety classifier training, evaluation, benchmarking, debugging), including the retention periods and access controls for each use.

Why it matters. Vendors may disclaim data use for 'training' while retaining broad rights for 'safety,' 'evaluation,' or 'product improvement' that amount to similar data exposure. Buyers must understand the full set of secondary uses to evaluate the true confidentiality risk.

Good answer
  • Provides an itemized list of all secondary uses with specific, narrow purposes.
  • Specifies bounded data retention periods for each secondary use.
  • Human-review access is minimized, logged, and subject to strict controls.
Red flags
  • Uses a broad, catch-all 'to improve our services' clause.
  • Unbounded retention periods for data flagged for safety or abuse review.
  • Human review of customer data occurs without disclosure or meaningful controls.

8. Describe your dispute resolution mechanism, including any required pre-litigation steps, mandatory arbitration provisions, and the seat and rules of any arbitration.

Why it matters. The dispute resolution process shapes both the expected cost of a dispute and the realistic ceiling of recovery. Mandatory arbitration with restrictive rules or an inconvenient seat can effectively waive material remedies or make them prohibitively expensive to pursue.

Good answer
  • A tiered escalation process (e.g., executive review before formal proceedings).
  • A choice between arbitration and court litigation, or arbitration is optional.
  • Arbitration is administered by a recognized body (e.g., ICC, AAA, JAMS, LCIA) under standard rules.
Red flags
  • Mandatory, binding arbitration in a vendor-controlled or inconvenient forum.
  • A class-action waiver is coupled with a low individual liability cap.
  • Arbitration is required to be confidential, preventing discovery of patterns of misconduct.

The full set: 99 questions in a scored Excel workbook

  • RFI, RFP and deep-dive sheets, with an evaluator guide on every question
  • A 0–5 score column, suggested weights and a scorecard that totals by depth and section
  • An RFP cover template in Word
  • An audit log of all 142 changes made to the draft

Consultancy License $399, for use with any number of clients.

What the module covers

  • IP ownership: customer data, vendor IP, AI output (22)
  • Indemnification scope, caps & AI-specific coverage (25)
  • Customer-data use for model training (22)
  • Governing law, venue & dispute resolution (30)

What the audit changed

A language model drafted these questions and a second model critiqued them. Three audit passes followed and made 142 changes. Three examples:

Wrong or outdated citation

Draft: Exclusions are narrow, specific, and standard (e.g., based on the Berne Convention).

Now: Exclusions are narrow and specific, and each one is listed.

The Berne Convention is a copyright treaty between states. It says nothing about contractual indemnity exclusions.

Wrong or outdated citation

Draft: The cap on customer indemnity is at parity with (or greater than) the vendor's general liability cap.

Now: The cap on customer indemnity is no greater than the vendor's corresponding cap.

The signal was inverted: a customer indemnity cap greater than the vendor's favors the vendor, not the buyer.

Wrong or outdated citation

Draft: Claims the customer can be an additional insured on a professional liability or E&O policy without an endorsement to show it.

Now: Claims the customer can be an additional insured on a professional liability, E&O or cyber policy without an endorsement to show it.

Cyber policies added; see the why_it_matters edit (https://especialty.com/industry-insights/non-affiliated-additional-insureds-not-recommended/).

Questions about this module

How many legal, contracting & ip questions are there?

99: 32 for the RFI stage, 36 for the RFP and 31 deep-dive questions for the finalists.

What comes with each question?

Why it matters, what a good answer looks like, the red flags, follow-up questions, the response format, whether most buyers treat it as mandatory, and a suggested weight for scoring.

Were the questions checked?

A language model drafted them and a second model critiqued them. Three audit passes followed (2026-10-05) and made 142 changes, each listed in the workbook with the old and new text. No named subject-matter expert wrote them.

Related