Comparison

SOW vs. MSA: What's the Difference and What Goes in Each

The short version

A Master Services Agreement (MSA) is the umbrella contract that governs an entire client relationship: payment terms, ownership of the work product, allocation of risk if performance fails, and how the relationship ends. A Statement of Work (SOW) is a shorter, engagement-specific document describing one piece of work under that umbrella: scope, deliverables, price, dates, and who signs off. The MSA is negotiated once and left in place, and a new SOW is drafted for each engagement without reopening the legal terms. Where more than one engagement with a client is plausible, the split is built from the outset.

Consultants and advisory firms scoping a compliance engagement, a BSA/AML program build, a gap analysis, a risk assessment, an audit-support retainer, run into this question the first time a prospective client sends over paperwork, or the first time the firm has to explain what its own contract looks like. SOW and MSA get used almost interchangeably in casual conversation, and the confusion has a real cost. A firm that skips the MSA and writes every engagement as a standalone contract renegotiates liability and IP terms from scratch each time. A firm that writes a thin SOW with no acceptance mechanic exposes itself to a dispute over whether the deliverable was completed, which is a harder question to resolve than a dispute over price.

The short distinction

An MSA governs the relationship. An SOW governs the work. If a term should hold true across every engagement a firm runs with a given client, payment terms, who owns what gets built, what a breach costs, how either side exits, it belongs in the MSA. If a term is true of only this engagement, what's being delivered, by when, for how much, signed off by whom, it belongs in the SOW. An SOW is not a standalone contract in a multi-engagement relationship. It is incorporated into, and inherits every standing term from, the MSA it references.

What a Master Services Agreement covers

The MSA is negotiated once, typically by counsel or firm leadership, and then left alone for the life of the relationship. It carries the standing commercial and legal terms every future engagement will inherit without re-litigating them.

ClauseWhat it sets
Services / SOW incorporationHow future SOWs attach to the agreement, and which document controls if they conflict.
Payment and invoicingInvoicing cadence, payment terms, a dispute window, late-payment interest.
IP / work-product ownershipWho owns what gets created: the client, the consultant, or a hybrid split between deliverables and background methodology.
ConfidentialityMutual protection obligations, standard carve-outs, a return-or-destroy obligation at termination.
IndemnificationWhich third-party claims each side covers, tied to the actual risk of the services being performed.
Warranty and liability capA performance warranty, a cure period, and a dollar- or fee-based cap on damages.
InsuranceCoverage limits matched to the liability cap, so the cap is actually collectible.
Term, termination, survivalHow long the relationship runs, how either side exits, and which obligations outlive termination.

What a Statement of Work covers

The SOW is the document delivery staff draft for every new engagement, quickly, without reopening the legal terms above. A well-formed SOW names the MSA it's issued under in its first paragraph, and states nothing that conflicts with that agreement unless it names the specific section it's overriding.

SectionWhat it names
Order of precedenceThe parent MSA the SOW is issued under, and which document controls if the two conflict.
Background and scopeWhy the work exists, and, explicitly, what's out of scope.
Specific requirementsThe obligations the consultant is contracted to deliver, usually stated one per line so each is independently verifiable.
Key personnelNamed or role-based staff, seniority, and how long they're committed to the engagement.
Deliverables and acceptanceWhat gets delivered, by when, who approves it, how long they have, and what a rejection triggers.
ChargesThe pricing model, fixed fee, time-and-materials with a not-to-exceed cap, or milestone-retainage, and the actual numbers.
Change managementWhat happens when scope drifts, and who has to sign before the drift becomes billable.

How the two documents relate

Every SOW names the MSA it's issued under and states, in its opening paragraph, that it's subject to that agreement's terms. What happens when the two documents disagree is a drafting choice, not an accident, and firms land on one of two conventions.

ConventionHow it worksRisk
MSA controls (recommended default)The MSA wins in a conflict unless the SOW expressly names the section of the MSA it's overriding.Low. Legal terms stay stable across every engagement unless a deliberate, named override is negotiated.
SOW controls for its own scopeWhatever the SOW says wins for that engagement, with no override flag required.High. A rushed or unreviewed SOW, drafted by delivery staff rather than counsel, can quietly change a liability cap or IP clause without anyone noticing the deviation.

Most firms should default to MSA-controls with a named-override escape hatch. It preserves the operational benefit of the split, a SOW that doesn't require legal review before every signature, without the risk that a scope document silently rewrites risk allocation.

When the split is warranted

The split earns its keep the moment a second engagement becomes plausible. For a genuine, one-time-only engagement, a single standalone consulting agreement that merges MSA-level and SOW-level content into one document is simpler and appropriate. Retrofitting an MSA+SOW split later means renegotiating terms that are already locked into an executed document, which is harder than building the split from day one.

Where consulting engagements get this wrong

What this looks like in a compliance engagement

A compliance-consulting SOW's Deliverables table is where the engagement's actual scope gets named in contract language. A BSA/AML program build might name a risk assessment, a gap analysis, and an independent-testing report as three separate line items, each with its own review window and approver. See the guides to BSA/AML risk assessment, AML program gap analysis, and BSA/AML independent testing for what each deliverable actually has to cover to hold up under exam. An engagement scoped for a fintech operating under a bank charter should also account for how sponsor-bank oversight allocates responsibility between the parties, since that allocation often shapes who the SOW names as the approver for each deliverable.

Practical guidance

The MSA is built once, with counsel, and treated as settled. A fresh SOW is drafted for each engagement, referencing the MSA by section number where relevant, without reopening legal negotiation. Where SOWs repeatedly require legal review of terms the MSA was meant to settle, the MSA under-specified those terms, and the correction belongs in the MSA rather than in each successive SOW.

Primary sources

Common questions

What is the difference between an SOW and an MSA?
A Master Services Agreement (MSA) is the umbrella contract that governs an entire client relationship: payment terms, IP ownership, confidentiality, indemnification, a liability cap, and how the relationship ends. A Statement of Work (SOW) is a shorter, engagement-specific document describing one piece of work under that umbrella: scope, deliverables, price, dates, and who signs off. The MSA is negotiated once; a new SOW is drafted for every engagement.
Are both an MSA and an SOW needed, or is one enough?
For a genuine one-time engagement, a single standalone consulting agreement that merges MSA-level and SOW-level content is simpler and appropriate. The split earns its keep the moment a second engagement becomes plausible: build the MSA once, then issue a fresh SOW for each new piece of work without renegotiating the legal terms.
If the MSA and the SOW conflict, which one controls?
It depends on the precedence clause the MSA states, and this should never be left implicit. The recommended default is MSA-controls: the MSA wins in a conflict unless the SOW expressly names the section of the MSA it is overriding. The alternative, SOW-controls, lets a SOW silently change legal terms for its own engagement, which is higher risk because a delivery-drafted SOW can alter a liability cap or IP clause without anyone flagging it.
What should never appear in an SOW?
Restated or contradicted MSA-level terms without a named override. Indemnification scope, liability caps, IP-ownership language, and termination mechanics belong in the MSA and should not be silently rewritten inside a scope document. A well-formed SOW references those sections by number rather than re-describing them.
Can work start on an SOW before the MSA is signed?
Only if both sides say so explicitly and name the authority relied on. Starting delivery before the parent agreement is executed, without documenting that decision, invites an implied-contract argument later about which terms actually govern the work already performed.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.