Regulated Customer Contract Checker
Every country ยท North America

United States

Outside the EEA. A customer here pulls on the regimes below by its sector; the rest are named and not quoted.

By customer sector

read on a SaaS subscription that names personal data
A bankISO 27001, ISO 27701expected on a SaaS subscription with personal data: security schedule, audit right, breach clock
An insurerISO 27001, ISO 27701expected on a SaaS subscription with personal data: security schedule, audit right, breach clock
A hospital or health systemHIPAA, ISO 27001, ISO 27701expected on a SaaS subscription with personal data: BAA, security schedule, audit right, breach clock
A retailerISO 27001, ISO 27701expected on a SaaS subscription with personal data: security schedule, audit right, breach clock
A government departmentISO 27001, ISO 27701expected on a SaaS subscription with personal data: security schedule, audit right, breach clock
A technology companyISO 27001, ISO 27701expected on a SaaS subscription with personal data: security schedule, audit right, breach clock
Named, not quotedthe US state breach notification laws.

Codes the register reads for this country: US, United States, usa, u s a, u s, united states of america, america, new york, chicago, houston.

The clauses, quoted

21

Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.

HIPAA 164.308(a)(6)(ii) Response and Reporting (Required)

Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.

Evidence an auditor accepts: Incident ticket log; Post-incident reports; Breach risk assessments per 164.402
Where it usually falls short: Incident closure without root cause
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

A covered entity may permit a business associate to handle ePHI only after obtaining satisfactory assurances via written contract. NIST recommends due diligence, security questionnaires, and ongoing monitoring of BAs.

Evidence an auditor accepts: BA inventory; Executed BAAs; Vendor risk assessments
Where it usually falls short: BA inventory incomplete
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.308(b)(2) Subcontractor Arrangements

A business associate may permit a business associate that is a subcontractor to create, receive, maintain, or transmit electronic protected health information on its behalf only if the business associate obtains satisfactory assurances, in accordance with 164.314(a), that the subcontractor will appropriately safeguard the information.

Evidence an auditor accepts: Inventory of subcontractors that create, receive, maintain or transmit electronic protected health information on the business associate's behalf; Executed written agreements with each subcontractor containing the satisfactory assurances required; Evidence the assurances obtained are equivalent to those the business associate provided to the covered entity
Where it usually falls short: Assurances obtained from the immediate subcontractor while its own downstream subcontractors handling the same data are unaddressed
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.308(b)(3) Written Contract or Other Arrangement

Document the satisfactory assurances required by paragraph (b)(1) of this section through a written contract or other arrangement with the business associate that meets the applicable requirements of 164.314(a).

Evidence an auditor accepts: Standard BAA template aligned to 164.314(a); Executed BAAs stored in contract repository; Alternative arrangement documentation where BA is a government entity
Where it usually falls short: BAAs missing required Security Rule clauses
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.314(a)(1) Business Associate Contracts or Other Arrangements (Standard)

The contract or other arrangement required by 164.308(b)(3) must meet the requirements of paragraph (a)(2)(i), (a)(2)(ii), or (a)(2)(iii) of this section, as applicable.

Evidence an auditor accepts: BAA template addressing all required 164.314(a)(2) elements; Government arrangement documentation where applicable; Special arrangement records (group health plan, plan sponsor)
Where it usually falls short: Older BAAs missing post-Omnibus requirements
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.314(a)(2)(i) Business Associate Contract Required Provisions

The contract between a covered entity and a business associate must provide that the business associate will comply with the applicable Security Rule requirements, ensure subcontractors comply, report security incidents including breaches, and authorize termination by the covered entity if the business associate violates a material term.

Evidence an auditor accepts: BAA template with required clauses traceable to 164.314(a)(2)(i); Incident reporting requirements and SLAs; Subcontractor flow-down clause
Where it usually falls short: Incident reporting SLA missing or longer than reasonable
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.314(a)(2)(iii) Business Associate Contracts with Subcontractors

The requirements of paragraph (a)(2)(i) of this section apply to the contract or other arrangement between a business associate and a subcontractor required by 164.308(b)(4) in the same manner as such requirements apply to contracts or other arrangements between a covered entity and business associate.

Evidence an auditor accepts: Subcontractor BAA template aligned to 164.314(a)(2)(i); Executed subcontractor BAAs; Subcontractor inventory with ePHI scope
Where it usually falls short: Subcontractor inventory incomplete
HIPAA Security Rule in The Art of Service standards library
ISO 27001 A.5.19 Information security in supplier relationships

Define and apply processes to manage the security risk suppliers introduce.

Evidence an auditor accepts: Supplier risk assessment; Contractual security requirements; Supplier security monitoring
Where it usually falls short: Treating all suppliers as low risk
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.20 Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

Evidence an auditor accepts: Contract security clauses; Supplier risk assessment; Security incident reporting
Where it usually falls short: missing explicit security clauses
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.21 Managing information security in the ICT supply chain

Extend security requirements down the ICT products and services supply chain.

Evidence an auditor accepts: Supplier security requirements; Contractual security clauses; Supply chain risk assessments
Where it usually falls short: Treating supplier security as one-off check
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.23 Information security for use of cloud services

Govern acquisition, use, management and exit of cloud services against your security requirements.

Evidence an auditor accepts: Cloud service selection; Cloud contract management; Cloud security monitoring
Where it usually falls short: Relying solely on provider's security assurances
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.24 Information security incident management planning and preparation

Define incident roles, processes and readiness before an incident happens.

Evidence an auditor accepts: Incident response plan; Role assignment matrix; Training and awareness records
Where it usually falls short: roles are defined but not formally assigned or approved
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.31 Legal, statutory, regulatory and contractual requirements

Identify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.

Evidence an auditor accepts: Legal register; Contractual obligations; Regulatory filing records
Where it usually falls short: outdated legal register
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.34 Privacy and protection of personal identifiable information (PII)

Identify and meet privacy and PII-protection requirements from law, regulation and contract.

Evidence an auditor accepts: Privacy policy; Data inventory; Processing agreements
Where it usually falls short: Missing documented consent for all data subjects
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27701 A.2.2.2 Customer agreement

Where relevant, the contract to process personal data must address the organization's role in assisting the customer with the customer's own obligations, taking account of the nature of processing and the information available to it, covering as relevant privacy by design and by default, achieving security of processing, notifying breaches to a supervisory authority and to cust...

Evidence an auditor accepts: Customer contracts carrying the assistance provisions relevant to the engagement; Where the jurisdiction requires it, contract terms stating subject matter, duration, nature, purpose, data types and categories of individuals; Operational capability behind each assistance commitment, not the commitment alone
Where it usually falls short: Assistance promised in contract with no operational capability behind it, discovered only when the customer first asks
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.4.3 Return, transfer or disposal of PII

The organization must provide the ability to return, transfer or dispose of personal data securely and must make its policy available to the customer, managing the capability securely whether the outcome is return to the customer, transfer to another organization or controller, deletion, destruction, de-identification or archiving, providing the assurance the customer needs tha...

Evidence an auditor accepts: Documented return, transfer and disposal policy, made available to customers; Assurance evidence that erasure reaches backups, continuity copies and subcontractors; Stated post termination retention period before disposal, with its rationale
Where it usually falls short: Erasure certified for primary systems while backups retain the data for the full backup cycle, which the customer is not told
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.7 Disclosure of subcontractors used to process PII

The organization must disclose to the customer any use of subcontractors to process personal data before that use, with provisions included in the customer contract, disclosing that subcontracting is used and the names of the relevant subcontractors, the countries and international organizations to which they can transfer data, and the means by which they are obliged to meet or...

Evidence an auditor accepts: Current subcontractor list with names, the countries they can transfer to, and how their obligations are secured; Evidence of disclosure before use, not after; Contract provisions covering subcontractor disclosure
Where it usually falls short: Subcontractors disclosed only on request, with customers never told the information exists
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.8 Engagement of a subcontractor to process PII

The organization must engage a subcontractor to process personal data only according to the customer contract, obtaining written authorization from the customer before the subcontractor processes the data, whether through appropriate clauses in the customer contract or a specific one off agreement, holding a written contract with every such subcontractor that addresses implemen...

Evidence an auditor accepts: Written customer authorization for each subcontractor, whether general or specific; Written contract with every subcontractor carrying the processor control obligations; Justification for any processor control not required of a subcontractor
Where it usually falls short: Subcontractor engaged on the strength of a general authorization that does not in fact cover it
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.9 Change of subcontractor to process PII

Where it holds a general written authorization, the organization must inform the customer of any intended change involving the addition or replacement of a subcontractor that processes personal data, giving the customer the opportunity to object, and where it changes the subcontractor carrying out some or all of the processing, written authorization from the customer is require...

Evidence an auditor accepts: Change notification procedure with the notice period and the objection route; Records of notifications given and objections received, with outcomes; Evidence that new subcontractors did not begin processing before authorization
Where it usually falls short: Notification given at the point of change or after, so the objection right is theoretical
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.3.10 Addressing information security within supplier agreements

Agreements with suppliers shall specify whether PII is processed and the minimum technical and organizational measures the supplier must meet for the organization to meet its information security and PII protection obligations, shall clearly allocate responsibilities between the organization, its partners, suppliers and applicable third parties taking account of the type of PII...

Evidence an auditor accepts: Supplier agreements stating whether PII is processed and the minimum measures required; Responsibility allocation clauses by type of PII; Audit or assurance clause and the independent evidence obtained under it
Where it usually falls short: Supplier contracts silent on PII while the supplier processes it
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.3.12 Response to information security incidents

For a PII controller, an incident that involves PII shall trigger a review to determine whether a breach involving PII requiring a response has occurred, an event alone not necessarily triggering it; when a breach has occurred the response shall include the relevant notifications and records, jurisdictions defining when the supervisory authority and PII principals must be notif...

Evidence an auditor accepts: Breach determination records for incidents involving PII; Breach register carrying every field the standard names; Notifications made to authorities, PII principals or customers with timing against the legal limit
Where it usually falls short: Incidents closed as security events with no PII breach determination
ISO/IEC 27701:2025 in The Art of Service standards library

Read your customers in United States

Paste the list; every agreement with a customer here is read against these regimes by its sector and its kind. Eight agreements free, no account.

Check my contract list