Audit rights over a data supplier: what to audit, and what you cannot

An audit clause that is too broad gets refused, and an audit that finds nothing proves nothing. How to scope the right, the sample and the follow-up.

What an audit can actually establish

The records that make a corpus defensible are auditable: the signed speaker forms in the version that applied, the roster with dates and locations, the guideline revisions, the quality control records, the provenance log, and the deletion confirmations. Those are the reason to have the right at all.

What an audit cannot do is prove a negative. It inspects the records the vendor keeps. If a session was never documented, the audit will not find it, and a clean report will be read as proof of compliance when it is only proof that the paperwork was in order. That limit shapes how the clause should be built — an audit verifies a disclosure stream, it does not search reality.

Scope the right to your project

Vendors refuse broad audit rights because a competitor could use them to walk through the operation. The refusal is reasonable, and it usually disappears once the scope is narrowed to the records that concern your delivery: the sessions, speakers and batches supplied under your agreement, and the subcontractors who touched them.

Three limits make an audit clause signable. The auditor may not be a competitor or employed by one. The auditor signs a confidentiality undertaking covering everything seen. And the vendor may redact information relating to other clients, on a stated basis rather than at their discretion. In exchange, insist on the point that matters: consent records for your sessions cannot be withheld on the grounds that they are commercially sensitive.

Cadence, and how the sample is drawn

The usual structure is one audit a year on reasonable notice. That is a floor rather than a design, because the events that make you want an audit do not respect a calendar. Add a for-cause right exercisable on short notice, and define the triggers: a breach notification from the vendor, a consent withdrawal the vendor cannot fully trace, a claim or regulator inquiry involving material supplied to you, or a material change in the vendor's subcontracting arrangements.

Set the notice periods differently for the two kinds. The annual audit on weeks of notice, so the vendor can prepare. The for-cause audit on days, because the value of a for-cause audit is that it happens before the records have a chance to change.

An audit of a large corpus is a sampling exercise, and the sample decides the result. Two rules keep it meaningful. The auditor selects the sample, not the vendor. And the sample is drawn from the delivery manifest rather than from the vendor's filing system, so sessions with missing records cannot be quietly left out of the pool.

Size the sample in the contract as a proportion of sessions or speakers, with a minimum count so that small deliveries are still checked. Add a rule for what happens when the sample fails: the auditor may extend it at the vendor's cost, up to a defined limit, which turns a finding into an investigation rather than an argument.

Cost, findings, and follow-up

The usual allocation is that the buyer pays for the audit unless it finds a material discrepancy, in which case the vendor bears the cost. Define material with a threshold rather than an adjective — a proportion of the sampled sessions missing consent records, for example — or the clause will be argued about instead of applied.

Findings need a path. Write a remediation clause: the vendor has a stated period to cure, with a written plan due sooner, and the buyer may withhold a portion of future payments until the cure is complete. If the gap cannot be cured — records that never existed — the remedy is a credit against the fees for the affected material, or termination of the affected part of the licence.

Keep the report. The audit output belongs in your own compliance file, because when your use of the data is questioned, the audit trail is evidence about how the corpus was assembled and what you knew at the time.

The clause, in eight parts

Written this way, the clause is specific enough to be accepted and strong enough to be used.

  • Scope: records relating to the material supplied under this agreement.
  • Auditor qualification, and the confidentiality undertaking.
  • Redaction rules, and what cannot be redacted.
  • An annual audit on notice, plus for-cause triggers listed explicitly.
  • Sample drawn by the auditor from the delivery manifest.
  • Cost allocation with a defined materiality threshold.
  • Remediation periods, payment holdback, and the remedy for gaps that cannot be cured.
  • A standing change-notification obligation, so the audit verifies disclosures rather than hunting for surprises.

The limit worth remembering

An audit right is a detection mechanism, not a warranty. The most useful thing it does is create a standing obligation for the vendor to tell you when something changes, and the audit checks whether that stream is honest. A supplier who notifies you of a new subcontractor before you ask is worth more than a supplier who passes an inspection once a year.

This is an operational outline rather than legal advice. Audit clauses interact with confidentiality and data protection obligations on both sides, and the wording should go to counsel.

More insights

Submit a sourcing request

Tell us the language, the hours, and what the data needs to look like. You will get a real number and a real timeline — not a range. If we cannot source it well, we will tell you that instead.

  • Pilot batch before the full run, so problems surface early.
  • Consent documentation delivered with the data.
  • No medical or clinical data. No recorded telephone calls.

We reply within two business days. Your details are used only to answer this request. See our privacy policy.

Contact

Talk to a human

Send a specification and we will come back with a real number and timeline.

Submit a sourcing request

Or email hello@linguacorpus.com