A Master Services Agreement (MSA) is the umbrella contract that governs an entire client relationship: payment terms, ownership of the work product, allocation of risk if performance fails, and how the relationship ends. A Statement of Work (SOW) is a shorter, engagement-specific document describing one piece of work under that umbrella: scope, deliverables, price, dates, and who signs off. The MSA is negotiated once and left in place, and a new SOW is drafted for each engagement without reopening the legal terms. Where more than one engagement with a client is plausible, the split is built from the outset.
Consultants and advisory firms scoping a compliance engagement, a BSA/AML program build, a gap analysis, a risk assessment, an audit-support retainer, run into this question the first time a prospective client sends over paperwork, or the first time the firm has to explain what its own contract looks like. SOW and MSA get used almost interchangeably in casual conversation, and the confusion has a real cost. A firm that skips the MSA and writes every engagement as a standalone contract renegotiates liability and IP terms from scratch each time. A firm that writes a thin SOW with no acceptance mechanic exposes itself to a dispute over whether the deliverable was completed, which is a harder question to resolve than a dispute over price.
The short distinction
An MSA governs the relationship. An SOW governs the work. If a term should hold true across every engagement a firm runs with a given client, payment terms, who owns what gets built, what a breach costs, how either side exits, it belongs in the MSA. If a term is true of only this engagement, what's being delivered, by when, for how much, signed off by whom, it belongs in the SOW. An SOW is not a standalone contract in a multi-engagement relationship. It is incorporated into, and inherits every standing term from, the MSA it references.
What a Master Services Agreement covers
The MSA is negotiated once, typically by counsel or firm leadership, and then left alone for the life of the relationship. It carries the standing commercial and legal terms every future engagement will inherit without re-litigating them.
| Clause | What it sets |
|---|---|
| Services / SOW incorporation | How future SOWs attach to the agreement, and which document controls if they conflict. |
| Payment and invoicing | Invoicing cadence, payment terms, a dispute window, late-payment interest. |
| IP / work-product ownership | Who owns what gets created: the client, the consultant, or a hybrid split between deliverables and background methodology. |
| Confidentiality | Mutual protection obligations, standard carve-outs, a return-or-destroy obligation at termination. |
| Indemnification | Which third-party claims each side covers, tied to the actual risk of the services being performed. |
| Warranty and liability cap | A performance warranty, a cure period, and a dollar- or fee-based cap on damages. |
| Insurance | Coverage limits matched to the liability cap, so the cap is actually collectible. |
| Term, termination, survival | How long the relationship runs, how either side exits, and which obligations outlive termination. |
What a Statement of Work covers
The SOW is the document delivery staff draft for every new engagement, quickly, without reopening the legal terms above. A well-formed SOW names the MSA it's issued under in its first paragraph, and states nothing that conflicts with that agreement unless it names the specific section it's overriding.
| Section | What it names |
|---|---|
| Order of precedence | The parent MSA the SOW is issued under, and which document controls if the two conflict. |
| Background and scope | Why the work exists, and, explicitly, what's out of scope. |
| Specific requirements | The obligations the consultant is contracted to deliver, usually stated one per line so each is independently verifiable. |
| Key personnel | Named or role-based staff, seniority, and how long they're committed to the engagement. |
| Deliverables and acceptance | What gets delivered, by when, who approves it, how long they have, and what a rejection triggers. |
| Charges | The pricing model, fixed fee, time-and-materials with a not-to-exceed cap, or milestone-retainage, and the actual numbers. |
| Change management | What happens when scope drifts, and who has to sign before the drift becomes billable. |
How the two documents relate
Every SOW names the MSA it's issued under and states, in its opening paragraph, that it's subject to that agreement's terms. What happens when the two documents disagree is a drafting choice, not an accident, and firms land on one of two conventions.
| Convention | How it works | Risk |
|---|---|---|
| MSA controls (recommended default) | The MSA wins in a conflict unless the SOW expressly names the section of the MSA it's overriding. | Low. Legal terms stay stable across every engagement unless a deliberate, named override is negotiated. |
| SOW controls for its own scope | Whatever the SOW says wins for that engagement, with no override flag required. | High. A rushed or unreviewed SOW, drafted by delivery staff rather than counsel, can quietly change a liability cap or IP clause without anyone noticing the deviation. |
Most firms should default to MSA-controls with a named-override escape hatch. It preserves the operational benefit of the split, a SOW that doesn't require legal review before every signature, without the risk that a scope document silently rewrites risk allocation.
When the split is warranted
The split earns its keep the moment a second engagement becomes plausible. For a genuine, one-time-only engagement, a single standalone consulting agreement that merges MSA-level and SOW-level content into one document is simpler and appropriate. Retrofitting an MSA+SOW split later means renegotiating terms that are already locked into an executed document, which is harder than building the split from day one.
- Build the split if: more than one engagement is plausible, even if only one is signed today.
- Build the split if: the client relationship is expected to run more than a few months.
- Build the split if: the legal terms will be negotiated by a different person than the one drafting delivery scope.
- Build the split if: the engagement could expand into follow-on work, a risk assessment that leads to a remediation build, a gap analysis that leads to policy authoring.
- A single merged agreement is fine if: the relationship is genuinely one-and-done, and no one on either side expects a second statement of work.
Where consulting engagements get this wrong
- No acceptance mechanic. A deliverables table with no named approver, no stated review window, and no stated consequence of silence leaves completion undefined and unenforceable.
- Uncapped time-and-materials. A T&M SOW with no not-to-exceed figure leaves the client's total obligation unbounded.
- SOW language that quietly overrides the MSA. A liability cap or IP clause rewritten inside a scope document, without naming the MSA section it overrides, creates a conflict nobody notices until it matters.
- No explicit out-of-scope statement. A single sentence — "anything not addressed in this SOW is out of scope" — routes an added request through the change-order mechanism rather than into a scope dispute.
- Treating the SOW as a standalone contract. An SOW that does not reference its parent MSA, or references it loosely, leaves open which document's confidentiality, IP, or liability terms apply.
What this looks like in a compliance engagement
A compliance-consulting SOW's Deliverables table is where the engagement's actual scope gets named in contract language. A BSA/AML program build might name a risk assessment, a gap analysis, and an independent-testing report as three separate line items, each with its own review window and approver. See the guides to BSA/AML risk assessment, AML program gap analysis, and BSA/AML independent testing for what each deliverable actually has to cover to hold up under exam. An engagement scoped for a fintech operating under a bank charter should also account for how sponsor-bank oversight allocates responsibility between the parties, since that allocation often shapes who the SOW names as the approver for each deliverable.
Practical guidance
The MSA is built once, with counsel, and treated as settled. A fresh SOW is drafted for each engagement, referencing the MSA by section number where relevant, without reopening legal negotiation. Where SOWs repeatedly require legal review of terms the MSA was meant to settle, the MSA under-specified those terms, and the correction belongs in the MSA rather than in each successive SOW.
Primary sources
- Federal Acquisition Regulation (FAR), Part 37: Service Contracting, including the performance-based acquisition subpart that defines and structures statements of work, performance work statements, and statements of objectives in U.S. federal contracting.
- U.S. Department of Homeland Security, Science and Technology Directorate: Information Assurance Compliance Support Services Statement of Work (RFQ 70RSAT22Q00000040, Attachment I, 2022), a public federal-procurement record illustrating numbered requirements, key-personnel, and deliverables-acceptance structure.
- NATO Support and Procurement Agency (NSPA): Statement of Work for SAP S/4HANA Consultancy Services (2021, NATO UNCLASSIFIED), a framework outline-agreement SOW illustrating staffing-profile and work-package structure.
- Commonwealth of Virginia, Virginia Information Technologies Agency (VITA): Statement of Work Template, Attachment A to the VITA Master Services Agreement, a public-sector procurement template illustrating deliverables, milestone, and SLA-credit structure.
- University of Cincinnati: Master Service Agreement and CampusConnect Statement of Work No. 1 with Deloitte Consulting LLP (2020, public-institution procurement record), a real executed MSA-and-SOW pair illustrating the incorporation and precedence mechanism this guide describes.
- World Commerce & Contracting (formerly IACCM): a professional standards body for contract and commercial management, publishing widely used benchmarking on MSA and SOW risk allocation and negotiation practice.