A service level agreement usually enters a business's life in one of two ways. You are the customer, reading a page of promises about uptime and response times before you sign a managed services deal, wondering what those numbers actually mean. Or you are the provider, and a client is asking you to commit to targets you are not sure you can hit. Either way, the SLA is the part of the arrangement most likely to turn into a dispute, and also the part most often left vague. This guide explains how an SLA is built, how it becomes enforceable, what Australian law adds on top of it, and how to run it so it prevents arguments instead of creating them.
What an SLA actually is (and when you need one)
An SLA is the part of a services arrangement that turns "we'll do our best" into commitments that can be measured. It sets service standards and performance targets for an ongoing relationship: how available a system will be, how quickly a fault gets a response, how quickly it gets fixed, and what happens when a target is missed.
An SLA is not usually the whole contract. The commercial deal, covering price, scope, liability limits and termination, sits in the main services agreement. The SLA is the operational rulebook that sits with it, and the two documents need to be consistent with each other.
In practice, an SLA takes one of three forms:
- Schedule to the main agreement: the SLA is attached to the contract and referred to directly, for example as "Schedule 2: Service Level Agreement". This is usually the cleanest approach, because signing the contract signs the SLA.
- Separate document incorporated by reference: the contract states that a named document, with a date and version, forms part of the agreement. Workable, but it relies on the reference being precise.
- Embedded terms: the service levels are written into the platform or services terms themselves. Common for online services, but less flexible when targets change.
You need an SLA when the relationship involves ongoing services rather than a one-off job: managed IT or cybersecurity, a SaaS platform, a marketing retainer, logistics, or outsourced functions such as payroll. It earns its place when delivery is mission-critical, when there are support obligations with promised response times, when several teams depend on the arrangement, or when disputes about "what was promised" keep recurring. For a one-off project with a defined deliverable and a completion date, the engagement contract usually carries the weight on its own.
How an SLA becomes legally binding
An SLA is enforceable only to the extent it forms part of the contract between the parties. It becomes part of the contract the same way any term does: by being signed as part of the agreement, by being incorporated by reference with reasonable notice of its existence and location, or through a course of dealing between the parties. The practical point is that an SLA left floating next to a contract, undated and unreferenced, may be treated as an informal guide rather than a set of binding obligations.
Three habits make the connection reliable:
- Attach the SLA as a schedule and refer to it in the main contract.
- Incorporate it by reference, naming the exact document, its date and where it can be found.
- Use version control: date the SLA, state which version applies to the agreement, and require any changes to be made in writing.
Once the connection is made, the drafting traps that commonly undo SLAs are these:
- Overpromising: targets the business cannot staff, measure or fund, such as 99.99% uptime with no monitoring or redundancy behind it.
- Undefined metrics: a "reasonable response time" with no measurement method, service hours or starting point.
- Contradictions: the SLA promises remedies that the main contract's liability cap or indemnities rule out.
- No process: no escalation path, no reporting and no opportunity to cure repeated failures.
- Unclear exclusions: maintenance windows, third-party outages and customer-caused faults left undefined, so every miss counts against the provider.
What a strong SLA needs to cover
Strong SLAs tend to share the same building blocks, whatever the industry.
Service description and scope
Start with what the service is, and just as importantly what it is not. Does support include training, configuration and onboarding? Does it cover liaising with third parties such as an internet provider? Is the provider supporting customer-owned hardware or only its own systems? If the main agreement already defines scope, the SLA must match it; misalignment between the two documents is one of the most common reasons an SLA fails.
Availability and uptime
Where uptime matters, define the percentage (for example 99.9% per calendar month), how it is measured (monitoring tool, sampling frequency), the service hours behind it, and the exclusions that do not count against it, such as scheduled maintenance carried out with notice, customer-side issues and force majeure events. A marketing-grade "99.99% uptime" promise creates legal risk if the systems and staffing cannot deliver it.
Response times versus resolution times
Response time is how quickly the provider acknowledges an issue and starts work. Resolution time is how quickly it fixes it or provides a workaround. Many disputes start because a customer reads "we respond within one hour" as "we fix it within one hour". The SLA should state both, separately, and say what resets each clock.
Severity levels and escalation
Define incident categories and attach a response to each:
- Severity 1 (critical): total outage, major security incident, or the customer's business cannot operate. Typically 24/7 support, the fastest response target and a named emergency contact.
- Severity 2 (high): a major function not working or significant degradation, with a defined response target and update frequency.
- Severity 3 (medium): a non-critical fault with a workaround available.
- Severity 4 (low): minor issues and "how-to" questions, handled in business hours.
Each level needs a response target, a resolution target or update frequency, and an escalation contact, so a ticket is never lost between teams.
Customer responsibilities
An SLA is a two-way arrangement. Common customer obligations include providing accurate information and timely access to systems, keeping credentials secure and reporting suspected compromise, maintaining a compatible hardware and software environment, and following the documented support process, such as lodging tickets rather than messaging individual staff. If the customer's conduct causes a miss, the provider should not carry it.
Exclusions
Set out what does not count as a failure: planned maintenance with notice, outages caused by third parties outside the provider's control, customer-caused faults and force majeure events. An SLA without exclusions measures the provider against events it cannot control.
What happens when a target is missed: credits, caps and termination
Most SLAs answer the "what happens if you miss" question with a menu of remedies: service credits (a percentage of the monthly fee credited when a target is missed), additional support time at no cost, and termination rights for persistent failure. The choice of remedy matters more than most providers assume.
A service credit is usually structured as a reduction in the fee, not a payment the provider must make. That distinction keeps it outside the penalty doctrine, the rule most recently applied by the High Court in Paciocco v Australia and New Zealand Banking Group Ltd [2016] HCA 28, which strikes down clauses that impose a payment on breach out of all proportion to the legitimate interest protected. A credit that simply reduces the price is generally safe; a clause dressed up as a penalty payment is not.
Remedies should also work with the rest of the contract. If the main agreement caps total liability, the SLA should say how credits sit within that cap, and whether they are the customer's sole remedy for service failures or an addition to other rights. Termination rights for repeated failures need an objective trigger, such as three consecutive months of missed targets, rather than a vague "material breach". And the customer's statutory rights sit above all of this, which is the next point.
Where Australian law puts limits on your SLA
Consumer guarantees sit underneath the SLA
When the customer is a "consumer" under the Australian Consumer Law (ACL), which is Schedule 2 of the Competition and Consumer Act 2010 (Cth), services are supplied with automatic guarantees of due care and skill (s 60), fitness for any disclosed purpose and for a stated result (s 61), and supply within a reasonable time where the contract does not fix a time (s 62). A customer is a consumer for services where the amount paid or payable does not exceed $100,000, or where the services are of a kind ordinarily acquired for personal, domestic or household use, and a person is presumed to be a consumer unless the contrary is proved (s 3).
The guarantees apply whether or not the SLA mentions them, and s 64 makes void any term that purports to exclude, restrict or modify them. An SLA that says "no warranties" or "service credits are your only remedy" cannot displace the guarantees where they apply.
For business-to-business services there is a partial escape. Section 64A lets a supplier of services that are not of a kind ordinarily acquired for personal, domestic or household use limit liability for failure to comply with the guarantees to re-supplying the services or paying the cost of having them supplied again, provided it is fair and reasonable to rely on the term in all the circumstances. That is why the nature of the counterparty, consumer or business, drives how an SLA can be drafted.
Misleading conduct reaches your marketing too
Section 18 of the ACL prohibits conduct in trade or commerce that is misleading or deceptive or likely to mislead or deceive, and it applies to business-to-business dealings as well as consumer sales. The practical consequence is that the SLA and the sales page, the proposal and the pitch deck should tell the same story. A provider that promises "guaranteed 99.99% uptime" in marketing while the SLA quietly excludes weekends has created a mismatch that can be complained about either way.
Unfair terms can void part of the SLA
Since the unfair contract terms regime was extended in late 2023, a term of a standard form small business contract is void if it is unfair, and proposing or relying on an unfair term can now attract pecuniary penalties. A contract is a small business contract if at least one party employs fewer than 100 persons or has turnover of less than $10 million (s 23). A term is unfair if it causes a significant imbalance in the parties' rights, is not reasonably necessary to protect the legitimate interests of the party advantaged by it, and would cause detriment if relied on; a term is presumed not to be reasonably necessary unless the advantaged party proves otherwise (s 24). Terms commonly at risk in SLAs include unilateral variation of service levels without notice or objective criteria, "sole and exclusive remedy" clauses that strip the customer of the consumer guarantees, and suspension or termination rights that operate without any trigger. If an SLA is one-sided, it may be both unenforceable in part and a compliance problem in itself.
Privacy obligations run alongside
If the services involve handling personal information, the SLA sits on top of obligations the provider already owes under the Privacy Act 1988 (Cth), including the Notifiable Data Breaches scheme, under which an entity covered by the Act must notify affected individuals and the Office of the Australian Information Commissioner when a data breach is likely to result in serious harm. The SLA should allocate responsibility for access controls, security incident notification timelines, data storage locations and subcontractors, but it cannot contract the parties out of their statutory privacy obligations.
Running the SLA day to day so it prevents disputes
An SLA only works if it is treated as an operating tool, not a document signed and filed. Five habits make the difference:
- Negotiate it up front: An SLA introduced after a major incident feels defensive and is harder to agree. Treat it as a normal part of onboarding and contracting.
- Match service tiers to price: Standard: business hours support, next-business-day response. Premium: extended hours, faster response, proactive monitoring. Enterprise: 24/7 incident response and a dedicated account manager. Tiers protect the provider from giving enterprise service for a standard price, and give the customer a genuine option.
- Measure what you promised: Monitoring tools and ticketing system timestamps should feed a monthly report covering incidents by severity, average response and resolution times, uptime percentage, root cause analysis for major incidents and planned improvements.
- Review the SLA when the business changes: Quarterly reviews suit fast-moving technology businesses; six to twelve months suits stable operations; and any significant incident or run of failures should trigger an immediate look. Expanding into new time zones, adding premium tiers or increasing transaction volume all change what is realistic.
- Operationalise the commitments: Staff the promised support hours, train the team on severity definitions and escalation steps, and keep written records whenever a credit or other remedy is triggered. A record of how the SLA actually performed is what makes a dispute short.
When an SLA needs a lawyer's hand
Some of the decisions in this article are judgement calls that depend on your specific deal. Whether the counterparty is a consumer or a business, and therefore whether the consumer guarantees can be limited to re-supply under s 64A of the ACL, turns on the nature of the services and the price. Whether a proposed remedy clause survives an unfair contract terms challenge turns on how standard form the contract is and how transparent the term is. Whether the SLA and the main agreement contradict each other on liability caps, indemnities and termination requires reading both documents together, not just the SLA.
That is where a commercial lawyer adds value. A lawyer can draft the SLA as a schedule that matches the head agreement, review an existing SLA for ACL exposure and unfair terms risk, and advise on the limits that can legitimately be placed on liability for a particular customer. At Artificer Legal we regularly help Australian businesses put service level arrangements in place that protect the provider and give the customer something worth relying on. If you are about to sign a services deal, or you are being asked to commit to service levels you are not sure you can meet, that is the moment to get the SLA checked, before it is signed rather than after the first dispute.
The counterparty decides how far your SLA can go
The most misunderstood point about SLAs in Australia is that they are not a blank slate. A provider can draft the cleanest, most commercially sensible SLA in the world, and for a consumer customer the consumer guarantees in ss 60 to 62 of the ACL still sit underneath it, untouched by anything the SLA says, while an unfair term in a standard form small business contract is simply void. The same SLA that works perfectly for a business customer being supplied with custom software needs to be redrawn before it is offered on standard terms to a small business customer. Getting that distinction right, and connecting the SLA properly to the contract, is what separates a document that manages risk from one that creates it.
In short: define the service in measurable terms, attach the SLA to the contract with version control, set credits and caps that fit the main agreement, and remember that consumer guarantees, misleading conduct law and the unfair contract terms regime all sit above whatever the parties write. Run it with monthly reporting and regular reviews, and keep the counterparty's identity front of mind, because that is what decides how far the SLA can legally go.