Right to Audit Clause

A clause that lets one party inspect the other's books, records, systems, or facilities to verify payments, compliance, usage, or security under the contract.

Reviewed by

GC AI Solutions Team

Updated

September 2026

Definition

A right to audit clause, also called an audit rights clause, lets one party inspect the other's books, records, systems, or facilities to confirm that the other is meeting its obligations. It is used to verify payments and royalties, license usage, regulatory compliance, and security. The clause is defined by its limits as much as its grant: scope, frequency, notice, lookback period, who pays, and what happens if the audit turns up a shortfall. It appears in software licenses, supply and royalty deals, financial-services partnerships, leases, and data processing addenda.

What It Does

A right to audit clause gives one side a way to check the other's work rather than take it on trust. The auditing party gets access to records or systems; the audited party takes on the burden and risk of that access. For in-house counsel, the clause is usually more dangerous when you are the one being audited, because an open-ended audit right is an operational and security liability. The terms that matter are the boundaries: how often, on how much notice, over what period, into what records, and at whose cost. A practical test: if a vendor can audit your systems at any time, with no notice, no frequency cap, and no confidentiality obligation, the clause is a standing disruption you have agreed to in advance.

  • Grants access to records, systems, or facilities to verify compliance or payments

  • Turns on scope, frequency, notice, and lookback period

  • Allocates cost, often shifting to the audited party only on a material underpayment

  • Covers financial, license-usage, regulatory, and security audits

  • Should bind the auditor to confidentiality over what it sees

The market-standard guardrails are one audit per twelve months, reasonable prior written notice, a bounded lookback, and an underpayment threshold that shifts cost.

When You'll See It

Right to audit appears in software and SaaS licenses, supply and manufacturing agreements, royalty and licensing deals, financial-services and bank-partner agreements, commercial leases, data processing addenda, and government contracts. It sits near payment terms, confidentiality, and records provisions. The flavor changes with the deal: a payment audit verifies royalties, a license audit checks seat counts, a security audit tests controls under a DPA, and a lease audit reviews operating-expense pass-throughs.

It matters most where one side's numbers or controls drive the other's exposure: a royalty owed on the auditee's sales, license fees tied to usage the licensee self-reports, or security obligations a customer cannot otherwise verify. The more you depend on the other side's self-reporting, the more you want the right, and the more the audited party wants it bounded.

Examples

Marqeta, Inc. / Sutton Bank

Eighth Amendment to Prepaid Card Program Agreement

Bank audits manager, at-expense, audit-or-report

One-Sided

2025

"Manager acknowledges Sutton Bank has the right to audit any such ledger at least once per year or, in lieu of such audit, Sutton Bank may request Manager provide a copy of a report of an independent audit obtained by Manager, at Manager's expense, that reasonably satisfies Sutton Bank's expectations."

Source

Green Plains Inc.

Marketing Agreement

Mutual records audit, lookback cap

Mutual

2025

"During normal business hours, each party shall have the right to audit such books, records, documents, contracts, accounts and electronic data as it relates specifically to GPTG's fuel grade ethanol purchases hereunder... provided such right to audit shall be limited to two (2) calendar years following the completion of any sale."

Source

AllianceBernstein L.P.

Office Lease

Tenant audits landlord's operating expenses, time-limited

One-Sided

2025

"Audit Rights: Tenant has the right to audit Landlord's books and records relating to Operating Expenses for a period up to (i) three years following the receipt of any Statement for the Stabilized Adjustment Period and any Adjustment Period prior thereto, and (ii) two years following the receipt of any Statement for any Adjustment Period after the Stabilized Adjustment Period."

Source

Beyond, Inc.

Amended and Restated Commercial Agreement

Payment audit, underpayment true-up with interest

Mutual

2025

"In the event such audit reveals an underpayment by a Party, such Party will within thirty (30) days' pay the amount in excess of the fees actually paid together with interest accrued from the date such amounts were originally due."

Source

Negotiate

If you hold the audit right:

If you hold the audit right:

You want to verify

  • Secure access to the records or systems you need to confirm payments, usage, or compliance, described specifically rather than vaguely.

  • Add an underpayment cost-shift, so a material shortfall, often more than 5 percent, makes the audited party pay for the audit.

  • Allow a qualified independent third party to conduct the audit, and require a true-up of any amount owed plus interest.

If you're the one being audited:

If you're the one being audited:

You want to limit disruption

  • Cap frequency at once every twelve months, require reasonable prior written notice, and limit the lookback to a defined period such as two years.

  • Narrow the scope to records relevant to this agreement, and conduct the audit during business hours with minimal disruption.

  • Require the auditing party and its auditor to sign confidentiality obligations, and make the auditor bear the cost unless a material underpayment is found.

The audit right itself is rarely the fight; the boundaries around it are, so spend the negotiation on frequency, scope, notice, and cost.

Red Flags

  • An audit right with no frequency cap, notice requirement, or lookback limit, which allows open-ended disruption.

  • No confidentiality obligation on the auditing party or the auditor accessing your sensitive records.

  • A security audit that permits unrestricted access to systems with no scoping or coordination.

  • Cost borne by the audited party regardless of outcome, even when no underpayment is found.

  • A software-license audit that lets the vendor true up at list price plus penalties with no dispute mechanism.

FAQs

It is a clause that lets one party inspect the other's books, records, systems, or facilities to verify that the other is meeting its obligations, such as paying the right royalties, staying within a license, or maintaining required security.

It is a clause that lets one party inspect the other's books, records, systems, or facilities to verify that the other is meeting its obligations, such as paying the right royalties, staying within a license, or maintaining required security.

The purpose is verification. When one side relies on the other's self-reporting, such as royalties on sales or fees tied to usage, the audit right lets it confirm the numbers and compliance rather than take them on trust.

The purpose is verification. When one side relies on the other's self-reporting, such as royalties on sales or fees tied to usage, the audit right lets it confirm the numbers and compliance rather than take them on trust.

Usually the auditing party pays, with a shift to the audited party if the audit reveals a material underpayment, often defined as more than a set percentage. The audited party also typically owes the shortfall plus interest.

Usually the auditing party pays, with a shift to the audited party if the audit reveals a material underpayment, often defined as more than a set percentage. The audited party also typically owes the shortfall plus interest.

It is an audit right focused on security rather than payments, letting a customer verify the vendor's security controls, often through a review of records, a questionnaire, or a report such as a SOC 2 in lieu of direct access. These are common in data processing addenda and vendor security exhibits.

It is an audit right focused on security rather than payments, letting a customer verify the vendor's security controls, often through a review of records, a questionnaire, or a report such as a SOC 2 in lieu of direct access. These are common in data processing addenda and vendor security exhibits.

That depends on the contract. A common, balanced limit is once per twelve months on reasonable prior written notice, with more frequent audits allowed only for cause, such as a prior audit that found a material discrepancy.

That depends on the contract. A common, balanced limit is once per twelve months on reasonable prior written notice, with more frequent audits allowed only for cause, such as a prior audit that found a material discrepancy.

This content is for informational purposes only and does not constitute legal advice.

Try GC AI Free

Find Every Gap in Your Right to Audit Clause

Trusted by 2,000+ in-house teams

Upload your contract. In 60 seconds, see every missing trigger, weak notice window, and one-sided fee provision, quoted exactly where it appears.

14-day free · No credit card required

SOC 2

Type II Certified

SOC 3

Certified

GDPR

Compliant

Book a personalized demo call

The AI platform built for in-house legal teams. SOC 2 certified. Zero data retention. See it for yourself.

What to expect:

A walkthrough of the GC AI platform, tailored to your team's use cases.

Answers to your questions about security, integrations, and onboarding.

A 14-day free trial if the platform looks like a fit for your team.

Related Clauses

Confidentiality

A contractual provision requiring one or both parties to keep specified information secret and use it only for an agreed purpose.

Data Protection (DPA)

A provision, often a standalone data processing agreement, that governs how a vendor processes personal data on a customer's behalf and meets privacy-law requirements.

Service Level Credits

A clause giving the customer a partial credit when the vendor misses a committed service level, such as uptime, often as the customer's only remedy for the failure.

Governing Law

A contractual provision that selects which jurisdiction’s substantive law will be used to interpret and enforce the agreement.