Table of Contents
With third-party technology playing an increasingly critical role in business operations, organisations need to protect business-critical applications from potential disruption.
A Software Escrow Agreement is a tri-party arrangement between the software customer, the software supplier, and an escrow provider. This agreement involves securely storing the software source code for a business-critical application with the escrow service provider to ensure it's available in case it's needed in the future, for example, in the case of bankruptcy or a lack of support. If a pre-determined release condition is met, the escrow deposit is released to the software customer, enabling them to recreate and maintain their software application.
In this blog, we walk through eight steps legal teams can follow when helping organisations establish software escrow arrangements, from assessing risk through to creating a repeatable process for future technology investments.
Before recommending a Software Escrow Agreement, legal teams should help organisations understand their exposure to supplier risk.
A useful starting point is asking:
To build a complete picture, organisations should also consider factors such as implementation time, costs, regulatory requirements, data usage and retention, and the supplier's financial stability.
Not sure where to start? Download our Technology Supplier Risk Assessment Matrix to help identify and evaluate potential supplier and technology risks.
Once the requirement for software escrow has been established, the next step is understanding exactly what is being provided by the supplier and what would be required to maintain continuity if the software became unavailable.
Questions to consider include:
Depending on the solution, this may include source code, build instructions, database schemas, infrastructure-as-code assets such as Terraform scripts, technical documentation, deployment processes, and other supporting materials.
At this stage, legal teams should engage with an escrow provider to arrange a scoping call with the relevant parties. This helps ensure all required materials are identified and captured appropriately within the agreement.
One of the main considerations is determining how frequently deposits should be updated. All parties should consider how often changes are made to the application and agree a suitable deposit schedule that ensures an up-to-date version of the materials is always available.
Organisations may also wish to evaluate more than one escrow provider before making a decision.
Further reading: How to Choose a Software Escrow Provider
Once the solution has been scoped, the escrow provider can recommend services that align with the organisation's risk profile and budget.
Although Software Escrow is not necessarily expensive, organisations should budget appropriately. Typical costs may include legal fees, escrow administration fees, and technical verification services to confirm the integrity and completeness of deposited materials.
Organisations may also wish to consider different service options, including varying levels and frequencies of verification testing.
As a general principle, the level of investment in Software Escrow should reflect the perceived level of risk, the criticality of the application, and the value of the investment being protected.
Despite these associated expenses, the advantages of a Software Escrow Agreement often outweigh the costs. By safeguarding technology investments, organisations can mitigate the risks associated with relying on third-party technology providers while reducing the likelihood of costly business disruption.
Once the provider has been selected and the solution has been scoped, the parties can agree the legal and technical framework of the escrow arrangement.
This should clearly define:
Taking the time to agree these points upfront can help avoid disputes later and ensure all parties have a shared understanding of how the arrangement will operate.
The parties involved in contract negotiation are as follows:
Legal teams can help organisations avoid disputes and unnecessary costs by agreeing upfront which materials will be deposited, how often deposits will be updated, and the circumstances under which the escrow materials may be released.
Our best practice advice is to discuss software escrow during the negotiation stages of the software licence agreement, rather than after the contract has been signed. For new software licence agreements, legal teams should also consider including an escrow provision within the contract from the outset to ensure business continuity requirements are addressed early and all parties are aligned on their obligations.
We would also advise attaching a copy of the escrow agreement to the software licence agreement where possible, so the terms can be agreed upfront and incorporated into the wider contractual arrangement.
However, Escode can also support organisations that are looking to implement software escrow once the licence agreement has already been signed.
Verify the deposit as soon as possible, preferably within 30 days.
A Software Escrow Agreement is only effective if all the essential components have been properly deposited. If certain items are agreed but never verified, there can be no assurance that the application can be recreated when needed.
Software Escrow Verification provides confidence that, should the application ever need to be recreated from the deposited materials, the required knowledge and guidance will be available.
Organisations gain assurance that they can maintain continuity if required, while software suppliers can demonstrate their commitment to best practice and customer protection.
The work does not end once the agreement has been signed and the materials have been deposited.
Legal teams should encourage the organisation to appoint a key contact to oversee the agreement, manage ongoing deposits, and ensure any changes to the application are reflected within the escrow arrangement.
Regular reviews can help ensure the agreement continues to align with the organisation's business requirements and technology changes over time.
Why reinvent the wheel the next time around?
The lessons learned from an initial Software Escrow project can help organisations establish a repeatable process for future technology procurements and supplier risk management initiatives.
By creating a consistent approach to identifying critical third-party software, assessing risk, scoping requirements, verifying deposits and managing agreements, organisations can streamline future projects and ensure business-critical applications are protected from the outset.
Third-party technology continues to underpin many critical business services. By following these eight steps, legal teams can help organisations assess supplier risk, implement appropriate protections and build greater resilience into their technology strategies.