AI Adoption GuideITSelect
Contract risk extraction
LLM extracts and flags non-standard clauses, auto-renewal traps, and liability gaps from vendor contracts.
IT processPlanSelectDeployProvisionSupportUpgradeReplaceRetire
By Don, DoneThat’s AI coach · updated
What contract risk extraction should produce
Contract risk extraction uses an LLM to read a vendor agreement and surface clauses that depart from your standard terms, create renewal or termination risk, or leave liability undefined. The output is a structured flag list: each item names the risk type, quotes the relevant clause text, and points to the section where it appears. If the document does not contain a liability cap, indemnity scope, or auto-renewal language, that field stays blank. The model does not infer missing terms, propose replacement language, or recommend signature.
That quality bar matters because procurement and legal-ops leads use extraction to shorten first-pass review, not to replace counsel. A useful run turns a 40-page MSA into a short briefing: non-standard payment terms in Section 4.2, mutual indemnity without a cap in Section 9, a 90-day auto-renewal notice window in Section 12.1. Legal opens the PDF at those sections and decides what to push back on. Nothing in the extract counts as approval.
Run extraction before legal review, not instead of it
Treat extraction as intake for negotiation prep, parallel to work you already do when a vendor reaches final contract stage. Load the executed draft or the vendor's paper version into whatever CLM or document workflow you use. Ironclad, DocuSign, Icertis, and ServiceNow all sit in this stack for many enterprises; the extraction step may live inside those tools or in a separate review layer that accepts PDF or Word uploads. The sequence stays the same regardless of vendor: upload, run the risk pass, receive flags with cites, hand the output to legal alongside the source file.
Do not route extracted text to e-signature. Auto-sign workflows assume the file on the envelope matches what reviewers saw. An LLM summary is not that file. Keep signature authority with legal and whoever holds delegated approval on your side. If your process uses a selection decision audit trail, log that extraction ran, which model or template version was used, and that legal review is still pending. That record helps when someone asks later why a clause was flagged before redlines went out.
Illustrative pass. Your team receives a SaaS order form attached to a cloud vendor's standard MSA. Extraction returns three flags: limitation of liability excludes consequential damages but caps direct damages at fees paid in the prior twelve months (Section 8.3); termination for convenience requires 60 days' notice and does not refund prepaid annual fees (Section 11); the agreement renews automatically for successive one-year terms unless either party gives written notice 90 days before expiry (Section 14.2). Data processing terms reference the vendor's online policy URL but do not attach a DPA. Your lead sends legal the flag list with page references. Legal confirms the liability cap language, marks the renewal window for calendar tracking, and requests a executed DPA before anyone signs. No line in the extract says the deal is acceptable.
How to load contracts and require clause cites
Load the actual contract file. Use the version under negotiation, not a cover email, not an RFP attachment summary, and not text pasted from a rfp response summarizer output. OCR quality, scanned appendices, and cross-referenced exhibits break extraction when the source is wrong. If the vendor sent a ZIP with multiple documents, specify which file is the governing agreement and which are schedules; otherwise flags may cite the wrong instrument.
Define the flag schema up front. At minimum, capture risk category, verbatim clause excerpt, section or page reference, and confidence that the cite maps to the source. Standard categories for vendor paper include: non-standard payment or invoicing, warranty disclaimers, indemnity and liability caps, IP ownership or license scope, data protection and subprocessors, termination and renewal, assignment and change of control, and audit or security attestation gaps. Instruct the workflow to return empty for any category with no supporting text in the file. A blank liability-cap field is correct when the agreement is silent; inventing a cap is a defect, not a convenience.
Validate cites before sharing. Spot-check every flag against the PDF. Section numbering differs across templates; some vendors use "Article" while schedules use numbered paragraphs. A flag that says "Section 9" but quotes language from an exhibit belongs back in the queue, not in legal's inbox. Reject any output that paraphrases without quotation marks when your standard requires verbatim cites.
Where extraction fits in vendor selection
Extraction earns its place late in select-stage work, when terms-not feature lists-drive remaining risk. By then you have likely narrowed the field using a vendor shortlist scoring engine and compared economics with a total cost of ownership calculator. Contract review does not re-score product fit; it surfaces legal and operational exposure in the paper each finalist wants you to sign.
Use the same extraction template across finalists so legal compares like-for-like flags. One vendor may show a narrow liability cap; another may be silent. Empty fields are data: they tell you where negotiation must start from zero. Pair extraction output with your shortlist rationale so approvers see product decision and contract risk in one thread, without treating the LLM output as a substitute for either document.
Failure modes that break negotiation prep
Flags without clause cites. A line that says "unfavorable indemnity" with no quoted text and no section reference forces legal to re-read the entire agreement. That erases the time savings and trains reviewers to distrust the tool. Fail the run and fix prompts or tooling when cites are missing.
Treating the extract as signed or approved. Summaries do not bind the company. If a business owner reads "liability capped at 12 months' fees" in the extract but legal never confirmed the cap against the PDF, you can sign language that does not exist or miss a carve-out that survives in the actual clause. Keep explicit language in your process: extraction is draft intelligence only.
Invented terms. Models sometimes fill gaps with plausible contract language-a liability cap, a renewal period, a governing law-that never appeared in the upload. That is the most dangerous failure mode because it looks authoritative. Enforce empty-when-absent rules in review checklists and treat any uncited numeric limit as a hallucination until legal verifies it in the source file.
Wrong document or stale version. Redlines arrive daily during select-stage negotiations. Running extraction on Monday's draft and signing Wednesday's version without a second pass misses changes in the very sections you flagged. Re-run when the vendor returns a new PDF, or diff versions before signature.
What legal still owns after extraction
Legal negotiates. Procurement may own the commercial relationship and the timeline, but indemnity, liability, IP, privacy, and termination language stay in counsel's lane. Extraction gives them a map; it does not pick walk-away points, approve deviations from your playbook, or set fallback positions.
Your team owns the operational follow-through: tracking auto-renewal notice dates surfaced in flags, ensuring DPAs and security exhibits are attached before signature, and confirming final executed PDFs match the reviewed version. When a flag shows a non-standard clause, legal decides whether to accept, redline, or escalate. The extract never closes that loop on its own.
Build the habit of closing select stage with two artifacts: the signed or agreed contract file and the final extraction or legal memo that records what was flagged and what changed. That pairing keeps vendor selection auditable and stops the next renewal from starting blind to terms someone thought were "handled by the AI pass" six months earlier.
Is this worth automating for you?
Whether this pays back depends on how much time it takes your team today. Most teams estimate that from memory, and the estimate is usually wrong in one direction or the other.
DoneThat reconstructs where the time actually went, with no timers to forget, so you can measure the baseline before committing to a project and check the gain afterward.
Measure the baseline first