Vault Mark
Business leaders reviewing an agency agreement beside a three-part visual for scope, data and AI control, and KPI decision rules

Executive buyer guide • Agency governance • Evidence reviewed 8 August 2026

The agency has been selected, the proposal looks sensible, and procurement is ready to move. Then the contract arrives. It promises SEO, paid media, content, AI, reporting and optimisation—but does not define what “managed” means, who approves work, who controls the accounts, whether customer data enters AI tools, which editable files are handed over, or which KPI determines whether the work should continue. This is where avoidable delivery disputes begin: not because either side intended to fail, but because the operating agreement was never made precise enough to become a shared source of truth.

Direct answer: what should an AI marketing agency contract define before work starts?

An AI marketing agency contract should make three things explicit before work begins: the agency scope of work and acceptance criteria, data and AI-tool rights including access and retention, and marketing agency KPIs with agreed data sources and decision rules. Price and contract length matter, but unclear scope, uncontrolled access and undefined metrics usually create the harder operational problems.

Important scope note

This is an operational governance and buyer-readiness guide, not legal advice and not a substitute for contract drafting by qualified counsel. PDPA roles, intellectual-property rights, liability, termination and cross-border data obligations depend on the actual agreement, actual data flows and applicable law. Use this guide to identify questions and evidence that need to be resolved before signature.

Why does an AI marketing agency contract need more operational detail?

“We use AI” is not a meaningful governance description. An agency might use AI to summarise reports, generate ideas, draft copy, analyse datasets, create images, classify leads or run automation. Those activities do not carry the same data, approval or quality risk. A buyer therefore needs to ask a more specific set of questions: which workflow uses AI, what data enters it, which vendor or workspace is used, who reviews the result, and what can be audited later?

AI-provider terms are also product-specific and can change. As one current example, OpenAI states on its Business Data Privacy page that data from its business offerings and API is not used for model training by default. Its current Services Agreement addresses rights in business-customer Input and Output. Those statements are specific to the covered OpenAI services; they are not universal rules for every AI vendor, plan or setting. The contract should therefore require the actual tool terms and data settings to be checked rather than treating labels such as “enterprise”, “private” or “secure” as sufficient evidence.

The same governance problem exists beyond AI. Advertising and measurement platforms have their own access structures. Google explains that an individual Google Ads client account retains its own campaign history when it is unlinked from a manager account, while Google Tag Manager explicitly recommends that an account be managed by someone inside the organisation rather than an outside agency. See Google Ads guidance on unlinking manager accounts and Google Tag Manager user and permission guidance. The contract implication is practical: know which business asset sits in which account, who has administrative control, and how the organisation can change suppliers without losing continuity.

If the underlying growth problem is still unclear, however, contract precision is not the first issue. A perfectly specified scope can still be the wrong scope. Vault Mark’s Customer Growth Blueprint is designed for that earlier decision: identify what is blocking growth and what should happen first before more budget, tools or execution are committed.

What are the three controls to agree before work starts?

A long contract is not automatically a controllable contract. For an executive buyer, three operating layers matter most: Scope, Data/AI Rights and KPI/Decision Rules. They need to work together rather than live in separate documents that contradict each other.

1. Scope: what will be done, when is it complete, and how is it accepted?

Service names such as SEO, paid media, content or AI optimisation are categories, not acceptance criteria. The agency scope of work should translate each category into outputs, cadence, ownership, dependencies and a definition of done. Where delivery depends on client access, product data, approval or legal review, the contract should show what happens to timing when that dependency is late.

2. Data and AI rights: what can enter a system, who controls access, and what happens afterwards?

“The client owns the data” is not enough on its own. Buyers also need to know who administers each account, which roles the agency receives, which data classes may be uploaded to which AI or third-party tool, who approves a new tool, how long data is retained, what must be deleted or returned, and what changes if a vendor processes data in another jurisdiction.

Thailand’s PDPA recognises controller and processor concepts, but the correct role in a real engagement depends on the purposes, means and actual processing activities. It should not be assigned solely from the labels “client” and “agency”. The Personal Data Protection Committee’s GPPC resources are an official starting point, but a DPO or qualified legal adviser should review material or high-risk personal-data flows.

3. KPIs: what does the metric mean, where does it come from, and what decision does it trigger?

A useful KPI has a shared definition, a source of truth, an owner and a decision rule. “Qualified Lead” should have criteria that Sales accepts, not simply mean a form submission. “Revenue from digital” should distinguish observed, sales-confirmed and modelled data where relevant. “AI visibility” should keep brand mention, direct citation and recommendation separate rather than combining them into one inflated measure.

Where measurement itself is fragmented, the contract should point to a measurement design rather than promise that another dashboard will solve the problem. Vault Mark’s AI-Data & Measurement OS describes the principle of using one signal spine and decision logic rather than disconnected reporting surfaces.

Vault Mark AI Agency Contract Control Matrix

The following matrix is a Vault Mark professional methodology for a pre-signature discussion between leadership, Marketing, Procurement, IT/Data and the agency. It is not a statutory standard and it is not a benchmark derived from a research sample. Its purpose is to turn vague language into verifiable operating evidence.

Control pointDecision to makeEvidence or contract exhibitWarning sign
1. Business outcomeWhich business problem is this engagement responsible for, and what is outside its mission?Objective statement + success conditionThe scope begins with channels but no business decision
2. DeliverablesWhat is delivered, how often, and to what minimum acceptance standard?SOW + deliverable register + acceptance criteria“Manage”, “optimise” or “support” with no inspectable output
3. Roles & approvalsWho performs, approves and is accountable for each critical step?RACI or owner mapAn account manager is named, but specialists and approvers are not
4. Platform controlWhich assets sit under a business-controlled identity, and which role is delegated to the agency?Access matrix + admin list + handover routeThe client has no administrator or cannot remove the supplier independently
5. Data classesWhich information is Public, Internal, Confidential or Personal, and where may each class be used?Data classification + approved upload rulesOnly a generic confidentiality sentence governs AI workflows
6. AI/third-party toolsWhich tools are approved, for what purpose, with which settings and review process?Tool register + purpose + data setting + reviewerThe agency may switch tools without disclosure even when data handling changes
7. Rights & licencesWho can reuse final files, editable files, prompts, outputs, templates and licensed assets?Asset-by-asset rights matrixOne broad “all IP” sentence ignores third-party licences or pre-existing IP
8. KPI definitionsHow is each metric calculated, what system is authoritative, and who validates it?Metric dictionary + data ownerThe meaning of a KPI changes between proposal and report
9. Decision cadenceWhen are results reviewed, and what conditions trigger Stop, Fix, Test or Scale?Review agenda + decision rulesMonthly reporting exists but no decision log does
10. Change controlHow is out-of-scope work approved and how does it affect cost and timing?Change-request processSmall requests accumulate without a scope or timeline reset
11. Exit & handoverWhat is returned, deleted, exported or transferred when the engagement ends?Handover checklist + formats + access-removal processThe exit plan is discussed only after termination notice

This is deliberately a control matrix rather than an agency score. Not every engagement needs the same level of governance. A project that never touches personal or confidential data can use lighter controls than a CRM, healthcare or regulated-sector workflow. The principle is that every relevant risk has a named owner and evidence that can be checked.

What does a usable agency scope of work look like?

A useful SOW answers a simple operational question: if the two parties disagree later, which document tells them what was actually agreed? A practical structure is to define six fields for each workstream: Outcome, Deliverable, Frequency, Owner, Dependency and Acceptance.

Outcome: define the problem the scope is responsible for

“Increase qualified organic demand for service X” is more useful than “improve SEO” because it tells the team that visibility has to connect to relevant commercial demand rather than to any possible traffic. When several capabilities are involved, define the role of each capability rather than presenting a service menu. That is consistent with Vault Mark’s Diagnose → Recommend → Install → Steward approach described on how Vault Mark works.

Deliverable: name what can be inspected

Examples include a technical audit, query map, campaign build sheet, landing-page specification, tracking plan, monthly decision report or content package. The SOW should state what is included and excluded without demanding disclosure of every internal agency technique. Buyers need enough detail to accept the work and manage dependencies; they do not need to own every proprietary operating method.

Acceptance: define what “done” means

Delivered and accepted are not identical. A landing page might be accepted only after copy approval, tracking-event testing, mobile QA and a working CTA. An evidence-led article might require a source log, claim review and brand approval before publication. These checks convert an activity promise into an acceptance condition.

Dependencies: name what the client must supply

Many launches slip because access, product information or feedback arrives late. Naming the client owner and due date for each dependency lets both sides discuss delay from evidence rather than memory. For multi-team workflows, an operating model such as AI-Ops OS can make ownership, approvals and recurring documentation explicit.

What should the contract say about accounts, data and AI tools?

The most useful question is not simply “who owns the data?” It is: who controls access, who may use which data for which purpose, which vendor receives it, how long it is retained, what audit trail exists, and what happens at the end of the engagement?

Separate business control from agency access

For many marketing platforms, a lower-lock-in operating model is for the organisation to retain an account or administrator it controls and delegate the agency only the access required for delivery. That is an operational recommendation, not a claim that every platform uses the same legal concept of ownership.

Google Ads, for example, distinguishes individual client accounts from manager accounts and explains that client-account history remains when a manager is unlinked. Its documentation on ownership of client accounts also distinguishes manager-account administrative privileges from the client account’s data. Google Analytics separately supports role and access management at account and property levels; see Google Analytics access and data-restriction management.

A contract-access schedule should therefore identify business-controlled administrators, agency roles, account IDs, billing dependencies, linked manager accounts, export/handover methods and the process for removing access when a person or supplier changes.

Create an Approved AI Tool Register

Instead of a clause saying that “the agency may use AI to improve efficiency”, maintain a compact register with Tool, Purpose, Data Allowed, Data Prohibited, Account/Workspace Type, Human Reviewer and Review Date. A material tool change that changes the data flow, retention or subprocessors should trigger the agreed review path rather than happen invisibly.

Vault Mark’s AI Governance, Brand Safety & Compliance OS provides a broader Do / Don’t / Human Review framework. The contract layer goes one step further by assigning responsibility between organisations: who approves a tool, who fact-checks output, who handles incidents, and who must disclose a material process change.

Classify data before anyone writes a prompt

If the team has not distinguished Public, Internal, Confidential and Personal information, even a technically strong tool can receive the wrong input. The contract should therefore connect AI use to a real data-handling rule. Work involving personal data should be reviewed with the appropriate DPO/Legal owner rather than being described with a blanket “PDPA compliant” statement that has no data-flow evidence behind it.

Vault Mark publishes its own PDPA Data Protection & Processing Terms as information about Vault Mark’s processing approach. That is useful internal context, but it does not replace case-specific legal review of another organisation’s controller/processor roles, data transfers or contract wording.

Who can use prompts, AI outputs, creative and source files after the engagement?

“The client owns the work” can still be too vague. One deliverable may contain client-provided information, newly created copy or artwork, stock or licensed material, an agency template, a prompt, workflow logic, editable source files, plugins, fonts or output from an AI vendor. Those components can have different rights and licence conditions.

OpenAI is a useful example of why vendor-specific terms matter. Its current business Services Agreement says that, as between OpenAI and the customer and to the extent permitted by law, the customer retains rights in Input and owns Output. The same agreement also notes that output may not be unique and that third-party services have their own terms. That does not tell a buyer what its agency agreement says, nor does it determine the rights for another AI vendor. It demonstrates why a rights review should identify the tool and asset type rather than rely on a single generic sentence.

A practical Rights Matrix separates at least five categories:

  • Client source material: brand files, product data, business documents and information supplied by the client.
  • Final deliverables: the agreed copy, artwork, reports, configurations or other outputs delivered to the client.
  • Editable/source files: Figma, PSD, Canva, repositories, automation configurations or other files needed for future maintenance.
  • Agency background IP: frameworks, templates, processes or reusable components that existed before the engagement.
  • Third-party/licensed material: stock assets, fonts, plugins, datasets and model/tool outputs subject to another party’s terms.

The goal is not to assume that the client must receive everything or that the agency can retain everything. The goal is to make continued use, licence limitations, export obligations and handover conditions explicit. High-value or disputed IP wording should be reviewed by qualified counsel.

How should marketing agency KPIs be defined in the contract?

Marketing agency KPIs should not be a list of isolated numerical promises. Performance depends on factors the agency may not control alone, including offer, pricing, stock, sales follow-up, approval speed and market conditions. What the operating agreement can control is the measurement language and the process used to decide what happens next.

Required fieldQuestionExample
Metric nameWhat do we call this measure?Qualified Lead
DefinitionWhat counts and what does not?Matches ICP + valid contact + passes Sales validation
Source of truthWhich system is authoritative?CRM lifecycle stage, not platform lead count
OwnerWho owns data quality?Marketing Ops + Sales Ops
CadenceWhen is it reviewed?Weekly diagnostic, monthly executive review
Decision ruleWhat action follows a meaningful change?Lead volume rises but qualification rate falls → inspect targeting/offer before scaling
LimitationWhat does this metric not prove?Platform attribution is not identical to sales-confirmed revenue

Google Analytics provides account/property access roles, but access permissions do not automatically create a shared business definition. The handoff should therefore include a Metric Dictionary beside the dashboard. Leadership, Sales and the agency should be able to read “qualified lead”, “pipeline”, “revenue”, “organic demand” or “AI citation” and mean the same thing.

For AI or automated experiments, add guardrail measures where relevant—error rate, approval failure, data-quality checks, budget limits or rollback criteria—rather than tracking upside metrics alone. Vault Mark’s AI-GrowthLab OS describes a test-and-learn model built around hypotheses, measures and guardrails.

Practical scenario: a Thai B2B manufacturer hires an agency for SEO, paid media and AI-assisted content

Consider a B2B manufacturer with a three-person marketing team and an eight-person sales team. It wants to build international pipeline. The agency proposal includes SEO, Google Ads, four articles a month, AI-assisted content production and a monthly dashboard. Price and timing are clear, but the first contract draft still has three material gaps.

  1. Scope gap: “Four articles” does not say who supplies subject-matter input, who checks technical claims, whether SEO/AEO/GEO research is included, or whether publication is included.
  2. Data/AI gap: the team is about to share a CRM export and engineering documents, but there is no approved-tool rule for identifiable contact data or confidential product information.
  3. KPI gap: the proposal has a lead target, while Sales and Marketing use different definitions of a qualified lead and there is no agreed CRM source of truth.

Using the AI Agency Contract Control Matrix, the parties can resolve those gaps before signature. The content deliverable becomes research → subject-matter input → source log → draft → human fact-check → approval → publish. The tool register prohibits identifiable CRM exports from public AI workflows unless explicitly approved under the right environment. The company retains administrator control of Ads/Analytics/GTM and delegates agency access by role. Sales approves the Qualified Lead definition, and the monthly decision rule states that if lead volume rises while opportunity rate deteriorates, the team checks ICP, offer and traffic quality before adding budget.

None of this guarantees commercial performance. It does something more defensible: it makes responsibility, evidence and decision points visible. That is the difference between a contract stored in a folder and an agreement that can actually govern the work.

What contract mistakes should buyers avoid?

  • Using service labels as scope: “SEO management” or “AI optimisation” does not define an inspectable deliverable.
  • Treating data ownership as one concept: account control, access, IP, licences, source files and retention are different questions.
  • Accepting “AI-safe” without a tool register: privacy and security behaviour depends on vendor, product, workspace and settings.
  • Leaving the agency as the only administrator: this can create lock-out and handover risk for GTM, Analytics, Ads and related assets.
  • Using KPIs without formulas or data sources: different teams can report different versions of “lead” or “revenue”.
  • Having no change-control process: scope expands one “small request” at a time while cost and timeline assumptions stay frozen.
  • Designing exit only after notice is served: teams discover too late that exports, source files or administrative access were never agreed.
  • Using AI-generated legal wording without accountable review: AI can help organise questions, but legally operative wording should be reviewed by a qualified professional responsible for the specific contract.

What 15 questions should you answer before signing an AI marketing agency contract?

  1. What is the dominant business decision this engagement is meant to support?
  2. What is explicitly in scope, and what is explicitly excluded?
  3. What are the acceptance criteria for each material deliverable?
  4. Who is the owner, approver and escalation contact for each critical workstream?
  5. Which client access, data and approvals are dependencies, and what happens if they are late?
  6. Are Ads, GA4, GTM, website, domain, CRM and repositories controlled by business-managed accounts where appropriate?
  7. Which access role does the agency receive, and who can change or remove it?
  8. Which AI and third-party tools are approved for real production work?
  9. Which data classes are prohibited from each tool?
  10. Are retention, deletion, export and incident-handling processes documented?
  11. How can each final deliverable, source file, prompt, template and licensed asset be used after the engagement?
  12. Does every KPI have a definition, formula and source of truth?
  13. Does the reporting cadence end with a decision and owner, not just a performance summary?
  14. How are out-of-scope requests approved and priced, and how do they affect timing?
  15. At exit, which accounts, history, files, configurations and documentation must be handed over?

If most of these answers already exist in the proposal, SOW, access matrix, tool/data register and metric dictionary, the agreement is beginning to function as an operating system. If the answers exist only in meeting memory or chat messages, the main risk is still shared interpretation rather than shared evidence.

Assumptions, limitations and source notes

Assumption: this guide addresses a typical Thai business buying digital and AI-enabled marketing services. It is not designed to replace procurement standards for public companies, government projects, financial institutions, hospitals or other regulated environments.

Limitation: platform permissions, AI-vendor terms, retention settings and laws can change. Recheck the current source documents on the signing date. Legal/DPO review is particularly important where work involves personal or sensitive data, cross-border transfers, regulated claims or high-value intellectual property.

Verified facts used: Google Ads, Google Analytics and Google Tag Manager expose documented account/access structures; OpenAI publishes business-data and customer-content terms for covered business services; Thailand’s PDPC publishes official compliance resources.

Professional recommendations: the AI Agency Contract Control Matrix, Approved Tool Register, Rights Matrix and Metric Dictionary are Vault Mark methodologies intended to improve buyer governance. They are not statutory requirements or statistical research findings.

What is the next decision: fix the contract, or first decide what the agency should actually do?

If the business problem and required scope are already clear, use this matrix to review the AI marketing agency contract with the Agency, Procurement, IT/Data and Legal/DPO teams and close governance gaps before signature. Then make the access schedule, tool register, metric dictionary and handover checklist part of the working agreement rather than leaving them as informal assumptions.

If leadership is still debating whether the priority is SEO, Ads, Content, CRM, Website or AI, do not over-engineer a contract around an uncertain scope. Start with the Customer Growth Blueprint to identify the constraint and priority first. The contract can then be designed around the business decision rather than around a list of services.

Before signing, make the documents answer three questions

What work are we buying that can be accepted? How are data and AI tools controlled? Which KPI will cause us to Stop, Fix, Test or Scale? If the agreement cannot answer those questions without relying on somebody’s memory, it is not yet ready to govern the work.

Review Vault Mark’s growth strategy and digital performance approach or examine selected work and operating context when evaluating fit.

Published for business information, not legal advice • Recheck vendor terms and official guidance before contract signature • Last evidence review: 8 August 2026

Facebook
Threads
X
LinkedIn
Reddit
Telegram