Previous versions of the Master Subscription Agreement, retained for reference.
AiBizzApps Limited
A record of all previously published versions of the GRCxAI Master Subscription Agreement.
Current Version
Version 1.3 — Effective from 16 August 2026
Version 1.2
Operative from 11 August 2026 to 15 August 2026.
View the full text of version 1.2 →
Summary of the changes made by version 1.3:
(a) vCISO added as an Add-On Module, bundled with TPRM. A new definition of “vCISO Module”; the definition of “Add-On Module” restated to identify the TPRM Module and the vCISO Module as the Add-On Modules available, licensed together as a single bundle; the definition of “TPRM Module” cross-referenced to that bundle; a sentence added to clause 6.7 providing that a bundle of Part B modules is treated as a single Add-On Module charged at a single fee; a new paragraph 8 of Schedule 1 Part B describing the vCISO Module; and a new paragraph 9 of that Part governing the licensing of the two modules together, as an addition to the Core Platform or on a standalone basis.
(b) What the vCISO Module covers. Paragraph 8 records that the Module assesses only the estate the Customer has declared in the estate register, so undeclared or inaccurately declared components are not assessed and appear in no output; that maintaining that declaration is the Customer's responsibility; that forecasts are predictive and are not a representation that any event will or will not occur; and that the Module supports the Customer's security function rather than replacing it, its outputs being decision-support information and not professional security, legal or regulatory advice.
(c) External and third-party information addressed in one place, across the whole Service. New clause 11.6 applies wherever the Service presents, matches against or derives output from information obtained from external sources — public and statutory registers such as company registries, tax and VAT registers and data-protection, certification and scheme registers; credit and financial data providers; sustainability and vendor-rating providers; vulnerability, exploit and threat-intelligence feeds; security advisories; news and media reporting; and information a third party publishes about itself — and applies to the Core Platform as well as to every Add-On Module. It records, at (a) to (e): that source coverage is selective rather than exhaustive and the Service is not a complete record; that the Provider prefers sources it considers established and credible but that this is a statement of practice and not a warranty, does not independently verify all such information, and that the information may be inaccurate, out of date, retracted, contested as to attribution or affected by the publisher's editorial bias, national perspective or commercial interest, with derived scores and ratings being opinions rather than statements of fact; that no commitment is given as to how quickly information published at source becomes available, or how often a source is refreshed, and that the Service is not a real-time, monitoring, detection, alerting or incident response service; that the absence of a finding is not assurance that nothing exists and may not be relied upon or represented to a third party as such; and that where an output looks inconsistent with what the Customer knows, or would be material to a decision, the Customer should check it against the underlying source before acting, in addition to the human review already required by clause 11.4.
These consequences already followed from clauses 11.3(b), 11.3(c), 11.3(d) and 11.3(e), from clause 11.4 and from Schedule 2, which between them disclaim accuracy, completeness, fitness for the Customer's requirements and AI-generated output, place reliance on the Customer, and give no commitment as to timing. Clause 11.6 states them expressly, and in terms specific to externally sourced information, rather than leaving them to be inferred. It is therefore a clarification under clause 17.2(d).
(d) Sub-processor change carried into the source. The replacement of Supabase, Inc. with Hetzner Online GmbH in the Schedule 4 sub-processor table, made under Schedule 4 paragraph 6 while version 1.2 was in force, now forms part of the document text rather than being applied on publication. The archived version 1.2 linked above records the document as published, including that change. No wording is altered by carrying it across.
(e) No other change. All other terms of version 1.2 are carried forward unaltered.
Adding an Add-On Module, and bundling it with an existing one at no separate fee, is an expansion of the Service that removes no right and imposes no new obligation. It is therefore a non-material change under clause 17.2(d), so version 1.3 takes effect on publication.
Version 1.1
Published 6 August 2026 with an effective date of 6 September 2026. Superseded by version 1.2 before it took effect, so it was never the operative version.
View the full text of version 1.1 →
Summary of the changes made by version 1.2:
(a) Two frameworks added. Schedule 1 paragraph 2 now states twenty-nine (29) frameworks rather than twenty-seven (27), adding the Digital Operational Resilience Act (Regulation (EU) 2022/2554) and HIPAA (Security, Privacy and Breach Notification Rules). Both now ship with a dedicated content set — DORA with 46 mapped controls, 18 document templates and 56 assessment questions; HIPAA with 67 controls, 18 templates and 54 questions — together with training courses. Version 1.1 omitted them because that content did not exist when it was drafted.
(b) No other change. The Add-On Module and TPRM provisions introduced by version 1.1 (definitions, clauses 2.2, 2.3 and 6.7, and Schedule 1 Part B) are carried forward unaltered.
Adding framework coverage is an expansion of the Service and therefore a non-material change under clause 17.2(d), so version 1.2 takes effect on publication.
Version 1.0
Operative from 1 May 2026 to 5 September 2026.
View the full text of version 1.0 →
Summary of the changes made by version 1.1:
(a) Third-Party Risk Management separated as an Add-On Module. New definitions of “Core Platform”, “Add-On Module” and “TPRM Module”; the definition of “Service” restated as the Core Platform together with any Add-On Module identified in the Order Form; clauses 2.2 and 2.3 scoped accordingly; new clause 6.7 governing Add-On Module fees, pro-rating and independent renewal; and a new Part B of Schedule 1 describing the TPRM Module, which may be taken as an addition to the Core Platform or on a standalone basis.
(b) Compliance framework coverage restated. Schedule 1 paragraph 2 previously referred to nineteen (19) frameworks in a single undifferentiated list. It now states the twenty-seven (27) frameworks that have their own dedicated content set — controls library, assessment questions and document templates — and separately identifies ISO/IEC 27002, CCPA and US state privacy law, the FCA Handbook (relevant sections), ISO 9001 and the NIST AI Risk Management Framework, which are addressed through mapped controls, guided assessments and document templates delivered within those frameworks and the guided assessment library rather than as separate framework programmes. Coverage of these is unchanged in substance; only its description is now accurate. Two frameworks named in version 1.0 — DORA and HIPAA — are no longer named, as the Service does not currently deliver a control, assessment or template set for either (HIPAA is addressed in training content only). The paragraph also notes that the IASME MSP scheme remains under development and records the dedicated EU AI Act and Provision 29 modules.
(c) Core vendor capability made explicit. Schedule 1 paragraph 3 now records the vendor register and questionnaire-based vendor assessments included in the Core Platform, and distinguishes them from the continuous vendor intelligence provided by the TPRM Module.
In accordance with clause 17.2(f) of the Master Subscription Agreement, the Provider maintains a publicly accessible archive of all previous versions of the Agreement at this page. Each archived version will be listed below with:
(a) the version number;
(b) the period during which it was the operative version;
(c) a link to the full text of that version; and
(d) a brief summary of the changes made in the version that superseded it.
Customers seeking the version of the Agreement that applied to their account at a particular point in time, or wishing to receive a copy of the change history in another form, should contact [email protected].