Service Level Agreement

Thames International Consulting Ltd — Nigeria Electronic Invoicing Services

Version

1.0

Effective Date

May 2026

Classification

Public

Next Review

May 2027

Chapter 1 – Introduction

This Service Level Agreement (SLA) establishes the service commitments between THAMES INTERNATIONAL CONSULTING LTD ("the Service Provider") and organizations, businesses, and taxpayers ("the Customer") utilizing the Enterprise Resource Planning (ERP) platform for electronic invoicing and tax-related transactions within the Federal Republic of Nigeria.

The ERP platform enables taxpayers to generate, validate, transmit, receive, and manage electronic invoices in compliance with the Federal Inland Revenue Service (FIRS) Electronic Invoicing Framework and the Merchant Buyer Solution (MBS) integration requirements.

This SLA defines measurable service levels, operational responsibilities, security obligations, and support commitments to ensure that services are delivered in a timely, reliable, secure, and compliant manner. The document establishes standards for service availability, response times, issue resolution, system maintenance, security controls, data protection, and disaster recovery.

Chapter 2 – Purpose, Objectives & Scope

Purpose

The purpose of this Service Level Agreement is to define the minimum service commitments, responsibilities, operational standards, and performance expectations governing the delivery of the ERP electronic invoicing solution. This SLA establishes measurable service standards to ensure that the ERP platform consistently delivers reliable, secure, available, and compliant electronic invoicing services in accordance with FIRS requirements and applicable regulatory obligations.

Key Objectives

Service Reliability

Ensure uninterrupted availability through resilient infrastructure and proactive monitoring

Regulatory Compliance

Support compliance with all applicable regulations governing electronic invoicing

Secure Processing

Protect taxpayer information through industry-recognized security controls

Performance Excellence

Maintain high transaction processing performance and fast response times

Customer Satisfaction

Deliver responsive support through defined service procedures and escalation

Continuous Improvement

Review performance to identify and implement enhancement opportunities

Scope

This SLA applies to all electronic invoicing services delivered through the ERP platform to registered customers and taxpayers. Services covered include: Invoice Management, Credit and Debit Notes, Customer Management, Product Catalogues, Tax Management, Electronic Invoice Transmission, API Services, Reporting, User Administration, Audit Services, and Notification Services.

Chapter 3 – Service Description

Core Service Components

User Authentication & Identity Management

Secure authentication with MFA, SSO, and session management (99.9% availability)

Customer Management

Customer registration, profile updates, TIN management (99.9% availability)

Product & Service Catalogue

Product registration, classification, pricing, and VAT assignment

Electronic Invoice Generation

Create compliant invoices with automatic tax calculation and validation

Invoice Validation

Automated validation with field verification and compliance checks

Invoice Transmission

Secure transmission to Nigeria e-Invoicing infrastructure (≥99% success rate)

Invoice Status Tracking

Real-time visibility into invoice processing status

Credit & Debit Notes

Issue credit notes and debit notes with full audit history

Reporting & Analytics

Sales, VAT, tax, and audit reports in multiple formats

Audit Trail Service

Comprehensive logging of all user activities and transactions

Notification Service

Event notifications via email, SMS, and in-app channels

Chapter 4 – Service Availability & Performance

Monthly Availability Target

99.9%

The ERP platform shall be available to authorized users 99.9% of the time, measured on a monthly basis.

Performance Standards

FunctionTarget
User Login≤ 3 Seconds
Dashboard Load≤ 5 Seconds
Customer Search≤ 3 Seconds
Invoice Creation≤ 5 Seconds
Invoice Validation≤ 5 Seconds
Invoice Submission≤ 15 Seconds
PDF Generation≤ 10 Seconds
Report Generation≤ 30 Seconds

Planned Maintenance

Standard Maintenance Window:

Sundays between 12:00 AM and 4:00 AM (WAT)

  • 48 hours' notice required
  • Expected impact will be described
  • Completion notification will be sent

Chapter 5 – Service Support & Help Desk

Support Channels

Customer Portal

24×7

Incident logging, service requests, ticket tracking

Email

24×7

General enquiries and support requests

Telephone

24×7 Critical

Immediate technical assistance

Live Chat

Business Hours

Real-time assistance

Remote Support

As Required

Technical troubleshooting

Incident Severity & Response Times

PriorityResponseResolutionImpact
Critical15 Minutes4 HoursComplete outage
High30 Minutes24 HoursMajor functionality affected
Medium2 Hours48 HoursPartial functionality loss
Low4 Business HoursNext Business DayMinor issues

Chapter 6 – Incident Management

Incidents are detected through multiple channels including customer reports, automated monitoring, system logs, security monitoring, API monitoring, and scheduled health checks. Every incident receives a unique reference number and is tracked through the Service Management System.

Major Incident Examples:

  • Complete ERP outage
  • Failure of invoice transmission to Nigeria e-Invoicing platform
  • Authentication service failure or database corruption
  • Cybersecurity incidents affecting production systems

For Major Incidents, the Service Provider activates the Major Incident Response Team, notifies customers promptly, provides updates every 30 minutes, and produces a Post-Incident Report within 5 business days with root cause analysis and preventive measures.

Chapter 7 – Change Management

Change Categories

Standard Changes

Minimal approval

Routine, low-risk changes (user account creation, password reset, scheduled patches)

Normal Changes

Change Advisory Board

Modifications requiring formal assessment and testing (new features, API enhancements)

Emergency Changes

Documented retrospectively

Critical changes addressing incidents or security risks (security vulnerabilities, cyberattacks)

Security & Data Protection

The Service Provider implements comprehensive security controls to protect taxpayer information and ensure compliance with the Nigeria Data Protection Act (NDPA). Security measures include Multi-Factor Authentication (MFA), Transport Layer Security (TLS) encryption, Advanced Encryption Standard (AES) for data at rest, regular security audits, penetration testing, and SIEM monitoring.

All taxpayer data is protected in compliance with applicable regulations. The Service Provider implements access controls, data encryption, audit logging, and retention policies to ensure data confidentiality, integrity, and availability at all times.

Backup & Disaster Recovery

Business Continuity

The Service Provider maintains backup systems and disaster recovery capabilities to ensure business continuity in case of service disruption.

RPO (Recovery Point Objective): Maximum 1 hour data loss

RTO (Recovery Time Objective): Service restoration within 4 hours

Backup Frequency: Daily incremental, weekly full backups

Geo-Redundancy: Off-site backup storage

Chapter 10 – Customer Obligations

The Customer agrees to fulfill the following obligations to ensure optimal service delivery and compliance with this SLA:

System Access & Security

  • Maintain secure login credentials and immediately notify the Service Provider of any unauthorized access attempts
  • Implement multi-factor authentication (MFA) as recommended by the Service Provider
  • Maintain confidentiality of API keys and access tokens

Infrastructure & Connectivity

  • Provide and maintain reliable internet connectivity with sufficient bandwidth
  • Ensure network firewalls are configured to allow communication with Service Provider infrastructure
  • Maintain customer-owned hardware and local area networks (LANs)

Data & Compliance

  • Ensure all invoice data and taxpayer information are accurate and complete
  • Comply with all applicable tax regulations and reporting requirements
  • Maintain backup copies of critical business data as a supplementary measure

Support & Communication

  • Report issues promptly to the Service Provider through designated support channels
  • Provide accurate and complete information when reporting incidents
  • Designate authorized contacts for service communications and escalations

Service Usage

  • Use the ERP platform only for authorized business purposes
  • Comply with all acceptable use policies and terms of service
  • Refrain from attempting unauthorized system access, reverse engineering, or service disruption

Note: Failure to meet these obligations may impact service performance or result in service suspension. The Service Provider is not responsible for service disruptions caused by customer non-compliance with these obligations.

Chapter 11 – Termination Conditions

Either party may terminate this Service Level Agreement under the conditions outlined below. Termination does not waive any obligations or liabilities that may have accrued prior to the date of termination.

By the Customer

Standard Termination

Customer may terminate this agreement with written notice of 30 days. Final invoices will be issued for any outstanding charges through the termination date.

Termination for Material Breach

Customer may terminate immediately if the Service Provider materially breaches this SLA and fails to remedy the breach within 15 days of written notice.

Data Return

Upon termination, the Service Provider shall provide Customer with copies of all data in a standard format within 30 days.

By the Service Provider

Non-Payment

Service Provider may suspend service if fees remain unpaid for more than 30 days. Service will be terminated if payment is not received within 60 days.

Customer Breach

Service Provider may terminate if Customer materially breaches this SLA and fails to remedy within 15 days of written notice.

Regulatory Requirement

Service Provider may terminate if required by law, regulation, or government action that makes service delivery impossible.

Insolvency

Service Provider may terminate if Customer becomes insolvent, bankrupt, or subject to similar legal proceedings.

Upon Termination

  • Access Cessation: All access to the ERP platform will be terminated immediately upon effective termination date
  • Data Retrieval: Customer shall retrieve all data within 30 days; data not retrieved will be securely deleted after 90 days
  • Financial Settlement: Outstanding invoices must be paid within 30 days of termination
  • Compliance: Both parties remain bound by confidentiality and compliance obligations post-termination
  • Survival: Provisions related to confidentiality, liability, and indemnification survive termination

Chapter 12 – Terms & Conditions

Key Performance Indicators (KPIs)

KPITarget
Monthly Availability≥ 99.90%
Invoice Submission Success Rate≥ 99.00%
API Availability≥ 99.90%
Average Login Response≤ 3 Seconds
Average Invoice Processing Time≤ 15 Seconds
Failed Invoice Rate< 1%
Successful Backup Completion100%

Service Exclusions

  • Scheduled maintenance communicated in advance
  • Force majeure events (natural disasters, civil unrest, government restrictions)
  • Failures of customer-owned infrastructure or internet connectivity
  • Outages from third-party providers outside Service Provider's control
  • Customer misconfiguration or misuse of the ERP platform

Continuous Improvement

The Service Provider is committed to continually enhancing service quality through regular performance reviews, root cause analysis of incidents, customer feedback collection, security assessments, capacity planning, technology upgrades, and staff training. All improvement initiatives are documented, prioritized, tracked to completion, and reviewed for effectiveness.

Document Information

Document Owner

Service Delivery Department

Approved By

Managing Director

Review Cycle

Annual (Next: May 2027)

For questions or to request additional information about this SLA, please contact our Service Delivery Department through the support channels listed in Chapter 5.