Identity-provider contract and SLA checklist
The contract should describe the exact identity service being bought and what happens when it changes or fails. Attach product, region, methods, evidence, data flow, thresholds and support—not only a generic provider name.
Contract and liability positions require professional advice. This checklist identifies operational questions and does not provide legal drafting or determine enforceability.
For: procurement, legal, privacy, security, operations and vendor-management teams. This is independent information, not legal, compliance or security advice.
Scope and evidence
- Named product, modules, version model, regions and supported methods.
- Required tests, certifications and continuing evidence.
- Accuracy, fraud and accessibility representations with defined scope.
- Configuration ownership and acceptance criteria.
Data and security
- Roles, instructions, purposes, locations and subprocessors.
- Retention, deletion, backups and exit proof.
- Security controls, access and audit evidence.
- Breach/security incident definition and notification timetable.
- Restrictions on model training and cross-client reuse.
Service and change
- Availability and latency measurement/exclusions.
- Support severity, response, resolution and escalation.
- Document/model/SDK updates and deprecation notice.
- Material adverse change and revalidation rights.
- Business continuity, outage fallback and disaster recovery.
Commercial and exit
- Attempts, retries, reviews, minimums and overage.
- Price-change and volume terms.
- Responsibility for false decisions, incidents and regulatory cooperation.
- Data/decision portability, transition assistance and deletion.
- Termination after evidence, security or compliance failure.
Evidence and limits
MyID separates enacted rules, official implementation material, testing and vendor claims. A source can establish what its publisher says; it does not prove that every product, deployment or interpretation works as claimed. Where Irish implementation remains unsettled, this page says so.
- General Data Protection Regulation
- NIST SP 800-63A-4 identity proofing
- ENISA Remote Identity Proofing: Attacks and Countermeasures
Sources checked 22 August 2026. Re-check the linked primary material before making a consequential decision.
Next useful pages
Follow the Irish evidence
Get the business briefing when Irish wallet, verification and age-assurance evidence changes.
Join the business briefing