Contract review checklist: 10 critical clauses to assess in every contract review

Most contracts arrive when the deal is already moving. Commercial terms are agreed, timelines are fixed, and legal is expected to review quickly across multiple competing priorities. The challenge is not knowing what to look for. It is applying that knowledge consistently across the full legal team when time is short, and the backlog is substantial.
What slips through in these conditions is rarely an obscure provision. It is a familiar clause with a small but significant variation: a liability cap that appears reasonable but is quietly superseded by a higher cap buried in a data processing annex, an indemnity that uses “arising out of” instead of “caused by,” a force majeure clause that allows indefinite suspension with no exit mechanism. None of these are difficult to understand. But they are easy to miss.
The checklist below is structured to catch exactly these variations. Each clause area includes a severity rating drawn from standard commercial practice, the specific question to ask during review, and the language or position to push for.
The 10-clause first-pass contract review checklist
Use this before recommending any commercial agreement for signature. A “no” or “unsure” answer on any item means the clause needs closer review before the agreement proceeds.
Clause 1: Liability cap
Liability caps are almost never missed entirely. What gets missed are the layers: different caps applying to different scopes and carve-outs scattered across annexes that expand exposure beyond the main clause.
What to check: Is the cap clearly defined and tied to a suitable basis (e.g.: lump sum, fees paid, supplier insurance amount, etc.)? Check all annexes and schedules – particularly data processing agreements – for provisions that set a higher cap than the main clause.
Preferred position: A centrally orchestrated liability limitation mechanism. Instead of several clauses across several documents (e.g.: a main agreement and related annexes) dictating the liability of contracting parties, opt for a single clause in the main agreement that establishes the main principles and any carve-outs/exceptions within the same area of the contract.
⚠ A liability limitation clause capped at 1x fees can be effectively overridden by a data processing annex setting a 3x cap for breach scenarios. Read the whole agreement, not just the liability clause.
Clause 2: IP ownership
Most IP clauses are not missed. What is easy to miss is how drafters scope the definition of deliverables and the extent of the license granted over background IP – typically through the use of defined terms.
What to check: Are all deliverables owned by the client? How are “deliverables,” “work product,”, “background IP”, etc. defined?
Preferred position: Client owns all work product created specifically for it. Supplier retains background IP but grants a perpetual, royalty-free license to use it as part of the deliverables.
⚠ If the contract defines “deliverables” by reference to a Statement of Work, check that the SOW is specific enough to capture all expected outputs.
Clause 3: Indemnification
Indemnification clauses are rarely missed as such. Where things go wrong is confusing verbiage and unclear attribution of fault. Focus on stripping redundant verbs and mathematically isolating fault from the scope of coverage.
What to check: Watch where the clause uses “arising out of” or “caused by” when referring to an indemnifiable event to ensure all parties align on scope. Is there a duty to defend that requires paying legal costs from the moment a claim is filed, before liability is established? Is the obligation mutual?
Preferred position: A mutual obligation where each party indemnifies the other for nonparty claims arising out of the agreement, subject to a comparative-fault carve-out, with clear procedural rules for managing claims.
Clause 4: Termination rights
Termination provisions have many variables: grounds for termination, which party can invoke which ground, notice periods, obligations that survive termination, etc. The number of options makes it hard for teams to maintain a consistent position.
What to check: Is termination for convenience available to both parties, or only one? Are notice periods reasonable (30 days is standard; 90+ days warrants scrutiny)? Are the grounds for termination for cause limited to standard triggers – insolvency, material breach, gross negligence, willful misconduct?
Preferred position: A clear differentiation between termination for cause and termination for convenience, alongside appropriate notice periods for each.
Clause 5: Data protection obligations
With legislation such as GDPR, UK GDPR, and CCPA applying to most agreements involving personal data, regulatory exposure is nearly unavoidable. Most frameworks have clear obligations on what contracts must include – but departures from those requirements in either direction create risk.
What to check: Do the contractual obligations align with the applicable data protection legislation, or do they impose requirements the legislation does not require (e.g. a 24-hour breach notification window where GDPR does not specify a fixed period)? Are sub-processor obligations clearly defined?
Preferred position: Strict adherence to the requirements of applicable data protection law. Any departure from the legislative baseline should be explicitly justified and documented.
⚠ Contractually imposed breach notification windows beyond the usual “without undue delay” are common and create operational risk that data protection legislation often doesn’t require. Flag anything not in line with the applicable standard and push back unless there is a clear justification.
Clause 6: Governing law and jurisdiction
Governing law clauses are typically the first point of contention in cross-border agreements. The final position depends on negotiation leverage, but there are specific provisions within the clause that warrant scrutiny regardless.
What to check: Are there mandatory pre-litigation negotiation periods that delay enforcement? Is binding arbitration embedded in the definition of “Dispute” rather than in a dedicated clause? Are attorney fee provisions consistent with the customs of the relevant jurisdiction?
Preferred position: A simple clause designating the supplier’s jurisdiction, with exclusive court jurisdiction and no mandatory negotiation or arbitration requirements unless specifically agreed.
Clause 7: Consequential loss exclusion
Consequential loss clauses are frequently one-sided: suppliers exclude their liability for indirect loss while the client’s equivalent protection is absent or narrowly drafted. The asymmetry is easy to miss when the clause reads as mutual at first glance.
What to check: Does the exclusion apply equally to both parties? Are the carve-outs (fraud, willful default, death and personal injury) identical for each party, or does one party carry broader residual exposure?
Preferred position: Neither party is liable for indirect, special, or consequential loss. This mutual exclusion does not apply to fraud, willful default, or death and personal injury.
Clause 8: Assignment and change of control
Assignment clauses are often overlooked because they seem unlikely to be triggered. Without a change of control provision, a supplier acquisition can transfer the agreement to an unwanted third party without the client’s consent.
What to check: Can either party assign the agreement without the other’s consent? Does a change of control in the supplier trigger a review or termination right for the client? This is particularly relevant for software vendors, which are frequently acquired.
Preferred position: Suppliers will typically want to leave this option open. Customers need to consider if they want to be able to veto this (or at least have prior notice).
Clause 9: Auto-renewal provisions
Auto-renewal clauses are typically buried in the term and termination section in neutral language. Notice windows of 60, 90, or 120 days are commonly missed, particularly when contracts are stored in email threads or shared drives rather than a managed system.
What to check: Is the renewal period and notice window clearly stated? Is the notice window operationally manageable? Anything above 120 days is non-standard and warrants flagging. Will the renewal be visible in time to act on it?
Preferred position: The agreement renews automatically unless either party provides written notice of non-renewal within a defined window (60–90 days is standard). Non-standard windows should be flagged to whoever manages contract dates.
Clause 10: Force majeure
Force majeure clauses are often accepted as boilerplates. Overly broad definitions – including routine supply chain disruptions or labor shortages – can allow a supplier to suspend performance indefinitely without giving the client a clear exit.
What to check: Is the definition of force majeure appropriately scoped, excluding foreseeable or routine commercial risks? Does the clause include a termination right for either party if the force majeure event continues beyond a defined period (30 days is a reasonable baseline)?
Preferred position: If a force majeure event prevents either party from performing its material obligations for more than 30 consecutive days, either party may terminate the agreement with immediate effect by written notice.
Key terms: a quick reference
These terms appear across the checklist. Each is a standalone concept worth understanding, and each generates its own search and AI assistant queries.
What is a liability cap in a contract?
A liability cap is a contractual provision that limits the total financial exposure of one or both parties if something goes wrong. It is typically expressed as a multiple of fees paid (e.g. 1x or 2x the fees paid in the prior 12 months). The risk is not in the cap itself but in the carve-outs and annexes that may set different caps for specific scenarios – particularly data breaches – without being clearly cross-referenced to the main clause.
What is a consequential loss exclusion?
A consequential loss exclusion removes liability for indirect or downstream losses – lost profits, loss of data, reputational damage – that were not the direct result of the breach. The risk in commercial contracts is that these exclusions are frequently one-sided: the supplier excludes consequential loss while the client’s equivalent protection is absent or narrowly drafted. A well-drafted exclusion applies equally to both parties, with agreed carve-outs for fraud, willful default, and death or personal injury.
What is a force majeure clause and what should it include?
A force majeure clause excuses a party from performing its obligations when an extraordinary event beyond its control prevents performance. The risk in poorly drafted clauses is twofold: an overly broad definition (including foreseeable risks like supply chain disruptions or labor shortages) and the absence of an exit mechanism. Without a termination right after a defined period of non-performance, a client can be left with a suspended contract and no clean way out. Well-drafted force majeure clauses include a specific list of qualifying events and a termination right if the event persists beyond a defined period.
What should a contract playbook include?
A contract playbook is a documented set of pre-agreed positions on key clause types, defining what is acceptable, what requires escalation, and what the preferred fallback language is. For a first-pass review, a playbook should cover at minimum: liability cap structure, indemnification scope, consequential loss exclusion, termination rights, data protection obligations, governing law, IP ownership, assignment and change of control, auto-renewal thresholds, and force majeure exit rights. The value of a playbook is not in the positions themselves – which experienced lawyers generally understand – but in the consistency it creates across a team reviewing at speed.
Contract risk guide for legal