contract-review-checklist

Systematic contract review checklist — evaluating liability, IP ownership, data handling, termination clauses, SLAs, and compliance requirements with risk-rated findings and suggested protective language.

Contract Review Checklist

Before you start

Gather the following from the user. If anything is missing, ask before proceeding:

  1. What type of contract? (SaaS agreement, vendor contract, partnership, NDA, MSA)
  2. Which party are you? (Customer, vendor, partner — your review posture changes)
  3. What is the contract value? (Determines acceptable risk tolerance)
  4. What data is involved? (PII, PHI, financial data, trade secrets, none)
  5. What regulatory frameworks apply? (GDPR, HIPAA, SOC 2, industry-specific)
  6. Are there existing terms to compare against? (Prior version, your standard template)

This skill produces a structured review with risk-rated findings. It is not legal advice. Flag findings rated High or Critical for legal counsel review.

Review template

1. Contract Summary

Contract Type:   [SaaS Subscription Agreement]
Parties:         [Your Company] ("Customer") and [Vendor] ("Provider")
Term:            [Initial term + renewal terms]
Total Value:     [Annual or total contract value]
Review Date:     [Date]

2. Liability and Indemnification

ClauseSectionCurrent LanguageRiskRecommendation
Liability cap7.112 months of fees paidLowAcceptable — standard for SaaS
Indemnification scope8.1Vendor indemnifies IP onlyHighAdd data breach indemnification
Consequential damages7.3Mutual waiverLowStandard — acceptable

Red flags: liability cap below contract value, one-sided indemnification, no carve-outs for gross negligence or willful misconduct.

3. Intellectual Property

IssueSectionStatusRiskNotes
IP ownership of outputs4.1Customer ownsLowVerify includes derivatives
License to customer data4.3Broad licenseHighNarrow to service delivery only
Work product rights4.4Not addressedCritMust add assignment clause

Key questions: Who owns work product? Does the vendor retain rights to use your data for training or benchmarking? Are license grants surviving termination?

4. Data Handling and Privacy

RequirementSectionAdequate?Gap
Data processing terms9.1PartialMissing subprocessor notification
Breach notification9.3NoTimeline is 30 days — require 72 hrs
Data return/deletion9.4Yes30-day post-termination window
Encryption standards9.5N/AAdd at-rest and in-transit minimums

If the contract involves PII or regulated data and lacks a Data Processing Agreement, flag as Critical.

5. Service Levels and Remedies

SLA MetricCommitmentRemedyRisk
Uptime99.9%5% credit per 0.1%Low
Response timeNot definedNoneHigh
RTO/RPONot definedNoneCrit

Verify: Are credits the sole remedy, or can you terminate for persistent SLA failures? Does the vendor self-report uptime?

6. Termination and Exit

ProvisionTermsRiskNotes
Termination for convenienceNot permittedHighAdd with 90-day notice
Data portabilityCSV export availableMedRequire API access + format
Transition assistanceNot addressedHighAdd 90-day transition period

If you cannot exit the contract within a reasonable timeframe with your data intact, the contract creates vendor lock-in.

7. Findings Summary

Compile all findings prioritized by risk:

#FindingRiskSectionAction Required
1No work product IP assignmentCrit4.4Add IP assignment clause
2No RTO/RPO commitmentsCrit6.3Define recovery objectives
3Broad license to customer dataHigh4.3Narrow to service delivery

Quality checklist

Before delivering a contract review, verify:

  • Every finding cites a specific section number or notes the clause is missing
  • Risk ratings are consistent — Critical means business-threatening, not inconvenient
  • IP ownership is reviewed for both pre-existing IP and work product
  • Data handling covers processing terms, breach notification, and post-termination deletion
  • SLAs have measurable commitments with defined remedies
  • Termination provisions include data portability and transition assistance
  • Findings summary is prioritized with specific recommended actions

Common mistakes

  • Reviewing only what is written. Missing clauses are findings. No SLA, no data deletion — these omissions are risks.
  • Treating all risks as equal. A missing comma is not the same risk as unlimited liability. Rate findings consistently.
  • Ignoring the "other party" position. If you are the vendor, customer-favorable terms are your risk. Adjust review posture to your role.
  • Skipping auto-renewal terms. Contracts that silently renew with uncapped price increases are expensive surprises.
  • Reviewing without context. A $5K SaaS tool and a $2M infrastructure contract require different risk tolerances.
  • Not flagging missing DPAs. If personal data is processed without a Data Processing Agreement, this is a regulatory gap.