Contract Review Checklist for In-House Counsel: 7 Stages
Josh Bertini
Maury Bricks,General CounselatARKO Corp, did not start out wanting a contract review checklist. He started out proud of avoiding AI entirely. On theCZ and Friends podcast, GC AI’s show hosted by CEO and three-time general counsel Cecilia Ziniti, he described the moment a colleague changed his mind:
“I was not using AI, proudly staying away fromChatGPTand everything, saying, you know, not needed. I’m smart, I can do my work. And Michele showed me. I love how I type in ‘please redline this document’ and then press Easy Prompt, and it’s like, did you mean you wanted to know these 40 things? And I’m like, yes, that’s exactly what I wanted. I wanted to know those 40 things.”
Those 40 things are a contract review checklist, and every in-house lawyer runs one on every agreement, whether it lives in your head, on a Word template, or inside a legal AI platform. Writing it down is what turns reading a contract into reviewing one, and it keeps a buried indemnity or an auto-renewal from reaching the CEO’s desk unflagged.
Below is a complete, copy-ready contract review checklist for in-house counsel, built the way the work moves: triage first, the risk clauses next, the counterparty’s paper after that. World Commerce and Contracting estimates (2020) that weak contractingerodes roughly 9% of annual revenuethrough missed entitlements, scope disputes, and avoidable risk. A checklist is the cheapest insurance against that leakage.
The In-House Contract Review Checklist
A contract review checklist is a written set of items an in-house legal team verifies on every incoming agreement, organized so that the highest-risk terms get attention first. The point of the sequence is leverage: you spend your scarce attention where the dollars and the liability live, and you let a repeatable process carry the rest. The seven stages below run in review order, so use the list as a quick index, then work through the specific items under each one.
Triage the contract by risk
Confirm the parties, term, and renewal
Pin down the commercial terms
Flag the risk-allocation clauses
Check the counterparty’s paper for red flags
Redline against your playbook and fallbacks
Route for approval and signature
Triage the Contract by Risk
Decide how hard to look before you start reading. Sort each incoming contract into a risk tier by dollar value, data sensitivity, term length, and whether it uses your paper or the counterparty’s. A mutualNDAon your template is a five-minute review; a three-year data processing agreement with uncapped liability is not. Triage is what keeps a lean team from giving a renewal the same hour it gives a bet-the-company deal.
Confirm which side’s template the contract sits on
Note the total contract value and payment exposure
Flag whether the deal touches personal data, IP, or regulated activity
Set a review depth and turnaround based on the tier
Confirm the Parties, Term, and Renewal
Verify who is bound and for how long. Check that the named entities match the signing parties, that the effective date and term are unambiguous, and that renewal is something you control. Auto-renewal with a 90-day notice window is one of the most common ways companies stay locked into vendors they meant to leave. In a 2021 agreement betweenCenntro Electric Groupand a European counterparty, the renewal term reads: “the term of this Agreement will automatically renew for additional successive one (1) year terms unless either Party provides written Notice of non-renewal at least ninety (90) days prior to the end of the then-current term.” Miss that 90-day window and you are locked in for another full year.
Correct legal entity names and signing authority
Effective date, initial term, and renewal mechanics
Notice period required to prevent auto-renewal
Assignmentandchange-of-controlrights
Pin Down the Commercial Terms
Read the money before the boilerplate. Confirm pricing, payment timing, and any caps or escalators match the business deal, and that service levels and remedies are spelled out in writing.
Pricing, fees, and any annual escalators
Payment terms and late-payment consequences
Service levels, credits, and remedies
Expense, pass-through, and reimbursement terms
Flag the Risk-Allocation Clauses
This is the heart of any contract review checklist: the clauses that decide who pays when something goes wrong. Read each one against your company’s standard position, and note where the draft departs from it. These eight carry most of the risk in a commercial agreement:
| Clause | What to verify | Red flag to escalate |
|---|---|---|
| Indemnification | Who covers whom, for what, and with what carve-outs | One-way indemnity, or carve-outs that gut the protection |
| Limitation of liability | The cap, the exclusions, and whether it is mutual | No cap, or a cap that excludes the claims you are most likely to face |
| Intellectual property | Ownership of deliverables, license scope, and feedback rights | The counterparty claiming ownership of your inputs or outputs |
| Confidentiality | Definition, duration, and permitted disclosures | A short or one-sided confidentiality term |
| Data protection | The DPA, security obligations, breach notice, and sub-processors | No DPA, or breach notice measured in weeks |
| Warranties and representations | What each side promises and for how long | A blanket as-is disclaimer on a critical service |
| Termination and survival | For cause, for convenience, and what lives on after | No termination for convenience, or survival with no end date |
| Governing law and dispute resolution | Venue, arbitration, and fee-shifting | A hostile venue, or mandatory arbitration with fee-shifting against you |
The label matters less than the balance. In a 2024 consulting agreement betweenCaterpillar and Suzette M. Long, the indemnity runs both ways: “Each party shall indemnify, defend, and hold harmless the other party, along with its affiliates, directors, officers, employees and agents from and against any and all suits, claims, demands, losses, damages, costs and expenses.” Mutual is the position to anchor on, so flag any one-way version that protects the counterparty alone.
For deeper, clause-by-clause review of specific agreement types, see theSaaS agreement checklistand thevendor agreement review workflow.
Check the Counterparty’s Paper for Red Flags
When you are reviewing the other side’s template, the work shifts from confirming your terms to catching theirs. Counterparty paper favors the counterparty by design, so scan for the patterns that move risk onto you.
Uncapped liability, or carve-outs that swallow the cap
One-sided or asymmetric indemnification
Auto-renewal paired with a long notice window
Unilateral amendment rights (“we may update these terms”)
Assignment without consent
Missing clauses entirely, such as a confidentiality or data protection section that should be there
Tiffany Lee, General Counsel and Corporate Secretary atLiquid Death, described how she handles that last one:
“If it sees a missing confidentiality clause, I’ll just ask it to draft one I can drop right into the agreement, no leaving the system, no reformatting.”
Catching a missing clause is harder than reviewing a present one, because there is no text to react to. A written checklist is what surfaces the gap, and it is the reason “what is not here?” belongs on every review.
Redline against Your Playbook and Fallbacks
Mark up the contract against your standard positions so each pass starts from a known baseline. Your playbook holds the preferred language, the acceptable fallback, and the walk-away line for each key clause, so redlining becomes a matter of matching the draft to a position you can reuse on every deal. This is whereAI contract redlining softwareearns its keep, carrying your standard markup into Word automatically.
Apply preferred and fallback language for each flagged clause
Note your walk-away positions before negotiation starts
Keep comments tied to specific contract language
Track which positions you conceded for the next renewal
Route for Approval and Signature
Close the loop with clear escalation thresholds. Define which terms a reviewer can approve alone and which require finance, security, or the GC, so nothing ships above someone’s authority and nothing waits on the GC that did not need to.
Approval thresholds by dollar value and risk tier
Required sign-offs from finance, security, or privacy
Final version control and clean execution copy
Storage and key-date tracking after signature
A Contract Review Checklist by Contract Type
The seven stages hold for any agreement, but the clauses that matter most shift by contract type. A few quick variants:
NDAs: Definition of confidential information, term of the obligation, permitted disclosures, return-or-destroy requirements, and whether it is mutual.
SaaS and MSAs: Service levels and credits, data protection and security, liability cap relative to fees paid, IP and usage rights, and renewal mechanics. TheSaaS agreement checklistbreaks down the six clauses that carry the risk.
Vendor and procurement contracts: Pricing and escalators, indemnification, insurance requirements, termination for convenience, and sub-contractor flow-downs.
DPAs: Processing scope, sub-processor approval, breach notification timing, data transfer mechanism, and audit rights.
Make the Checklist Reusable
The fastest way to use this checklist is to turn it into something your team runs the same way every time, rather than a document someone remembers to open. A reusable version does three things a flat list cannot: it standardizes what “reviewed” means across reviewers, it gives junior team members a structured first pass, and it creates a record of which positions you held or conceded.
In GC AI, each stage can live as a saved skill the whole team runs on any contract, including pre-built ones like Review an NDA, Vendor MSA Review, and Review SaaS AI Terms, plus custom skills that encode your own standard positions and escalation thresholds. A reviewer builds the skill once, and everyone runs it on every deal.
KT Farley, Chief Privacy Officer and Associate General Counsel atHelix, described what that looks like on a real team:
“The ability to create and store reusable prompts and share them across the team has completely changed the work required to review standard work. Junior teammates now run the checklist prompt first and bring me the output as the predicate for my review.”
That is the highest-leverage version of a checklist: a senior reviewer designs it once, the team runs it on every contract, and the first time a junior teammate’s pass catches an auto-renewal the GC would have missed, it pays for itself.
How to Run Your Contract Review Checklist in GC AI
A legal AI platform built for in-house counsel turns the checklist from a document you remember to open into a workflow that runs on every contract automatically.GC AIwas built by Cecilia Ziniti, a three-time general counsel, to do exactly the work in-house teams do most.
That is what Maury Bricks ran into when “please redline this document” came back as 40 specific things to check. Load your standard positions intoPlaybooks, and GC AI applies them to every incoming contract, with pre-built playbooks for NDAs, DPAs, and MSAs and custom playbooks that encode your own.
Exact Quoteties every flag to the precise language in the source contract with character-level citation, so a reviewer can trace each item on the checklist back to the clause that triggered it.
And becauseGC AI for Wordruns insideMicrosoft Word, the redline, the issue spotting, and the drafted replacement clause happen where the contract already lives.
The reliability question matters for legal work, and GC AI publishes its own evidence. On theIn-House Legal Bench, GC AI’s May 2026 evaluation across 100 in-house tasks and more than 1,200 attorney-developed criteria, it scored 86.8%, ahead of ChatGPT at 79.8%, Claude at 68.4%, and Gemini at 57.5%.
On security, GC AI is SOC 2 Type II and SOC 3 certified, GDPR compliant, with zero data retention agreements with OpenAI and Anthropic, and AES-256 encryption. More than 2,200+ legal teams across 53 countries use GC AI as of September 2026, including the legal departments at Snyk, Tipalti, Columbia Sportswear, and Wayfair, as well as 300+ public companies.
How to Choose Software to Run Your Checklist
If you are choosing the software that will run this checklist, the buying decision has its own short checklist. The full version lives in the guide toAI contract review for in-house counsel; the essentials:
Built for in-house counsel: the workflows assume a lean team reviewing high volume across the business
Citations to the source: every flag traces to the exact contract language, so you can verify each one against the source
Works in your tools: review happens in Word and your existing workflow, with no copy-paste between systems
Customizable playbooks: the platform learns your own standard positions and fallbacks
Security you can show procurement: SOC 2 Type II, GDPR, and clear data retention terms
Proof you can check: published benchmarks and customer outcomes you can verify
For a wider view of the category, the guide toin-house counsel AI softwarecovers what to buy first and what to skip.
Start with One Contract
The best way to test a contract review checklist is to run it on a contract you already know. Take an agreement you reviewed by hand last week, run it through your checklist, and see what a structured pass catches that a manual read missed. Teams that adopt GC AI see value before the first month is out, and reclaim an average of 14 hours per person per week, according to GC AI’sDecember 2025 ROI studyof more than 100 active customers. With nearly half of corporate legal budgets going tooutside counselper ACC benchmarking, faster in-house review is where lean teams reclaim budget.
You can also learn the underlying technique in GC AI’slegal AI classestaught by former general counsels, including how to build review prompts your whole team can reuse.






