Service Level Agreement Review Scorecard: Outcomes, Evidence, Remedies and Escalation
A service level agreement should help two parties operate a service, not merely decorate a contract. Weak SLAs use impressive percentages without defining the user outcome, measurement source, exceptions or response when performance fails.
The SERVICE-9 scorecard below turns an SLA review into a repeatable 100-point decision tool.
The SERVICE-9 scorecard
| Dimension | Review question | Points |
|---|---|---|
| S — Service outcome | Is the user or business outcome unambiguous? | 15 |
| E — Exact metric | Is the formula, numerator, denominator and unit defined? | 15 |
| R — Record of truth | Is the authoritative measurement source named and auditable? | 15 |
| V — Variance band | Are target, tolerance and breach thresholds clear? | 10 |
| I — Inspection cadence | Are reporting and review frequency specified? | 10 |
| C — Consequence | Are remedies proportionate and operationally useful? | 10 |
| E — Escalation | Are severity, owner and time-to-escalate defined? | 10 |
| D — Dependencies | Are customer duties, exclusions and force-majeure boundaries explicit? | 10 |
| E — Evolution and exit | Can the measure change, and can data/service be transferred at exit? | 5 |
Score only what the document and operating process support. A polished promise with no reliable measurement source earns zero for Record of truth.
Decision bands:
- 85–100: operationally reviewable; confirm legal and technical fit.
- 70–84: usable with named remediation actions.
- 50–69: material ambiguity; renegotiate before relying on it.
- Below 50: the SLA is unlikely to guide performance or dispute resolution.
No total score overrides a fatal issue such as an undefined security incident, missing data-return obligation or legally unsuitable remedy.
A copyable SLA record
Use one record per service level:
| Field | Entry |
|---|---|
| Service outcome | |
| Metric name and formula | |
| Measurement window and timezone | |
| System of record | |
| Target / tolerance / breach | |
| Exclusions and customer dependencies | |
| Reporting frequency | |
| Review meeting and owner | |
| Remedy or service credit | |
| Escalation path and times | |
| Change-control rule | |
| Exit evidence and data handover |
This is an operational template, not legal advice. Counsel should review enforceability, liability, regulatory and jurisdiction-specific terms.
Worked example: cloud availability
“99.9% uptime” is incomplete. A stronger record might define:
- Service outcome: authenticated users can submit and retrieve a transaction.
- Formula:
(total eligible minutes − unavailable eligible minutes) ÷ total eligible minutes × 100. - Window: calendar month, UTC.
- System of record: named synthetic monitor plus incident log reconciliation.
- Target: 99.9%; tolerance: none below target; severe breach below 99.5%.
- Exclusions: announced maintenance only when notice and maximum duration conditions are met.
- Review: monthly report within five business days.
- Consequence: service credit plus corrective-action plan after repeated breach.
- Escalation: severe incident to named operational and executive owners within defined times.
For a 30-day month, 99.9% availability permits approximately:
30 × 24 × 60 × (1 − 0.999) = 43.2 minutes
That calculation is useful only if the contract defines which minutes are eligible. Broad exclusions can make the nominal percentage meaningless.
Review outcomes before remedies
Service credits can create accountability, but they rarely compensate for major business interruption. Review three layers:
- Prevention: capacity, resilience, access and change controls.
- Detection and recovery: monitoring, incident classification, communication and restoration.
- Commercial consequence: credit, corrective-action plan, termination threshold or other remedy.
The UK Government’s Contract Management Professional Standards provide a useful public-sector reference for disciplined contract management. NIST’s Cloud Computing Synopsis and Recommendations also emphasizes that cloud opportunities come with risks and responsibilities that customers must understand.
Common failure patterns
Metric without an outcome
A provider can meet ticket-response time while users remain unable to complete the task. Pair operational measures with the outcome they support.
Provider-only evidence
If the provider owns the only measurement source, define audit rights, raw-event retention or reconciliation with customer evidence.
Remedy without recovery
A credit formula does not restore service. Require an incident report and corrective-action process for material or repeated breaches.
Exclusions that consume the promise
List exclusions narrowly. Review whether planned maintenance, third parties, customer configuration or force majeure can remove most of the measurement window.
No evolution rule
A measure can become obsolete as architecture or volume changes. Define who can propose a change, evidence required, approval and effective date.
A 45-minute review workflow
- Map each SLA to a user or business outcome.
- Recalculate one example from the stated formula.
- Identify the system of record and evidence-retention period.
- Simulate one ordinary breach and one severe incident.
- Trace owner, escalation, remedy and corrective action.
- Review dependencies, exclusions, change and exit.
- Score SERVICE-9 and assign an owner and due date to every gap.
Deepen the capability
Professionals who want structured practice in contract lifecycle, performance, risk and supplier governance can explore MTF Institute’s Commercial Contract Manager programme. The scorecard is a practical review aid; course study can deepen the broader commercial and governance judgment around it.