Throughout this series, we have examined how indemnification clauses work, the problems that ambiguous language creates, the interpretive rules courts apply, and the specific issues that arise in IP indemnification, government contracting, and other specialized contexts. This final article in the indemnification series brings those lessons together into practical guidance for drafting or reviewing indemnification provisions that will accomplish their intended purpose and hold up if they are ever tested in a dispute or in court.
Good indemnification drafting is not about using the most expansive language you can find or protecting your business from every conceivable risk at the other party’s expense. It is about creating a clear, fair, and enforceable allocation of specific risks that both parties understand. Indemnification provisions that are overreaching, internally inconsistent, or so broad as to be unconscionable can be voided, narrowed, or refused enforcement by courts, producing a result worse than a well-drafted provision would have. The goal is language that works.
This article provides a practical framework for the structure, content, and specific language choices that produce effective indemnification provisions, along with the common drafting errors to avoid.
Start With Purpose: What Is This Provision Trying to Do?
Before drafting or evaluating an indemnification clause, articulate what specific risks it is intended to address. This sounds obvious but is frequently skipped in practice. Generic indemnification provisions borrowed from templates often address risks that are not relevant to the specific transaction while failing to address risks that actually matter. Tailoring indemnification provisions to the actual risk profile of the relationship produces more effective protection.
Consider the categories of third-party claims that are realistic in the context of this contract. If the vendor handles personal data, data breach claims by affected individuals are a real risk. If the vendor performs work at your physical locations, bodily injury and property damage claims are relevant. If the vendor provides software that might infringe someone else’s IP, IP indemnification is essential. If the vendor provides professional advice, professional liability claims are the concern. Matching the indemnification structure to the actual risk profile ensures the provisions you negotiate have practical value.
Also consider which party is more appropriately positioned to bear each type of risk. Risk should generally be allocated to the party best able to prevent, manage, and insure against it. If the vendor is the one who handles data, manages the platform, and controls security practices, the vendor is the party best positioned to prevent and manage data breach risk, and the indemnification structure should reflect that. If the customer controls how the product is used, deploys it in unusual configurations, or provides the data that creates risk, some of that risk logically sits with the customer.
Structural Elements of an Effective Indemnification Provision
A well-drafted indemnification provision has several structural components that work together. The opening clause should identify the indemnitor, the indemnitee, and the nature of the obligation. Using defend, indemnify, and hold harmless language covers the full spectrum of protection: the duty to defend covers litigation costs as incurred; indemnification covers final judgments and settlements; hold harmless covers keeping the indemnitee whole from loss. If you intend to include all three, use all three terms.
The scope clause should specifically identify the triggering events that activate the obligation. Common triggering events include breach of the indemnitor’s representations, warranties, or covenants; the indemnitor’s negligence; the indemnitor’s intentional misconduct; specified categories of claims such as IP infringement or data breaches; or any combination of these. Specify the triggering events affirmatively rather than relying on broad catch-all language. The more specifically you can identify what triggers the obligation, the less room courts have to narrow it through interpretive canons.
The covered losses clause should enumerate the categories of losses that are within the indemnification. Common categories include damages, judgments, settlements, regulatory fines and penalties, costs of investigation and remediation, attorney’s fees, expert witness fees, and court costs. If certain categories are intentionally excluded, say so explicitly. If the indemnification covers both third-party claims and direct losses, the provision should say so explicitly. If consequential damages are included, include them by name.
The carve-outs clause should list the specific circumstances in which the indemnification does not apply. Draft carve-outs with causation standards that reflect their intended scope. If you intend that a carve-out applies only when the indemnitee’s conduct was the sole cause of the loss, use solely caused by language. If the carve-out is intended to apply when the indemnitee’s conduct was a contributing cause, use that language. Be specific about what conduct qualifies for each carve-out, and consider whether the carve-outs in the indemnitee’s obligation mirror the carve-outs in the indemnitor’s obligation.
Language Precision: Words That Matter
The choice between any and solely or primarily reflects a significant difference in the causation standard being established. Any claims arising from the indemnitor’s conduct can be read to include claims where the indemnitor’s conduct was a minor or incidental contributing factor among many. Claims primarily or solely caused by the indemnitor’s conduct requires a more direct causal connection. Depending on the typical fact patterns in your industry, one or the other standard may be more appropriate.
Third-party claims language specifically limits the indemnification to claims brought by parties outside the contractual relationship. If you intend the indemnification to cover only third-party claims and not the parties’ own direct losses, include third-party claims language. If you intend to cover direct losses as well, omit this limitation or include specific language addressing both categories. Leaving this ambiguous is one of the most common drafting failures in indemnification provisions.
Including or which the indemnitor controls or which the indemnitor could have prevented language can be useful in carve-outs for the indemnitee’s conduct. This prevents the carve-out from being applied in situations where the indemnitee arguably could have done something differently but the primary cause of the loss was the indemnitor’s conduct. It is a nuanced addition that may be worth the extra language in high-stakes agreements.
Promptly, reasonable, and similar flexible standards should be defined whenever possible. A cure period that must be completed within a reasonable time invites dispute about what is reasonable. A notice requirement to be provided promptly invites dispute about whether forty-eight hours or forty-five days constitutes prompt notice. Wherever the parties have a common understanding of what these flexible terms mean, encoding that understanding in a specific definition or timeframe reduces future uncertainty.
Procedural Provisions That Support Enforceability
A complete indemnification provision includes not just the substantive obligation but the procedural framework for invoking it. The notice provision should specify the form of notice required, the time within which notice must be provided, and the specific information the notice must contain. If the indemnitor must receive specific information before its duty to defend is triggered, the indemnitee needs to know what to provide. Vague notice provisions generate disputes about whether adequate notice was given.
The control of defense provision should address who controls the defense, under what circumstances the indemnitee may retain separate counsel at the indemnitor’s expense, and what consent rights each party has with respect to settlement. As discussed elsewhere in this series, the indemnitee should always have a consent right with respect to settlements that impose obligations on it, include admissions of liability, or fail to include a full release. The indemnitor’s control right should not extend to making litigation decisions that affect the indemnitee’s interests without the indemnitee’s input.
The cooperation provision should specify what the indemnitee must do to support the defense, including providing documents, making witnesses available, and not taking actions that would prejudice the defense. Cooperation obligations that are burdensome, undefined, or unlimited in scope can create problems; cooperation obligations that are specific and proportionate to the complexity of the underlying claim are reasonable and appropriate.
Survival language should explicitly state that the indemnification obligations survive termination or expiration of the agreement, and for what period. Absent a survival provision, there is some risk that a court will conclude the indemnification no longer applies after the contract ends, even for claims arising from events that occurred during the contract term. Specify whether indemnification obligations survive indefinitely or for a defined period following termination.
The Intersection With Limitation of Liability Provisions
One of the most important drafting decisions in any indemnification provision is how it relates to the contract’s limitation of liability clause. If the agreement contains a cap on total liability, the parties need to decide whether the indemnification obligation is subject to that cap, excluded from the cap, or subject to a separate higher cap. Many sophisticated commercial agreements carve IP indemnification and data breach indemnification out of the general liability cap, recognizing that claims in those categories can easily exceed a fee-based cap in significant cases.
The limitation of liability clause may also exclude consequential damages from the indemnitor’s liability. If the indemnification provision covers consequential damages as a type of covered loss, but the limitation of liability clause excludes consequential damages, the interaction between the two provisions is ambiguous. One provision appears to include consequential damages; another appears to exclude them. Courts will attempt to harmonize such provisions, but may not succeed in a way that reflects the parties’ intent. The safer approach is to address this interaction explicitly, either by carving the indemnification out of the consequential damages waiver or by confirming that the waiver applies to indemnification as well.
A well-drafted commercial contract treats the indemnification provisions and the limitation of liability provisions as part of a single, coherent risk allocation structure, rather than separate provisions drafted by different people with different objectives. Reading these provisions together and ensuring they produce a consistent and intended overall risk allocation is a hallmark of quality commercial contract drafting.
Working With Counsel and Maintaining Your Own Standards
Developing a standard indemnification provision for contracts you regularly use, reviewed and approved by legal counsel familiar with your industry and the state law governing your contracts, is a valuable investment. Having a clear baseline position on indemnification terms, including the specific language you will accept and the specific modifications you will insist on in vendor-drafted agreements, allows you to process contracts more efficiently and reduces the risk that unfavorable terms slip through in busy periods.
Contracts worth significant investment in terms of revenue, data exposure, or operational dependency deserve careful attorney review of the indemnification provisions before signing. General practitioners may miss the nuances of technology contract indemnification; generalist corporate attorneys may not understand the specific regulatory indemnification implications in healthcare or financial services. Matching the reviewing attorney’s expertise to the specific risk profile of the contract produces better outcomes.
Finally, remember that indemnification clauses are only one element of a complete risk management strategy. Insurance coverage, carefully negotiated liability caps, robust warranty provisions, service level agreements with meaningful remedies, and thorough vendor due diligence all contribute to the overall protection of your business in commercial relationships. Indemnification provisions that work as intended are a critical piece of that protection, but they function best as part of a coherent whole rather than as a standalone safeguard.
