Contract anatomy: where the risk lives and how to move it

A commercial contract is a machine for deciding who pays when things go wrong — and a few clauses do all the deciding.

The idea

Most clauses describe the deal. A small number allocate the risk in it, and those are the load-bearing ones: reps & warranties, indemnities, and the limitation of liability (the cap, its carve-outs, and the consequential-damages waiver). When a loss lands, these clauses — working together — decide the dollar split between the parties.

The senior instinct is not “make it symmetric.” It’s match the risk to the exposure. The side that can actually cause a catastrophic loss, or actually suffer one, should carry that specific risk — regardless of whether the paragraph looks even-handed.

The skeleton · click a clause

Master services agreement — load-bearing clauses
Select a clause to see who it protects and which risk lever it moves.

The loss simulator · move the risk

Something goes wrong — pick the event

General liability cap
1.0× fees = $500k
Risk-shifting clauses (toggle on/off)
Read the split from…
Customer bears $0
customer bears vendor absorbs insurance absorbs
Customer bears
$0
Vendor absorbs
$0
Insurance
$0
A data breach costs $3.0M. Watch how the cap, the carve-outs, the waiver, and the insurance decide who eats it.

How it works

Four levers act in sequence on a loss. The waiver decides how much is recoverable at all; insurance takes the first bite; the indemnity shifts a category of loss to the other party; and the cap decides how much of that shift actually sticks — unless a carve-out lets it escape the cap.

Data breach  total = $3.0M   (direct $1.8M + consequential $1.2M)
annual fees = $500k        cap = 1.0x = $500k        cyber = $1.0M

1. waiver ON  -> recoverable = direct only          = $1.8M
                 (the $1.2M consequential stays with the customer)
2. insurance  -> pays min($1.0M, $1.8M)              = $1.0M
                 remaining to allocate               = $0.8M
3. indemnity  -> breach indemnity ON, carved out of the cap
                 vendor pays the full remaining      = $0.8M   (uncapped)
4. customer bears  = total - insurance - vendor
                   = $3.0M - $1.0M - $0.8M           = $1.2M

Turn the carve-out OFF -> vendor pays min($0.8M, cap $0.5M) = $0.5M,
and the customer's share jumps to $1.5M. One toggle, $300k moved.

Notice what did the damage: the consequential-damages waiver quietly handed the customer $1.2M, and the carve-out was the only thing keeping the indemnity bigger than the plain cap. Symmetry never entered the arithmetic.

When to use it

Your side / situationWhat to push for — and the trade-off
You’re the customer, exposed to the vendor’s breach or IPCarve IP + data-breach indemnities out of the cap; resist a waiver that swallows your real losses. Trade-off: the vendor prices that risk in.
You’re the vendor, one loss could exceed the deal’s valueA firm cap (a fee multiple) and a mutual consequential-damages waiver. Trade-off: too low a cap signals you won’t stand behind the product.
The exposure is asymmetric (one side holds the data / IP)Allocate that specific risk to that side even if the paragraph looks lopsided. Trade-off: harder to negotiate than a “fair” mutual clause.
An indemnity with no money behind itRequire insurance to back the big indemnities. Trade-off: adds cost and proof-of-coverage steps.

Watch out for

Worked example

An interviewer says: “You’re counsel for a company buying a SaaS platform that will hold its customer data. The vendor’s draft has a mutual liability cap of 12 months’ fees and a mutual waiver of consequential damages, with indemnities subject to the cap. What do you push on?” A strong answer maps risk to exposure: the customer, not the vendor, holds the catastrophic breach and IP exposure, so a symmetric cap under-protects the customer. Concretely — carve the data-breach and IP indemnities out of the general cap (or give them a much higher super-cap), keep the general cap for ordinary breaches, and narrow the consequential-damages waiver so it doesn’t wipe out the breach-notification and regulatory costs the customer will actually incur. Then require the vendor to carry cyber insurance sized to the carve-out. You’d note the trade — the vendor will want the general cap kept low in exchange — and accept it, because you’ve moved the right risk, not made the clause look even.

Check yourself

The vendor agrees to a broad data-breach indemnity but insists it stays “subject to the general liability cap” of $500k. For a $3M breach, what have you actually won?

Both sides accept a mutual waiver of consequential damages. Who does this clause usually help more?