Service Level Agreement
Thames International Consulting Ltd — Nigeria Electronic Invoicing Services
Version
1.0
Effective Date
May 2026
Classification
Public
Next Review
May 2027
Table of Contents
Chapter 1
Introduction
Chapter 2
Purpose & Scope
Chapter 3
Service Description
Chapter 4
Service Availability
Chapter 5
Service Support
Chapter 6
Incident Management
Chapter 7
Change Management
Chapter 8
Security & Data Protection
Chapter 9
Business Continuity
Chapter 10
Customer Obligations
Chapter 11
Termination Conditions
Chapter 12
Terms & Conditions
Chapter 1 – Introduction
This Service Level Agreement (SLA) establishes the service commitments between THAMES INTERNATIONAL CONSULTING LTD ("the Service Provider") and organizations, businesses, and taxpayers ("the Customer") utilizing the Enterprise Resource Planning (ERP) platform for electronic invoicing and tax-related transactions within the Federal Republic of Nigeria.
The ERP platform enables taxpayers to generate, validate, transmit, receive, and manage electronic invoices in compliance with the Federal Inland Revenue Service (FIRS) Electronic Invoicing Framework and the Merchant Buyer Solution (MBS) integration requirements.
This SLA defines measurable service levels, operational responsibilities, security obligations, and support commitments to ensure that services are delivered in a timely, reliable, secure, and compliant manner. The document establishes standards for service availability, response times, issue resolution, system maintenance, security controls, data protection, and disaster recovery.
Chapter 2 – Purpose, Objectives & Scope
Purpose
The purpose of this Service Level Agreement is to define the minimum service commitments, responsibilities, operational standards, and performance expectations governing the delivery of the ERP electronic invoicing solution. This SLA establishes measurable service standards to ensure that the ERP platform consistently delivers reliable, secure, available, and compliant electronic invoicing services in accordance with FIRS requirements and applicable regulatory obligations.
Key Objectives
Service Reliability
Ensure uninterrupted availability through resilient infrastructure and proactive monitoring
Regulatory Compliance
Support compliance with all applicable regulations governing electronic invoicing
Secure Processing
Protect taxpayer information through industry-recognized security controls
Performance Excellence
Maintain high transaction processing performance and fast response times
Customer Satisfaction
Deliver responsive support through defined service procedures and escalation
Continuous Improvement
Review performance to identify and implement enhancement opportunities
Scope
This SLA applies to all electronic invoicing services delivered through the ERP platform to registered customers and taxpayers. Services covered include: Invoice Management, Credit and Debit Notes, Customer Management, Product Catalogues, Tax Management, Electronic Invoice Transmission, API Services, Reporting, User Administration, Audit Services, and Notification Services.
Chapter 3 – Service Description
Core Service Components
User Authentication & Identity Management
Secure authentication with MFA, SSO, and session management (99.9% availability)
Customer Management
Customer registration, profile updates, TIN management (99.9% availability)
Product & Service Catalogue
Product registration, classification, pricing, and VAT assignment
Electronic Invoice Generation
Create compliant invoices with automatic tax calculation and validation
Invoice Validation
Automated validation with field verification and compliance checks
Invoice Transmission
Secure transmission to Nigeria e-Invoicing infrastructure (≥99% success rate)
Invoice Status Tracking
Real-time visibility into invoice processing status
Credit & Debit Notes
Issue credit notes and debit notes with full audit history
Reporting & Analytics
Sales, VAT, tax, and audit reports in multiple formats
Audit Trail Service
Comprehensive logging of all user activities and transactions
Notification Service
Event notifications via email, SMS, and in-app channels
Chapter 4 – Service Availability & Performance
Monthly Availability Target
99.9%
The ERP platform shall be available to authorized users 99.9% of the time, measured on a monthly basis.
Performance Standards
| Function | Target |
|---|---|
| User Login | ≤ 3 Seconds |
| Dashboard Load | ≤ 5 Seconds |
| Customer Search | ≤ 3 Seconds |
| Invoice Creation | ≤ 5 Seconds |
| Invoice Validation | ≤ 5 Seconds |
| Invoice Submission | ≤ 15 Seconds |
| PDF Generation | ≤ 10 Seconds |
| Report Generation | ≤ 30 Seconds |
Planned Maintenance
Standard Maintenance Window:
Sundays between 12:00 AM and 4:00 AM (WAT)
- •48 hours' notice required
- •Expected impact will be described
- •Completion notification will be sent
Chapter 5 – Service Support & Help Desk
Support Channels
Customer Portal
24×7Incident logging, service requests, ticket tracking
General enquiries and support requests
Telephone
24×7 CriticalImmediate technical assistance
Live Chat
Business HoursReal-time assistance
Remote Support
As RequiredTechnical troubleshooting
Incident Severity & Response Times
| Priority | Response | Resolution | Impact |
|---|---|---|---|
| Critical | 15 Minutes | 4 Hours | Complete outage |
| High | 30 Minutes | 24 Hours | Major functionality affected |
| Medium | 2 Hours | 48 Hours | Partial functionality loss |
| Low | 4 Business Hours | Next Business Day | Minor issues |
Chapter 6 – Incident Management
Incidents are detected through multiple channels including customer reports, automated monitoring, system logs, security monitoring, API monitoring, and scheduled health checks. Every incident receives a unique reference number and is tracked through the Service Management System.
Major Incident Examples:
- •Complete ERP outage
- •Failure of invoice transmission to Nigeria e-Invoicing platform
- •Authentication service failure or database corruption
- •Cybersecurity incidents affecting production systems
For Major Incidents, the Service Provider activates the Major Incident Response Team, notifies customers promptly, provides updates every 30 minutes, and produces a Post-Incident Report within 5 business days with root cause analysis and preventive measures.
Chapter 7 – Change Management
Change Categories
Standard Changes
Minimal approvalRoutine, low-risk changes (user account creation, password reset, scheduled patches)
Normal Changes
Change Advisory BoardModifications requiring formal assessment and testing (new features, API enhancements)
Emergency Changes
Documented retrospectivelyCritical changes addressing incidents or security risks (security vulnerabilities, cyberattacks)
Security & Data Protection
The Service Provider implements comprehensive security controls to protect taxpayer information and ensure compliance with the Nigeria Data Protection Act (NDPA). Security measures include Multi-Factor Authentication (MFA), Transport Layer Security (TLS) encryption, Advanced Encryption Standard (AES) for data at rest, regular security audits, penetration testing, and SIEM monitoring.
All taxpayer data is protected in compliance with applicable regulations. The Service Provider implements access controls, data encryption, audit logging, and retention policies to ensure data confidentiality, integrity, and availability at all times.
Backup & Disaster Recovery
Business Continuity
The Service Provider maintains backup systems and disaster recovery capabilities to ensure business continuity in case of service disruption.
RPO (Recovery Point Objective): Maximum 1 hour data loss
RTO (Recovery Time Objective): Service restoration within 4 hours
Backup Frequency: Daily incremental, weekly full backups
Geo-Redundancy: Off-site backup storage
Chapter 10 – Customer Obligations
The Customer agrees to fulfill the following obligations to ensure optimal service delivery and compliance with this SLA:
System Access & Security
- •Maintain secure login credentials and immediately notify the Service Provider of any unauthorized access attempts
- •Implement multi-factor authentication (MFA) as recommended by the Service Provider
- •Maintain confidentiality of API keys and access tokens
Infrastructure & Connectivity
- •Provide and maintain reliable internet connectivity with sufficient bandwidth
- •Ensure network firewalls are configured to allow communication with Service Provider infrastructure
- •Maintain customer-owned hardware and local area networks (LANs)
Data & Compliance
- •Ensure all invoice data and taxpayer information are accurate and complete
- •Comply with all applicable tax regulations and reporting requirements
- •Maintain backup copies of critical business data as a supplementary measure
Support & Communication
- •Report issues promptly to the Service Provider through designated support channels
- •Provide accurate and complete information when reporting incidents
- •Designate authorized contacts for service communications and escalations
Service Usage
- •Use the ERP platform only for authorized business purposes
- •Comply with all acceptable use policies and terms of service
- •Refrain from attempting unauthorized system access, reverse engineering, or service disruption
Note: Failure to meet these obligations may impact service performance or result in service suspension. The Service Provider is not responsible for service disruptions caused by customer non-compliance with these obligations.
Chapter 11 – Termination Conditions
Either party may terminate this Service Level Agreement under the conditions outlined below. Termination does not waive any obligations or liabilities that may have accrued prior to the date of termination.
By the Customer
Standard Termination
Customer may terminate this agreement with written notice of 30 days. Final invoices will be issued for any outstanding charges through the termination date.
Termination for Material Breach
Customer may terminate immediately if the Service Provider materially breaches this SLA and fails to remedy the breach within 15 days of written notice.
Data Return
Upon termination, the Service Provider shall provide Customer with copies of all data in a standard format within 30 days.
By the Service Provider
Non-Payment
Service Provider may suspend service if fees remain unpaid for more than 30 days. Service will be terminated if payment is not received within 60 days.
Customer Breach
Service Provider may terminate if Customer materially breaches this SLA and fails to remedy within 15 days of written notice.
Regulatory Requirement
Service Provider may terminate if required by law, regulation, or government action that makes service delivery impossible.
Insolvency
Service Provider may terminate if Customer becomes insolvent, bankrupt, or subject to similar legal proceedings.
Upon Termination
- •Access Cessation: All access to the ERP platform will be terminated immediately upon effective termination date
- •Data Retrieval: Customer shall retrieve all data within 30 days; data not retrieved will be securely deleted after 90 days
- •Financial Settlement: Outstanding invoices must be paid within 30 days of termination
- •Compliance: Both parties remain bound by confidentiality and compliance obligations post-termination
- •Survival: Provisions related to confidentiality, liability, and indemnification survive termination
Chapter 12 – Terms & Conditions
Key Performance Indicators (KPIs)
| KPI | Target |
|---|---|
| Monthly Availability | ≥ 99.90% |
| Invoice Submission Success Rate | ≥ 99.00% |
| API Availability | ≥ 99.90% |
| Average Login Response | ≤ 3 Seconds |
| Average Invoice Processing Time | ≤ 15 Seconds |
| Failed Invoice Rate | < 1% |
| Successful Backup Completion | 100% |
Service Exclusions
- •Scheduled maintenance communicated in advance
- •Force majeure events (natural disasters, civil unrest, government restrictions)
- •Failures of customer-owned infrastructure or internet connectivity
- •Outages from third-party providers outside Service Provider's control
- •Customer misconfiguration or misuse of the ERP platform
Continuous Improvement
The Service Provider is committed to continually enhancing service quality through regular performance reviews, root cause analysis of incidents, customer feedback collection, security assessments, capacity planning, technology upgrades, and staff training. All improvement initiatives are documented, prioritized, tracked to completion, and reviewed for effectiveness.
Document Information
Document Owner
Service Delivery Department
Approved By
Managing Director
Review Cycle
Annual (Next: May 2027)
For questions or to request additional information about this SLA, please contact our Service Delivery Department through the support channels listed in Chapter 5.