Establishing secure connection…Loading editor…Preparing document…

Terrorism Risk Management Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

TERRORISM RISK MANAGEMENT AGREEMENT

This Terrorism Risk Management Agreement ("Agreement") is made and entered into as of Effective Date: by and between Client Name: a/an whose principal address is , and Service Provider Name: a/an whose principal address is .

RECITALS

WHEREAS, Client operates assets, facilities or services that may be exposed to acts of terrorism or politically-motivated violence and seeks services to identify, measure and mitigate such risks; and

WHEREAS, Service Provider represents that it possesses specialized expertise in terrorism risk assessment, mitigation planning, incident response coordination and insurance placement related to terrorism risk; and

WHEREAS, the Parties desire to set forth their respective rights and obligations with respect to the provision of terrorism risk management services under the terms and conditions contained herein.

NOW, THEREFORE, in consideration of the mutual promises and covenants contained in this Agreement, the Parties agree as follows:

1. DEFINITIONS

1.1 "Assessment" means the documented analysis of Client's exposure to terrorism risk, including threat, vulnerability and consequence evaluations prepared by Service Provider. 1.2 "Mitigation Measures" means the physical, operational, administrative, insurance and other measures recommended to reduce terrorism-related loss or disruption. 1.3 "Confidential Information" means business, security, technical and other non-public information disclosed in connection with this Agreement, as further described in Section 8.

2. SCOPE OF SERVICES

Service Provider shall perform the terrorism risk management services described in the Statement of Work attached as Exhibit A and summarized below. The core services shall include risk assessment, mitigation planning, vendor coordination, insurance advisory and incident response planning.

3. RISK ASSESSMENT

Service Provider shall conduct an Assessment that identifies critical assets, plausible threat scenarios, vulnerability points and likely consequences. The Assessment shall include prioritized recommendations and an estimate of residual risk after recommended Mitigation Measures are implemented.

4. MITIGATION MEASURES AND IMPLEMENTATION

Service Provider shall recommend Mitigation Measures and, upon Client's written authorization, assist in implementation. Such assistance may include procurement oversight, coordination with security vendors, training of personnel and verification testing. Client shall make timely decisions and provide access necessary for implementation.

5. INCIDENT REPORTING AND RESPONSE

5.1 Service Provider shall provide incident response coordination in the event of an actual or suspected act of terrorism affecting Client's operations. Response services shall be provided in accordance with the incident response plan developed under this Agreement. 5.2 Service Provider shall notify Client of any material intelligence or information reasonably believed to affect Client within the timeframes agreed in the Statement of Work.

6. FEES, EXPENSES AND PAYMENT

Client shall pay Service Provider fees as set forth in the Fee Schedule attached as Exhibit B. Fees are payable in accordance with the invoicing terms; Service Provider may charge interest on overdue amounts at the lesser of 1.5% per month or the maximum permitted by law. Client shall reimburse reasonable preapproved out-of-pocket expenses.

7. INSURANCE

Service Provider shall maintain insurance coverage reasonably commensurate with the services performed, including commercial general liability, professional liability/errors and omissions and, where applicable, a policy or program covering acts of terrorism. Certificates evidencing coverage shall be provided to Client upon request.

8. CONFIDENTIALITY

Each Party shall maintain Confidential Information in strict confidence and shall not disclose such information except to employees, contractors or advisors who have a need to know and who are bound by confidentiality obligations no less protective than those herein. Confidential Information does not include information that is publicly available other than by breach of this Agreement.

9. INDEMNIFICATION

Service Provider shall indemnify, defend and hold harmless Client and its affiliates from and against third-party claims arising out of Service Provider's gross negligence or willful misconduct in performing the services. Client shall indemnify Service Provider against claims arising from Client's intentional misconduct or material breach of this Agreement.

10. LIMITATION OF LIABILITY

Except for liability resulting from fraud, willful misconduct or indemnifiable third-party claims, neither Party shall be liable to the other for consequential, incidental, punitive or special damages. The aggregate liability of each Party for any claim arising out of this Agreement shall not exceed the total fees paid to Service Provider under this Agreement in the twelve (12) months preceding the claim.

11. TERM AND TERMINATION

This Agreement shall commence on the Effective Date and continue for an initial term of unless earlier terminated in accordance with this Section. Either Party may terminate for material breach if the breach is not cured within thirty (30) days after written notice. Termination shall not relieve Client's obligation to pay fees for services rendered prior to termination.

12. AUDIT AND RECORDKEEPING

Service Provider shall maintain records relating to the performance of services for a period of at least five (5) years and shall permit Client, upon reasonable notice and during normal business hours, to audit such records to verify compliance with this Agreement, provided such audits do not unreasonably interfere with Service Provider's operations.

13. COMPLIANCE WITH LAWS

Each Party shall comply with applicable laws, rules and regulations in performing its obligations, including laws related to export controls, sanctions, anti-money laundering and data protection to the extent applicable. Service Provider shall not engage in activities that would cause Client to be in violation of applicable anti-terrorism financing or sanctions laws.

14. NOTICES

All notices required or permitted under this Agreement shall be in writing and shall be delivered by hand, nationally recognized overnight courier, certified mail (return receipt requested) or electronic delivery with confirmation to the addresses set forth below or such other address as a Party may designate by notice.

15. ASSIGNMENT AND SUBCONTRACTING

Neither Party shall assign this Agreement without the prior written consent of the other Party, which consent shall not be unreasonably withheld. Service Provider may engage subcontractors provided that Service Provider remains responsible for performance and compliance with this Agreement.

16. AMENDMENTS

This Agreement may be amended or modified only by a written instrument executed by both Parties. Any attempt to modify this Agreement by oral statements or conduct will be void.

17. WAIVER

The failure of either Party to enforce any right or provision of this Agreement shall not constitute a waiver of future enforcement of that right or provision. Waiver of any breach must be in writing to be effective.

18. GOVERNING LAW

This Agreement shall be governed by and construed in accordance with the laws of the State of without regard to choice of law principles that would apply the law of another jurisdiction.

19. ENTIRE AGREEMENT

This Agreement, together with any Exhibits and attachments expressly incorporated herein, constitutes the entire agreement between the Parties with respect to the subject matter and supersedes all prior and contemporaneous agreements, proposals, negotiations and communications, whether written or oral.

20. SEVERABILITY

If any provision of this Agreement is held to be invalid, illegal or unenforceable in any respect, the remainder of this Agreement shall remain in full force and effect and the Parties shall negotiate in good faith to replace the invalid provision with a valid provision that, to the extent possible, achieves the original economic intent.

21. COUNTERPARTS

This Agreement may be executed in counterparts, each of which shall be deemed an original, and all of which together shall constitute one and the same instrument. Signatures transmitted by electronic image or other facsimile method shall be binding.

EXHIBITS

Client:

By:

Date:

Service Provider:

By:

Date:

Enter text✕

What the Terrorism Risk Management Agreement Is and when it applies

A Terrorism Risk Management Agreement is a contract between parties that allocates responsibilities, coverage limits, reporting obligations, and mitigation measures related to acts of terrorism or politically motivated violence. It typically sits alongside property, liability, or specialty insurance provisions and defines covered perils, exclusions, and required cooperative steps after an incident. The document clarifies who bears financial risk, how losses are calculated, and what documentation is required for claims and regulatory reporting. Many organizations use it to coordinate prevention, insurance placement, and post-incident recovery responsibilities.

Why this agreement matters for organizational risk control

The agreement reduces ambiguity about coverage and obligations if a terrorism event occurs, helps streamline claims and compensation, and documents negotiated mitigation steps. Clear terms minimize disputes between insurers, reinsurers, contractors, and insured entities and support regulatory and lender reporting requirements.

Why this agreement matters for organizational risk control

Which roles commonly complete or sign this agreement

Typical signers and preparers include risk managers, insurance brokers, corporate counsel, and property or facility managers who coordinate coverage and post-incident response.

  • Insurance broker or agent: Prepares policy endorsements, negotiates limits and exclusions with carriers on behalf of the insured.
  • Corporate risk manager: Coordinates mitigations, loss prevention, and ensures policy terms match operational exposure and lender requirements.
  • Legal counsel or compliance officer: Reviews indemnity, reporting, and jurisdictional clauses to ensure enforceability and regulatory compliance.

In larger transactions, underwriters, reinsurers, or governmental contractors may also be required signers; identify authorized signers before execution.

Common authorized signers and their responsibilities

Risk Manager

The Risk Manager reviews operational exposures, confirms mitigation steps, and certifies the accuracy of exposure statements. They coordinate with insurance brokers to align policy limits and confirm required notices and timelines for claim submissions and investigations.

Underwriting Counsel

Underwriting Counsel reviews indemnities, jurisdiction clauses, and reinsurance allocation language. They ensure wording is legally enforceable, that exclusions are clear, and that any confidentiality or reporting requirements comply with corporate and regulatory obligations.

Essential compliance and security items to include

Encryption: TLS 1.2/1.3; AES-256 at rest
Audit Trail: Timestamped signing record
HIPAA Provision: BAA required for PHI
21 CFR Readiness: Controls for FDA-regulated records
Data Residency: Specify jurisdiction for records
Retention: Retention period noted

Consequences of incomplete or incorrect agreements

Contract Disputes: Delay or denial of coverage
Regulatory Fines: State or federal enforcement risk
Claim Rejection: Untimely notice may void claims
Indemnity Exposure: Uncapped liabilities possible
Reinsurance Gaps: Reinsurer denial for wording gaps
Operational Delay: Slower recovery and remediation

Common preparation mistakes to avoid

  • Vague peril definitions: failing to define 'terrorism' and related terms causes coverage disputes and differing interpretations between parties.
  • Missing notice timelines: not specifying how and when to notify insurers leads to claim denials or late settlement disputes.
  • Unclear indemnity boundaries: overly broad indemnities or undefined caps expose parties to excessive financial liability.
  • Incorrect signer authority: allowing unauthorized signers can render the agreement void or trigger corporate approval disputes.

Step-by-step: completing this agreement

Follow these sequential steps to prepare, review, and finalize the Terrorism Risk Management Agreement accurately.

  • 01
    Collect details: Gather policy numbers, limits, and insured asset list
  • 02
    Define scope: Specify covered perils, territories, and exclusions
  • 03
    Assign duties: Document mitigation, reporting, and cooperation obligations
  • 04
    Execute legally: Obtain authorized signatures and record retention

How the agreement moves from draft to effective

The typical lifecycle includes drafting, insurer negotiation, signatory approval, and post-execution distribution and storage.

  • Draft: Author prepares initial language and clauses
  • Negotiate: Insurers and counsel review and propose edits
  • Sign: Authorized parties sign and date the document
  • Store: Distribute copies and retain originals securely

Core sections to include in a professional agreement

A complete Terrorism Risk Management Agreement is modular: include coverage definitions, responsibilities, limits, reporting rules, and post-event cooperation terms to reduce ambiguity.

Peril Definition

Precisely define 'terrorism', 'sabotage', and closely related terms, and state whether political violence, cyberterrorism, or civil commotion are included or excluded.

Coverage Limits

Specify policy limits, per-occurrence caps, aggregate limits, and any sublimits that apply to different property classes or business interruption items.

Mitigation Obligations

List required preventive measures, security protocols, and notice obligations the insured must maintain to preserve coverage eligibility.

Claims Procedure

Describe immediate notice processes, required documentation, inspection rights, and timelines for submitting proofs of loss and invoices.

Indemnity & Allocation

Set out indemnity language, allocation of losses between parties, and how third-party liability and defense costs are handled.

Cooperation & Confidentiality

Require cooperation in investigations, evidence preservation, and set confidentiality parameters for sensitive security or intelligence-related information.

Typical digital workflow settings for online completion

Configure the signing workflow to match required signers, authentication strength, and sequencing before routing the agreement.

Field Configuration
Signer Order Sequential or parallel as required
Authentication Email + SMS or stronger KBA as needed
Attachments Require proof of loss or exhibits
Retention Copy Auto-send final PDF to all parties

Digital signing and submission considerations

Choose a platform that supports secure eSignatures, audit trails, and document retention required by insurers and regulators.

  • File formats: PDF, DOCX supported
  • Integrations: Connects to CRM and storage
  • Authentication: Supports SMS, email, and KBA

Ensure the chosen solution provides encrypted transit and at-rest storage, audit logs with timestamps, and the ability to retain or export records for compliance.

Key reporting and claim deadlines to include

Specify concrete deadlines for notices, documentation, and renewals to avoid late claims or policy breaches.

Initial Notice:

Require immediate notice 'as soon as practicable' with a defined business-day window

Proof of Loss:

Set a deadline (commonly 30–90 days) for submitting proofs and supporting invoices

Investigation Cooperation:

Require cooperation within specified business days after notice

Renewal Notification:

Set insurer and insured renewal notice periods, commonly 30–60 days

Preservation Period:

Require evidence preservation until claim resolution or specified period

Milestones from incident to claim resolution

A clear milestone timeline helps parties meet obligations and track progress during claims and recovery.

01

Incident Detection

Event is identified and initial internal notification occurs immediately

02

Insurer Notification

Formal notice provided to insurer within the agreement's specified timeframe

03

Evidence Collection

Preserve site, documents, and forensics per insurer and legal instructions

04

Claim Settlement

Adjuster review, negotiation, and payment or denial, per policy terms

Representative eSignature vendor pricing and features for executing this agreement

Compare basic commercial plans and common feature availability for executing and storing signed Terrorism Risk Management Agreements electronically.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies Varies Varies Varies
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No envelope cap 100 envelopes/user/year Varies Varies Varies

Frequently asked questions about validity, signing, and storage

Answers to common legal and technical questions when preparing or executing a Terrorism Risk Management Agreement electronically.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users