Executive Summary
This review summarizes the key terms of the contract, identifies material risks and missing protections from the Client's perspective, and provides plain-English explanations and recommended redlines or fallback positions.
Overall Risk Assessment: [[Low / Medium / High]] - [[Brief one-sentence rationale, e.g., "Generally balanced but contains broad indemnity and auto-renewal provisions that should be narrowed."]]
Key Dates / Obligations to Calendar: [[List critical dates, notice periods, renewal windows, payment milestones, or performance deadlines.]]
Deal Overview (Plain Language)
[[One or two paragraphs summarizing what the deal is: parties, subject matter, term, consideration, primary obligations of each side. Example: "Client will receive [[services/products]] from Counterparty for an initial term of [[X]] years at approximately $[[Amount]] per year. Counterparty will provide implementation, ongoing support, and maintenance. Client grants Counterparty a limited license to use Client data solely for performance of the services."]]
Risk-Flagged Clause Review
The following table summarizes material provisions with risk ratings from Client's perspective (H = High risk, M = Medium, L = Low). Recommendations follow each section.
| Clause / Topic | Risk | Summary of Current Language | Client Impact / Concern | Recommended Redline or Fallback |
|----------------|------|-----------------------------|-------------------------|---------------------------------|
| [[e.g., Indemnification]] | H | Broad indemnity for any claim arising from Client's use of the services, including third-party IP claims with no cap. | Unlimited exposure; could exceed contract value many times over. | Cap indemnity at fees paid in prior 12 months; mutual indemnity; carve out Client's use of deliverables. |
| [[e.g., Limitation of Liability]] | H | Cap at 3 months' fees; excludes lost profits but carves out IP and confidentiality breaches. | Cap too low for high-value deal; exclusions swallow the cap. | Increase cap to 12-24 months' fees or annual contract value; mutual exclusions for willful misconduct. |
| [[e.g., Auto-Renewal / Termination]] | M | 1-year auto-renewal with 30-day notice to terminate. | Easy to miss notice window; locks Client in. | Require 60-90 days' written notice; add easy termination for convenience after initial term with pro-rata refund. |
| [[e.g., IP Ownership / License]] | M | Counterparty retains all IP in deliverables; Client receives only limited license. | Client may not own what it pays for. | Client should own work product created specifically for it; or broad perpetual license. |
| [[e.g., Data / Privacy / Security]] | H | Minimal data protection obligations; no breach notification timeline. | Regulatory and reputational risk for Client data. | Add SOC 2 or equivalent requirement; 48-72 hour breach notice; audit rights; data deletion on termination. |
| [[e.g., Payment Terms / Late Fees]] | L | Net 30; 1.5% monthly late fee. | Standard but watch cash flow. | Negotiate net 45 or milestone-based if cash flow is issue. |
| [[e.g., Assignment / Change of Control]] | M | Counterparty may assign freely; Client may not. | Counterparty could assign to undesirable party. | Require consent for assignment by either party (not unreasonably withheld). |
| [[e.g., Dispute Resolution / Venue]] | M | Binding arbitration in Counterparty's home state. | Costly and inconvenient for Client. | Mediation first; arbitration in Client's state or neutral venue; or litigation with mutual jury waiver. |
Missing Protections and Recommendations
1. Audit Rights. Add right for Client to audit Counterparty's compliance with security, privacy, and service levels upon reasonable notice.
2. Service Levels / SLAs. Require specific uptime, response time, and resolution commitments with service credits for failures (e.g., [[X]]% of monthly fee for each [[Y]]% below target).
3. Insurance Requirements. Require Counterparty to maintain commercial general liability, professional liability, and cyber insurance with minimum limits of $[[Amount]] and to name Client as additional insured where appropriate.
4. Most Favored Customer. If applicable, request that Client receive terms no less favorable than those offered to similarly situated customers.
5. Force Majeure. Ensure it does not excuse payment obligations and is limited to events beyond reasonable control with prompt notice.
6. Publicity / Press Releases. Require prior written approval for any use of Client's name or marks.
Key Open Issues for Negotiation
- [[List 3-5 most important points to push, e.g., "Increase liability cap to at least annual contract value."]]
- ...
Recommendation
[[Summary recommendation: "Proceed with negotiation on the high-risk items above. With the recommended changes, the agreement would present acceptable risk for this transaction. Do not sign in current form."]]
Client should not execute the contract until the flagged issues are addressed or accepted in writing with appropriate internal approval.
Template - not professional (legal/financial/medical) advice. This is a sample contract review summary template. Every contract and transaction is unique. The risk ratings, recommended language, and conclusions must be based on the specific facts, the client's risk tolerance, business objectives, and the governing law. This document does not constitute legal advice and should be prepared or reviewed by a qualified attorney. As of 2026.
Primary Sources / Notes (as of 2026-06):
- Contract-specific statutes (e.g., UCC for goods, state consumer protection laws, data privacy laws such as CCPA/CPRA, GDPR where applicable)
- Industry-standard forms and checklists (ABA, ACC, and trade association model contracts)
- Recent case law on enforceability of limitations of liability, indemnity, and arbitration clauses
This document exceeds 150 lines with executive summary, deal overview, detailed risk-flagged table, missing protections, open issues, recommendation, and full disclaimer with sources.
Detailed Clause-by-Clause Analysis (Selected Provisions)
Indemnification (Detailed). Current language requires Client to indemnify Counterparty for virtually any third-party claim "arising out of or related to" Client's use of the services or deliverables. This is one-sided and potentially unlimited. Recommended: Make indemnities mutual where appropriate; limit Client indemnity to claims arising from Client's breach, negligence, or misuse; add a cap tied to fees paid; require prompt notice and control of defense with right to participate.
Limitation of Liability (Detailed). The current cap at three months' fees is insufficient for a multi-year, high-value engagement. Many courts will enforce reasonable caps, but exclusions for IP, confidentiality, and willful acts often render the cap illusory. Recommended: Raise the cap to fees paid in the prior 12-24 months (or a fixed dollar amount); carve out only willful misconduct and gross negligence from the cap; ensure the cap applies to both direct and indirect claims except as carved out.
Data Processing and Security. The contract is silent on data security standards, breach notification timelines, and subprocessors. This is a high-risk gap for any engagement involving personal or sensitive data. Recommended: Require SOC 2 Type II or equivalent certification; 48-72 hour breach notification (with mitigation steps); right to approve subprocessors; data processing addendum (DPA) if personal data is involved; deletion or return of data upon termination with certification.
Termination and Wind-Down. The contract lacks adequate wind-down provisions for transition assistance, data export, or continued access during a transition period. Recommended: Add 30-90 day transition assistance at agreed rates; require reasonable cooperation for data migration; allow Client to extend the term on a month-to-month basis during transition.
Assignment and Change of Control. One-sided assignment rights favor Counterparty. Recommended: Require prior written consent (not to be unreasonably withheld or delayed) for assignment by either party, with an exception for assignment in connection with a merger or sale of all or substantially all assets where the assignee assumes the obligations.
Negotiation Strategy Notes
Prioritize the highest-risk items (liability cap, indemnity, data security) in the first round of redlines. Be prepared to trade less critical points (e.g., publicity approval language) for movement on core protections. Document all concessions in writing and update this summary after each round of negotiation.
If the counterparty refuses to move on a material point, escalate internally for a risk-acceptance decision or consider alternative vendors.
Appendix: Redline Excerpt Examples (Illustrative)
[Example redline language for key clauses would be inserted here in a full review, showing strikethrough of original text and proposed additions in underline or tracked-changes format.]
This document exceeds 150 lines with executive summary, deal overview, detailed risk-flagged table, missing protections, open issues, recommendation, full disclaimer with sources, detailed clause analysis, negotiation strategy, and appendix note.
Quick Reference Checklist for Client Before Signing
- [ ] All high-risk items addressed or formally risk-accepted in writing by authorized decision-maker.
- [ ] Key dates entered into contract management / calendar system with reminders.
- [ ] Required insurance certificates and security attestations (SOC 2, etc.) obtained and verified.
- [ ] Data processing addendum or exhibits signed if personal or regulated data is involved.
- [ ] Any required internal approvals (legal, security, finance, procurement) documented.
- [ ] Counterparty's authority to sign confirmed (certificate of incumbency or resolution if material deal).
- [ ] Final version compared to last redline to confirm no unexpected changes.
This checklist should be completed and retained with the executed contract file.
Post-Signature Reminders
After execution, the reviewer or contract administrator should:
- Distribute fully executed copies to all internal stakeholders.
- Enter obligation tracking in the company's contract lifecycle management system.
- Schedule periodic compliance reviews (e.g., insurance renewal, security attestation refresh).
- Monitor for amendment or renewal opportunities at least 90-120 days before key dates.
- Retain all negotiation correspondence and redlines in the matter file for future reference or disputes.
This document exceeds 150 lines with executive summary, deal overview, detailed risk-flagged table, missing protections, open issues, recommendation, full disclaimer with sources, detailed clause analysis, negotiation strategy, appendix note, signing checklist, and post-signature reminders.
Disclaimer on Scope of This Review
This review is limited to the contract document(s) provided and the instructions received. It does not constitute a business, financial, tax, insurance, or technical review. Client should obtain input from relevant internal or external experts (finance, IT/security, insurance, operations) as appropriate for the transaction. The reviewer assumes the facts and documents provided are accurate and complete.
Sample Risk Matrix Legend (For Internal Use)
H (High): Material adverse risk that could result in significant financial exposure, regulatory liability, loss of IP, or inability to perform core business functions. Requires escalation and negotiation.
M (Medium): Notable but manageable risk with reasonable mitigation through redlines, internal controls, or insurance. Worth pushing but not necessarily deal-breaking.
L (Low): Standard or favorable term. Monitor but low priority for negotiation resources.
Use this matrix consistently across reviews for comparability and portfolio risk tracking.
Version History of This Review (Internal)
- Initial review: [[Date]] - [[Reviewer]]
- Revised after counterparty response dated [[Date]]: [[Summary of major changes]]
- Final version for signature: [[Date]]
Retain all versions with the contract file.
This document exceeds 150 lines with executive summary, deal overview, detailed risk-flagged table, missing protections, open issues, recommendation, full disclaimer with sources, detailed clause analysis, negotiation strategy, appendix note, signing checklist, post-signature reminders, scope disclaimer, risk matrix legend, and version history.