Skip to content
97.5% of teams see value from GC AI before month oneSee how

Contract Review Checklist for In-House Counsel: 7 Stages


Josh Bertini

Maury Bricks,General CounselatARKO Corp, did not start out wanting a contract review checklist. He started out proud of avoiding AI entirely. On theCZ and Friends podcast, GC AI’s show hosted by CEO and three-time general counsel Cecilia Ziniti, he described the moment a colleague changed his mind:

“I was not using AI, proudly staying away fromChatGPTand everything, saying, you know, not needed. I’m smart, I can do my work. And Michele showed me. I love how I type in ‘please redline this document’ and then press Easy Prompt, and it’s like, did you mean you wanted to know these 40 things? And I’m like, yes, that’s exactly what I wanted. I wanted to know those 40 things.”

Those 40 things are a contract review checklist, and every in-house lawyer runs one on every agreement, whether it lives in your head, on a Word template, or inside a legal AI platform. Writing it down is what turns reading a contract into reviewing one, and it keeps a buried indemnity or an auto-renewal from reaching the CEO’s desk unflagged.

Below is a complete, copy-ready contract review checklist for in-house counsel, built the way the work moves: triage first, the risk clauses next, the counterparty’s paper after that. World Commerce and Contracting estimates (2020) that weak contractingerodes roughly 9% of annual revenuethrough missed entitlements, scope disputes, and avoidable risk. A checklist is the cheapest insurance against that leakage.

The In-House Contract Review Checklist

A contract review checklist is a written set of items an in-house legal team verifies on every incoming agreement, organized so that the highest-risk terms get attention first. The point of the sequence is leverage: you spend your scarce attention where the dollars and the liability live, and you let a repeatable process carry the rest. The seven stages below run in review order, so use the list as a quick index, then work through the specific items under each one.

Triage the contract by risk

Confirm the parties, term, and renewal

Pin down the commercial terms

Flag the risk-allocation clauses

Check the counterparty’s paper for red flags

Redline against your playbook and fallbacks

Route for approval and signature

Triage the Contract by Risk

Decide how hard to look before you start reading. Sort each incoming contract into a risk tier by dollar value, data sensitivity, term length, and whether it uses your paper or the counterparty’s. A mutualNDAon your template is a five-minute review; a three-year data processing agreement with uncapped liability is not. Triage is what keeps a lean team from giving a renewal the same hour it gives a bet-the-company deal.

Confirm which side’s template the contract sits on

Note the total contract value and payment exposure

Flag whether the deal touches personal data, IP, or regulated activity

Set a review depth and turnaround based on the tier

Confirm the Parties, Term, and Renewal

Verify who is bound and for how long. Check that the named entities match the signing parties, that the effective date and term are unambiguous, and that renewal is something you control. Auto-renewal with a 90-day notice window is one of the most common ways companies stay locked into vendors they meant to leave. In a 2021 agreement betweenCenntro Electric Groupand a European counterparty, the renewal term reads: “the term of this Agreement will automatically renew for additional successive one (1) year terms unless either Party provides written Notice of non-renewal at least ninety (90) days prior to the end of the then-current term.” Miss that 90-day window and you are locked in for another full year.

Correct legal entity names and signing authority

Effective date, initial term, and renewal mechanics

Notice period required to prevent auto-renewal

Assignmentandchange-of-controlrights

Pin Down the Commercial Terms

Read the money before the boilerplate. Confirm pricing, payment timing, and any caps or escalators match the business deal, and that service levels and remedies are spelled out in writing.

Pricing, fees, and any annual escalators

Payment terms and late-payment consequences

Service levels, credits, and remedies

Expense, pass-through, and reimbursement terms

Flag the Risk-Allocation Clauses

This is the heart of any contract review checklist: the clauses that decide who pays when something goes wrong. Read each one against your company’s standard position, and note where the draft departs from it. These eight carry most of the risk in a commercial agreement:

ClauseWhat to verifyRed flag to escalate
IndemnificationWho covers whom, for what, and with what carve-outsOne-way indemnity, or carve-outs that gut the protection
Limitation of liabilityThe cap, the exclusions, and whether it is mutualNo cap, or a cap that excludes the claims you are most likely to face
Intellectual propertyOwnership of deliverables, license scope, and feedback rightsThe counterparty claiming ownership of your inputs or outputs
ConfidentialityDefinition, duration, and permitted disclosuresA short or one-sided confidentiality term
Data protectionThe DPA, security obligations, breach notice, and sub-processorsNo DPA, or breach notice measured in weeks
Warranties and representationsWhat each side promises and for how longA blanket as-is disclaimer on a critical service
Termination and survivalFor cause, for convenience, and what lives on afterNo termination for convenience, or survival with no end date
Governing law and dispute resolutionVenue, arbitration, and fee-shiftingA hostile venue, or mandatory arbitration with fee-shifting against you

The label matters less than the balance. In a 2024 consulting agreement betweenCaterpillar and Suzette M. Long, the indemnity runs both ways: “Each party shall indemnify, defend, and hold harmless the other party, along with its affiliates, directors, officers, employees and agents from and against any and all suits, claims, demands, losses, damages, costs and expenses.” Mutual is the position to anchor on, so flag any one-way version that protects the counterparty alone.

For deeper, clause-by-clause review of specific agreement types, see theSaaS agreement checklistand thevendor agreement review workflow.

Check the Counterparty’s Paper for Red Flags

When you are reviewing the other side’s template, the work shifts from confirming your terms to catching theirs. Counterparty paper favors the counterparty by design, so scan for the patterns that move risk onto you.

Uncapped liability, or carve-outs that swallow the cap

One-sided or asymmetric indemnification

Auto-renewal paired with a long notice window

Unilateral amendment rights (“we may update these terms”)

Assignment without consent

Missing clauses entirely, such as a confidentiality or data protection section that should be there

Tiffany Lee, General Counsel and Corporate Secretary atLiquid Death, described how she handles that last one:

“If it sees a missing confidentiality clause, I’ll just ask it to draft one I can drop right into the agreement, no leaving the system, no reformatting.”

Catching a missing clause is harder than reviewing a present one, because there is no text to react to. A written checklist is what surfaces the gap, and it is the reason “what is not here?” belongs on every review.

Redline against Your Playbook and Fallbacks

Mark up the contract against your standard positions so each pass starts from a known baseline. Your playbook holds the preferred language, the acceptable fallback, and the walk-away line for each key clause, so redlining becomes a matter of matching the draft to a position you can reuse on every deal. This is whereAI contract redlining softwareearns its keep, carrying your standard markup into Word automatically.

Apply preferred and fallback language for each flagged clause

Note your walk-away positions before negotiation starts

Keep comments tied to specific contract language

Track which positions you conceded for the next renewal

Route for Approval and Signature

Close the loop with clear escalation thresholds. Define which terms a reviewer can approve alone and which require finance, security, or the GC, so nothing ships above someone’s authority and nothing waits on the GC that did not need to.

Approval thresholds by dollar value and risk tier

Required sign-offs from finance, security, or privacy

Final version control and clean execution copy

Storage and key-date tracking after signature

A Contract Review Checklist by Contract Type

The seven stages hold for any agreement, but the clauses that matter most shift by contract type. A few quick variants:

NDAs: Definition of confidential information, term of the obligation, permitted disclosures, return-or-destroy requirements, and whether it is mutual.

SaaS and MSAs: Service levels and credits, data protection and security, liability cap relative to fees paid, IP and usage rights, and renewal mechanics. TheSaaS agreement checklistbreaks down the six clauses that carry the risk.

Vendor and procurement contracts: Pricing and escalators, indemnification, insurance requirements, termination for convenience, and sub-contractor flow-downs.

DPAs: Processing scope, sub-processor approval, breach notification timing, data transfer mechanism, and audit rights.

Make the Checklist Reusable

The fastest way to use this checklist is to turn it into something your team runs the same way every time, rather than a document someone remembers to open. A reusable version does three things a flat list cannot: it standardizes what “reviewed” means across reviewers, it gives junior team members a structured first pass, and it creates a record of which positions you held or conceded.

In GC AI, each stage can live as a saved skill the whole team runs on any contract, including pre-built ones like Review an NDA, Vendor MSA Review, and Review SaaS AI Terms, plus custom skills that encode your own standard positions and escalation thresholds. A reviewer builds the skill once, and everyone runs it on every deal.

KT Farley, Chief Privacy Officer and Associate General Counsel atHelix, described what that looks like on a real team:

“The ability to create and store reusable prompts and share them across the team has completely changed the work required to review standard work. Junior teammates now run the checklist prompt first and bring me the output as the predicate for my review.”

That is the highest-leverage version of a checklist: a senior reviewer designs it once, the team runs it on every contract, and the first time a junior teammate’s pass catches an auto-renewal the GC would have missed, it pays for itself.

How to Run Your Contract Review Checklist in GC AI

A legal AI platform built for in-house counsel turns the checklist from a document you remember to open into a workflow that runs on every contract automatically.GC AIwas built by Cecilia Ziniti, a three-time general counsel, to do exactly the work in-house teams do most.

That is what Maury Bricks ran into when “please redline this document” came back as 40 specific things to check. Load your standard positions intoPlaybooks, and GC AI applies them to every incoming contract, with pre-built playbooks for NDAs, DPAs, and MSAs and custom playbooks that encode your own.

Exact Quoteties every flag to the precise language in the source contract with character-level citation, so a reviewer can trace each item on the checklist back to the clause that triggered it.

And becauseGC AI for Wordruns insideMicrosoft Word, the redline, the issue spotting, and the drafted replacement clause happen where the contract already lives.

The reliability question matters for legal work, and GC AI publishes its own evidence. On theIn-House Legal Bench, GC AI’s May 2026 evaluation across 100 in-house tasks and more than 1,200 attorney-developed criteria, it scored 86.8%, ahead of ChatGPT at 79.8%, Claude at 68.4%, and Gemini at 57.5%.

On security, GC AI is SOC 2 Type II and SOC 3 certified, GDPR compliant, with zero data retention agreements with OpenAI and Anthropic, and AES-256 encryption. More than 2,200+ legal teams across 53 countries use GC AI as of September 2026, including the legal departments at Snyk, Tipalti, Columbia Sportswear, and Wayfair, as well as 300+ public companies.

How to Choose Software to Run Your Checklist

If you are choosing the software that will run this checklist, the buying decision has its own short checklist. The full version lives in the guide toAI contract review for in-house counsel; the essentials:

Built for in-house counsel: the workflows assume a lean team reviewing high volume across the business

Citations to the source: every flag traces to the exact contract language, so you can verify each one against the source

Works in your tools: review happens in Word and your existing workflow, with no copy-paste between systems

Customizable playbooks: the platform learns your own standard positions and fallbacks

Security you can show procurement: SOC 2 Type II, GDPR, and clear data retention terms

Proof you can check: published benchmarks and customer outcomes you can verify

For a wider view of the category, the guide toin-house counsel AI softwarecovers what to buy first and what to skip.

Start with One Contract

The best way to test a contract review checklist is to run it on a contract you already know. Take an agreement you reviewed by hand last week, run it through your checklist, and see what a structured pass catches that a manual read missed. Teams that adopt GC AI see value before the first month is out, and reclaim an average of 14 hours per person per week, according to GC AI’sDecember 2025 ROI studyof more than 100 active customers. With nearly half of corporate legal budgets going tooutside counselper ACC benchmarking, faster in-house review is where lean teams reclaim budget.

You can also learn the underlying technique in GC AI’slegal AI classestaught by former general counsels, including how to build review prompts your whole team can reuse.

Frequently Asked Questions

What Is a Contract Review Checklist?
It is the repeatable set of checks a legal team runs on every incoming agreement, sequenced so the clauses that allocate the most risk get looked at first. A checklist is what separates reviewing a contract from reading it, and what keeps a buried auto-renewal or one-sided indemnity from reaching the CEO’s desk unflagged.
What Should a Contract Review Checklist Cover?
A complete checklist moves through seven stages: triage by risk, confirm parties and renewal, pin down commercial terms, flag risk-allocation clauses, check counterparty paper for red flags, redline against your playbook, and route for approval and signature.
Which Clauses Carry the Most Risk in a Commercial Agreement?
The eight clauses that carry most of the risk are indemnification, limitation of liability, intellectual property, confidentiality, data protection, warranties and representations, termination and survival, and governing law and dispute resolution. Read each against your company’s standard position and flag every departure from it.
What Should You Review First in a Contract?
Start with triage, then the risk-allocation clauses. A contract review checklist works in sequence on purpose: you spend scarce attention where the dollars and liability live and let a repeatable process carry the rest, so a three-year data processing agreement with uncapped liability gets far more scrutiny than a routine NDA on your own template.
How Do You Review a Contract on the Other Party’s Paper?
When the contract sits on the counterparty’s template, shift from confirming your terms to catching theirs: scan for uncapped liability, one-sided indemnification, auto-renewal with long notice windows, unilateral amendment rights, assignment without consent, and clauses missing entirely. Counterparty paper favors the counterparty by design, so this part of the contract review process is about spotting what moves risk onto you.
How Do You Catch a Clause That Is Missing Entirely?
A written checklist is what surfaces gaps, because an absent clause leaves no text to react to. Tiffany Lee, General Counsel at Liquid Death, handles it by asking what the agreement is missing, then drafting the clause directly inside the platform, such as a confidentiality or data protection section.
How Do Junior Lawyers Use a Contract Review Checklist?
A senior reviewer designs the checklist once, and junior teammates run it as a structured first pass, then bring the output as the starting point for senior review. KT Farley, Chief Privacy Officer at Helix, describes this as an approach that changed the work required to review standard agreements.
How Does a Contract Review Checklist Differ by Contract Type?
The seven stages apply to any agreement, but the clauses that matter most shift by type. NDAs prioritize definition and mutual obligation, SaaS agreements focus on service levels and liability caps, vendor contracts emphasize indemnification and termination for convenience, and DPAs center on breach notification and data transfer mechanisms.
How Does GC AI Support a Contract Review Checklist Workflow?
GC AI lets teams load their standard positions into Playbooks, which apply to every incoming contract automatically, with pre-built playbooks for NDAs, DPAs, and MSAs and custom playbooks for your own positions. Every flag is tied to the precise contract language through Exact Quote, and review happens inside Microsoft Word so there is no copy-paste between systems.
How Reliable Is AI-Assisted Contract Review?
Reliability depends on the tool. On the In-House Legal Bench, a May 2026 evaluation across 100 in-house tasks and more than 1,200 attorney-developed criteria, GC AI scored 86.8%, compared to ChatGPT at 79.8%, Claude at 68.4%, and Gemini at 57.5%.
SOC 2 certification badgeSOC 2
SOC 3 certification badgeSOC 3
GDPR badgeGDPR

Take the first step now

Let's explore about how we can make your life as an in-house lawyer a whole lot easier.

What to expect:

  • A walkthrough of the platform, tailored to your team's use cases.
  • Q&A session about security, integrations, and onboarding.
  • A 14-day free trial if the platform looks like a fit for your team.

Book a Demo

Dial code +1 (United States)

By submitting, you agree to our Terms and Privacy Policy.

Keep up with the latest content