Scope of Services
Describe tasks, deliverables, timelines, and any conditions that trigger additional work. Be explicit about what the third party may and may not do regarding customer accounts and records.
A documented agreement limits ambiguity, allocates liability, and sets data access and confidentiality rules for sensitive account work. It creates a contractual basis for fee recovery, audit trails, and remediation steps, which supports regulatory compliance and internal controls.
Common users include bank operations, in-house counsel, outsourced legal service providers, and compliance teams responsible for account remediation and vendor oversight.
Use the agreement whenever third parties act on behalf of accounts or access nonpublic customer data to prevent regulatory and operational problems.
Typically signs for operational acceptance and confirms vendor onboarding requirements have been met. Responsible for enforcing access controls, verifying insurance or bonding, and coordinating audits or sampling of vendor work to ensure contractual compliance.
Signs for legal approval and risk acceptance. Reviews indemnity, limitation of liability, governing law, and confidentiality language; advises on notarization, witness requirements, and whether consumer disclosure or special consent is required under applicable law.
Describe tasks, deliverables, timelines, and any conditions that trigger additional work. Be explicit about what the third party may and may not do regarding customer accounts and records.
Specify who may act on behalf of each party, whether authority is exclusive or limited, and any required internal approvals before the contractor may commence specific actions.
Define protected data, permitted uses, data transfer restrictions, breach notification timelines, and encryption or access-control expectations to meet bank data policies.
Allocate risk, state liability caps if any, and describe responsibilities for third-party claims, defense obligations, and insurance requirements to support loss recovery.
State fixed fees, hourly rates, billing cycles, invoicing requirements, dispute resolution for charges, and any late payment remedies or offsets.
Require retention, audit access, and secure delivery of records. Specify retention periods and whether audit logs, transaction histories, or A/V files must be retained for regulatory review.
| Field | Configuration |
|---|---|
| Signer Authentication | Use email plus SMS code or ID verification for high-risk signers. |
| Conditional Fields | Show specific fields only when third-party services are selected. |
| Audit Trail | Enable timestamps, IP logging, and signer events. |
| Storage | Store encrypted signed copies in a secure archive. |
Ensure the eSignature platform supports required authentication, encryption, and enterprise integrations before routing the agreement.
Confirm the platform retains a tamper-evident audit trail and supports encryption (TLS and AES-256) and any industry addenda such as HIPAA BAAs where required.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No envelope cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |
No fixed deadline; furnish taxpayer identification to payers when requested.
Jan 31 — to recipient and IRS for nonemployee compensation.
Jan 31 to recipient; Feb 28 paper IRS, Mar 31 electronic IRS for other payments.
April 15 — Form 1040 due (Oct 15 with approved extension).
April 15 — auto-extension to Oct 15 for FBAR filings.