Skip to main content
Legal

Statement of Work template

Last updated 1 September 2026

Baseline Telemetry Advisory is the trading name of the practice.

Every Baseline Telemetry Advisory engagement is scoped in a Statement of Work ("SOW") issued under the Master Services Agreement. This page shows the structure of that document so a client knows what to expect and what to review before signing. Fees, dates, and named people are filled in per engagement.

1. Cover sheet

  • SOW reference number and version.
  • Client legal entity, registered address, and billing contact.
  • Named client engagement owner and named Baseline Telemetry Advisory lead.
  • Start date, end date, and review points.
  • Governing MSA reference and DPA reference.
  • Insurance levels in force for the engagement.

2. Objective

A short statement of the business outcome the client is buying, written in the client's terms. For example: reach SOC 2 Type I readiness for the core product before the Q4 enterprise renewal cycle, with an owned risk register and an evidence index an auditor can follow.

3. Scope

  • Frameworks in scope, and the version or trust services criteria being used.
  • Systems, environments, products, and legal entities in scope, and the ones expressly out of scope.
  • Locations and teams covered.
  • Number of vendors, policies, controls, or risks the fee assumes.

4. Delivery mode

The SOW states one of the two modes, and the operational detail that goes with it.

  • Mode A, Baseline Telemetry Advisory delivery workspace. Work is carried out in the workspace. Handover is by structured export (PDF, XLSX, DOCX, ZIP) and a handover bundle at close. Exports are unbranded: each file carries the document title and the generation timestamp only.
  • Mode B, in-platform execution. Work is carried out inside the client's own platforms. The SOW lists each platform, the specific accounts and roles granted, the access window, the client approver for changes, whether Baseline Telemetry Advisory may create or edit records directly or must submit proposals for client approval, and the logging the client will keep. Access is revoked at close and confirmed in writing.

The website describes the same two modes in plain language: Mode A is "we run delivery in our workspace" and Mode B is "we work embedded in your tools". The SOW wording governs.

5. Deliverables

Each deliverable is listed with its format, the mode it is delivered in, and the milestone it lands on. Typical items: framework scope and applicability statement, control library with ownership, gap assessment, risk register and treatment plan, policy set, vendor and third-party review pack, incident response and continuity documents, evidence index, buyer evidence pack, and a management report.

Two of these, the buyer evidence pack and the handover bundle, are composite deliverables. They are maintained across several workspace modules rather than as a single document, so they are delivered in one of two ways, and the SOW states which. First, as the live modules themselves, which the client and Baseline Telemetry Advisory work in and export per module. Second, as a single dated ZIP assembled from those modules and published to Deliverables, containing a cover README PDF, one workbook with a sheet per register, and a manifest of row counts. The ZIP is a point-in-time snapshot rather than a live record, and is regenerated whenever it needs to be current. A client should not expect one continuously updating "pack" record.

The buyer evidence pack is scoped for an external reader (a customer, partner, or auditor) and deliberately excludes open issue detail, unmitigated risk narrative, incident root causes, internal notes, and vendor commercial terms. It is readiness evidence, not a certification, attestation, or audit opinion. See section 8.

6. Milestones and schedule

Milestone name, target date, dependency, and the party responsible. The schedule assumes the client meets its dependencies; slippage on a client dependency moves the dates that follow it.

7. Client dependencies and assumptions

  • Named client owner available for a set number of hours per week.
  • Timely access to systems, documents, and subject-matter experts.
  • Existing documentation supplied in a usable format at kick-off.
  • For Mode B, access provisioned by the date stated, with the client's own change control in force.
  • The client reviews and approves deliverables within an agreed working-day window.
  • AI-assisted preparation, where used, is reviewed and validated by Baseline Telemetry Advisory before delivery under the MSA's AI tools clause.

8. Exclusions

Unless a line item says otherwise, the SOW excludes: certification and attestation issuance, audit fieldwork, penetration testing, red teaming, exploitation or code-level security testing, remediation engineering and infrastructure changes, legal advice, tax advice, licence and tooling costs, and staff training delivery beyond agreed walkthroughs. Baseline Telemetry Advisory is not a certification body and does not warrant an audit or certification outcome. See the MSA.

9. Acceptance

Each deliverable is accepted when the client confirms in writing, or after five business days from delivery with no written objection. Where the client objects, it states the specific gap against the SOW, and Baseline Telemetry Advisory corrects the deliverable within an agreed window. The acceptance route does not turn a readiness deliverable into an audit opinion.

10. Fees and payment

  • Pricing basis: fixed fee per milestone, monthly retainer, or day rate with a cap.
  • Invoicing schedule and payment terms of 30 days.
  • Expenses that require pre-approval.
  • Rate for out-of-scope work, and the change-control route it must follow first.

11. Change control

Any change to scope, deliverables, dates, or fees is recorded in a written change note signed by both named owners before the work starts. Verbal or in-channel requests are logged but not actioned until the change note is signed.

12. Personal data

The SOW states whether the engagement involves personal data, the categories involved, and whether Baseline Telemetry Advisory acts as processor. Where it does, the DPA governs the processing, and Annex I is completed from the SOW scope.

13. Exit and handover

Handover bundle content, the format the client keeps its records in, revocation of Mode B access within two business days of close, and the export window for workspace data.

At close, the handover bundle is published as a single dated ZIP in Deliverables so the client holds one file it owns outright, and the per-module exports remain available until the export window ends. The final ZIP is a snapshot taken on the close date; a later snapshot is produced only if the parties agree further work.

14. Signatures

Signed by an authorised signatory for each party. Signature of the SOW confirms acceptance of the MSA and DPA as they apply to the engagement.

Requesting a scoped SOW

To get a scoped SOW for a specific piece of work, book a session or email support@btadvisory.io. Contract questions go to legal@btadvisory.io.

Legal / last updated 1 September 2026