Service Level Agreement Review Scorecard: Outcomes, Evidence, Remedies and Escalation

A service level agreement should help two parties operate a service, not merely decorate a contract. Weak SLAs use impressive percentages without defining the user outcome, measurement source, exceptions or response when performance fails.

The SERVICE-9 scorecard below turns an SLA review into a repeatable 100-point decision tool.

The SERVICE-9 scorecard

Dimension Review question Points
S — Service outcome Is the user or business outcome unambiguous? 15
E — Exact metric Is the formula, numerator, denominator and unit defined? 15
R — Record of truth Is the authoritative measurement source named and auditable? 15
V — Variance band Are target, tolerance and breach thresholds clear? 10
I — Inspection cadence Are reporting and review frequency specified? 10
C — Consequence Are remedies proportionate and operationally useful? 10
E — Escalation Are severity, owner and time-to-escalate defined? 10
D — Dependencies Are customer duties, exclusions and force-majeure boundaries explicit? 10
E — Evolution and exit Can the measure change, and can data/service be transferred at exit? 5

Score only what the document and operating process support. A polished promise with no reliable measurement source earns zero for Record of truth.

Decision bands:

  • 85–100: operationally reviewable; confirm legal and technical fit.
  • 70–84: usable with named remediation actions.
  • 50–69: material ambiguity; renegotiate before relying on it.
  • Below 50: the SLA is unlikely to guide performance or dispute resolution.

No total score overrides a fatal issue such as an undefined security incident, missing data-return obligation or legally unsuitable remedy.

A copyable SLA record

Use one record per service level:

Field Entry
Service outcome
Metric name and formula
Measurement window and timezone
System of record
Target / tolerance / breach
Exclusions and customer dependencies
Reporting frequency
Review meeting and owner
Remedy or service credit
Escalation path and times
Change-control rule
Exit evidence and data handover

This is an operational template, not legal advice. Counsel should review enforceability, liability, regulatory and jurisdiction-specific terms.

Worked example: cloud availability

“99.9% uptime” is incomplete. A stronger record might define:

  • Service outcome: authenticated users can submit and retrieve a transaction.
  • Formula: (total eligible minutes − unavailable eligible minutes) ÷ total eligible minutes × 100.
  • Window: calendar month, UTC.
  • System of record: named synthetic monitor plus incident log reconciliation.
  • Target: 99.9%; tolerance: none below target; severe breach below 99.5%.
  • Exclusions: announced maintenance only when notice and maximum duration conditions are met.
  • Review: monthly report within five business days.
  • Consequence: service credit plus corrective-action plan after repeated breach.
  • Escalation: severe incident to named operational and executive owners within defined times.

For a 30-day month, 99.9% availability permits approximately:

30 × 24 × 60 × (1 − 0.999) = 43.2 minutes

That calculation is useful only if the contract defines which minutes are eligible. Broad exclusions can make the nominal percentage meaningless.

Review outcomes before remedies

Service credits can create accountability, but they rarely compensate for major business interruption. Review three layers:

  1. Prevention: capacity, resilience, access and change controls.
  2. Detection and recovery: monitoring, incident classification, communication and restoration.
  3. Commercial consequence: credit, corrective-action plan, termination threshold or other remedy.

The UK Government’s Contract Management Professional Standards provide a useful public-sector reference for disciplined contract management. NIST’s Cloud Computing Synopsis and Recommendations also emphasizes that cloud opportunities come with risks and responsibilities that customers must understand.

Common failure patterns

Metric without an outcome

A provider can meet ticket-response time while users remain unable to complete the task. Pair operational measures with the outcome they support.

Provider-only evidence

If the provider owns the only measurement source, define audit rights, raw-event retention or reconciliation with customer evidence.

Remedy without recovery

A credit formula does not restore service. Require an incident report and corrective-action process for material or repeated breaches.

Exclusions that consume the promise

List exclusions narrowly. Review whether planned maintenance, third parties, customer configuration or force majeure can remove most of the measurement window.

No evolution rule

A measure can become obsolete as architecture or volume changes. Define who can propose a change, evidence required, approval and effective date.

A 45-minute review workflow

  1. Map each SLA to a user or business outcome.
  2. Recalculate one example from the stated formula.
  3. Identify the system of record and evidence-retention period.
  4. Simulate one ordinary breach and one severe incident.
  5. Trace owner, escalation, remedy and corrective action.
  6. Review dependencies, exclusions, change and exit.
  7. Score SERVICE-9 and assign an owner and due date to every gap.

Deepen the capability

Professionals who want structured practice in contract lifecycle, performance, risk and supplier governance can explore MTF Institute’s Commercial Contract Manager programme. The scorecard is a practical review aid; course study can deepen the broader commercial and governance judgment around it.

References