Reviewing an audit rights clause

Review of an audit rights clause, from the audited party's or the auditing party's side, marked up with a written explanation, for a fixed fee of £495 in three working days.

Share

Reviewing an audit rights clause

A review of an audit clause in a commercial contract, from the side being audited or the side auditing, covering the scope and purpose of the audit, notice, frequency and access, who audits and at whose cost, confidentiality and the other customers' data, the statutory audits a controller must be able to carry out, and what happens with the findings. £495, in three working days.

Buy now, £495

An audit clause gives one party the right to inspect the other's premises, systems, records and staff to check compliance with the contract, and its terms decide the scope of that access, when it can be exercised, who pays for it and what the findings lead to. Some audits are required by law, for data processors and for anti-corruption procedures, and cannot be refused; the rest are a matter of negotiation. I review the clause from whichever side instructs me and return it marked up with a written explanation of what access it gives, what it should be limited to, and the changes the other side will accept, for a fixed fee of £495 in three working days.

Who this is for

Suppliers, processors, licensees, franchisees and sub-contractors in England and Wales asked to accept audit rights, and customers, controllers, licensors and prime contractors wanting to exercise them, in services, software, licensing, outsourcing, franchise and public sector contracts. Both parties are businesses.

What to look for in an audit rights clause

Scope and purpose: what the audit may look at and why

The clause should tie the audit to a purpose, verifying charges, compliance with the contract, security, regulatory obligations, and limit access to the records, systems, premises and personnel relevant to that purpose. The review narrows an audit of 'all books and records' to the records relating to the contract, excludes the audited party's cost base, margins and other customers' information, and asks for the auditor to be given what is needed to answer the question rather than everything.

Notice, frequency, hours and disruption

Audits should be on reasonable notice, during working hours, no more than once a year unless a breach has been found or a regulator requires it, and conducted so as not to disrupt the audited party's operations. The review adds those limits, provides for remote audit and reliance on existing audit reports and certifications before an on-site visit, and asks for the auditing party to bear its own costs and the audited party's reasonable costs unless the audit reveals a material breach.

The statutory audits that cannot be refused

A controller must be able to audit its processor: Article 28 of the UK GDPR, applied with the Data Protection Act 2018, requires the processor's contract to make available all information necessary to demonstrate compliance and to allow for and contribute to audits and inspections. A business relying on adequate procedures under section 7 of the Bribery Act 2010 audits its intermediaries, and a business with obligations under section 54 of the Modern Slavery Act 2015 audits its supply chain. The review keeps those audits within the clause and confines the negotiation to the audits the law does not require.

Who audits, confidentiality and other customers' data

The auditor may be the customer's own staff, its internal audit function, an external accountant, or a regulator, and the review asks for an independent auditor bound by confidentiality where the audited party's records contain other customers' information or trade secrets, which the audited party must protect to keep them within the Trade Secrets (Enforcement, etc.) Regulations 2018. It also excludes competitors of the audited party from acting as auditor and requires the auditor to report findings relevant to the contract only.

Findings, remediation and the disputed audit

The clause should say what happens with the findings: a written report, a right for the audited party to comment, a remediation plan with timescales, and, for a charges audit, an adjustment of overcharges with interest under the Late Payment of Commercial Debts (Interest) Act 1998 and a threshold above which the audited party pays the audit cost. The review checks that findings are not conclusive without a dispute procedure, that a remediation obligation is proportionate to the finding, and that an audit does not become a termination event without a material breach.

Access to systems, security and the auditor's own obligations

An audit of systems gives the auditor access to the audited party's networks and data, and the clause should require the auditor to comply with the audited party's security policies, to use only agreed tools, and not to test systems without written authority, since unauthorised access is an offence under section 1 of the Computer Misuse Act 1990. Where the audited party is a processor, the auditor's access to personal data must itself be lawful, and the review checks that the clause addresses it.

What it costs

Standard review, £495. Marked-up document and a written explanation of the changes. Three working days.

Buying online forms the engagement on payment. The scope is what the contract review page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • Your own contract returned with my amendments as tracked changes, plus a clean version with every change accepted, ready to send to the other side
  • Comments in the document where a point needs explaining
  • A written explanation of what I have changed and why, by email or as an attachment if it is lengthy, marking the points I would hold firm on and the ones that are negotiable
  • A view on what is normal market practice and what is the other side pushing their luck
  • One round of follow-up questions by email, included

What is not included

  • Negotiating directly with the other side, which I quote separately once I know who is on the other side. Where the other side is willing to share a live document, I can work in that document directly
  • Drafting a replacement contract from scratch
  • Advice on the law of any jurisdiction other than England and Wales
  • Tax, accounting or regulatory advice
  • Disputes about a contract that is already signed

Questions I am often asked

Our customer wants to audit us at any time without notice. Is that normal?

It is in customers' first drafts, and it is not what suppliers accept. The review asks for reasonable notice, working hours, once a year unless a breach is found, reliance on existing reports first, and the customer bearing the cost unless a material breach is found.

Can we refuse an audit by our controller?

Not one required by Article 28 of the UK GDPR, which obliges you to allow for and contribute to audits of your processing. You can insist that it is on notice, conducted by a qualified auditor under confidentiality, and limited to the processing for that controller. The review drafts those limits.

The audit found an overcharge. Who pays for the audit?

Whatever the clause says, and customers draft it so that the supplier pays if any overcharge is found. The review asks for a threshold, a percentage of the charges audited, above which the supplier pays and below which the customer does, with the overcharge repaid with interest.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.