contract risk assessment
How to Do Contract Risk Assessment (With or Without AI)
A contract risk assessment is the process of working out, before you sign, which parts of a contract can actually hurt you and how much attention each one deserves. Most teams either skip this (skim, sign, hope) or do it backwards, reading start to finish and flagging whatever feels wrong that day. Neither approach repeats reliably past a handful of contracts a month. The one thing almost everyone gets wrong is treating "risk" as a single number instead of separate dimensions with separate answers: how much money is exposed, who bears it, when the relationship can end, who owns what gets built, whether personal data is involved, and whether this counterparty can actually pay if something goes wrong.
Adira, which publishes this guide, sells contract risk scoring and CLM software. This page is written to work entirely by hand, because a real risk assessment needs a checklist, a set of weights, and a decision rule, not a subscription. If any of it helps, good; if you never buy anything from us, the process below still works.
Step 1: Define your risk dimensions
Before you can score anything, decide what you are actually scoring. Seven dimensions cover most commercial contracts:
- Financial exposure and liability cap. What you could owe, and whether a cap actually limits it. See limitation of liability clauses.
- Indemnity. Who pays for third-party claims, and whether that promise is capped or carved out of the liability cap. See indemnity clauses.
- Termination. How fast either side can exit, and what survives.
- IP. Who owns what gets created, under what default if the clause is silent. See IP assignment clauses.
- Data and DPDP. Whether personal data is processed, and what that triggers under India's data law. See data protection clauses.
- Compliance. Sector rules, tax, labour classification, anything that turns a bad clause into a regulatory problem.
- Counterparty. Whether the other side can actually stand behind its promises.
Writing these down as seven separate lines, even in a spreadsheet, does more for review quality than any scoring tool, because it forces a reviewer to check each dimension instead of stopping once something obviously bad catches the eye.
Step 2: Score each dimension against your playbook
For each dimension, compare the contract's actual language against your team's pre-agreed fallback position, not an abstract sense of "fair." A playbook that says "liability cap must not go below 12 months' fees" gives a clean pass or fail; without that written position, a reviewer negotiates the same point differently every time, depending on mood and deadline pressure.
This is the mechanism behind both rule-based and AI-based scoring tools. Contract Risk Scoring: What It Is and What It Misses covers how scoring engines work, what they get right, and where they break, including the India-specific enforceability gap covered below. Read that before trusting a green or red label on its own; a score is a starting point for this assessment, not a replacement for it.
Step 3: Weight by deal size
The same clause carries different real risk depending on what is at stake. An uncapped indemnity in a ₹40,000 pilot and the same clause in a ₹4 crore enterprise contract are not the same problem, even though the language is identical. Weighting fixes this by scaling scrutiny to deal value:
- Below roughly ₹5 lakh: treat flags as informational. A checklist pass is usually enough; escalate only for a bright-line legal issue (see the India-specific checks below), regardless of value.
- ₹5 lakh to ₹50 lakh: score every dimension, and have a named reviewer sign off on anything scoring red.
- ₹50 lakh to ₹1 crore: the top two or three flagged dimensions get a full manual read, not just a scored pass.
- Above ₹1 crore, or any deal with uncapped exposure: full review, including counterparty and compliance dimensions a value cutoff alone would under-weight.
These bands are a starting point; a business selling ₹8 lakh average deals should shift them down, one doing ₹5 crore deals should shift them up. What matters is that the bands exist in writing and get applied consistently, not decided fresh for each contract.
Step 4: Decide the review depth accordingly
Weighting from Step 3 should map directly onto how much human time a contract gets, not just how worried a score makes someone feel. A light-touch pass means a checklist run against the seven dimensions, roughly 15 to 20 minutes, similar to the sweep in How to Check a Contract for Red Flags. A full review means a lawyer reads the flagged clauses against the India-specific checks below and negotiates before signature. Most teams struggling with review are not failing at either step alone; they apply full-review depth to every contract regardless of size, burning out the team on the small, low-risk deals that never needed it. If intake does not already route requests by size before review starts, Contract Intake covers building that upstream.
A practical risk checklist by clause
Run this checklist against every contract above your light-touch threshold. Each row is a specific, checkable question, not a vibe.
| Clause | What to check | Where to read more |
|---|---|---|
| Indemnity | Mutual or one-sided? Inside or outside the liability cap? | Indemnity clauses |
| Liability cap | A real number, or "fees paid," which shrinks on a low-fee pilot? Any carve-outs (IP infringement, confidentiality, gross negligence)? | Limitation of liability |
| Termination | Exit for convenience, or only for cause? Notice period, and what survives? | Termination for convenience |
| IP assignment | Says "assign," not "licence"? States a period and territory, or relies on silence? | IP assignment clauses |
| Non-compete or non-solicit | Does any restraint operate after the relationship ends, in any form? | Are non-compete clauses enforceable in India? |
| Data and DPDP | Names specific obligations (breach notification, data minimisation), or just "comply with applicable law"? | Data protection clauses |
| Counterparty capacity | Insurance or a parent guarantee backing its promises, or is the entity thinly capitalised? | Insurance clauses, Guarantee clauses |
| Stamping | Stamped, and dated before or at execution, not after? | See the India-specific checks below |
How AI helps, and where it does not
AI-assisted review earns its place at triage: reading a 40-page MSA in seconds and flagging which clauses deviate from a standard template is a genuine time saving across a large batch, where speed matters more than any single answer being perfect.
Where it misses is consistent across tools, not one vendor's quirk. It does not know why this deal differs from the deal a playbook was written for, a fact that lives in your CRM, not the contract text. It also defaults to structural, reasonableness-spectrum thinking, checking whether a restraint "looks moderate," on fact patterns where Indian law asks a binary yes-or-no question instead. That gap deserves its own section, because getting it wrong is not a near miss, it is a legal error dressed up as a green score.
India-specific risks to always check, regardless of what a score says
Three categories of Indian law turn a moderate-looking clause into a legally void or unusable one, and none show up on a structural, how-extreme-does-this-look pass.
Void non-competes. Section 27 of the Indian Contract Act, 1872 states plainly:
"Every agreement by which any one is restrained from exercising a lawful profession, trade or business of any kind, is to that extent void."
Read the section on India Code or Indian Kanoon. Unlike a reasonableness test asking whether duration and geography are fair, Section 27 asks one binary question: does the restraint operate after the relationship ends? If yes, it is void, no matter how narrow it looks. The Delhi High Court applied exactly this in Varun Tyagi v Daffodil Software Private Limited (FAO 167/2025, judgment dated 25 June 2025), quashing an injunction against a departing employee because a post-termination restrictive covenant cannot be enforced under Section 27 regardless of how it is framed. A risk assessment that scores a moderate, India-only non-compete as low risk because it "isn't the worst version" has the legal question backwards.
The Section 19(5) IP trap. If an IP assignment clause does not state a duration, Section 19(5) of the Copyright Act, 1957 does not read that silence as "forever." It reads it as five years:
"If the period of assignment is not stated, it shall be deemed to be five years from the date of assignment."
The Delhi High Court's Division Bench confirmed this is applied literally in Pine Labs Private Limited v Gemalto Terminals India Private Limited (2011), holding that Sections 19(5) and 19(6) were "inevitably triggered" once a Master Service Agreement's assignment clause left period and territory unstated. Read Section 19 on Indian Kanoon. A checklist that only asks "does this assign IP to us" misses the real exposure: an unstated period quietly expires the assignment on a clock nobody was watching.
Unstamped admissibility. Section 35 of the Indian Stamp Act, 1899 says that an instrument chargeable with duty:
"...shall be admitted in evidence for any purpose by any person having by law or consent of parties authority to receive evidence... unless such instrument is duly stamped."
Read the section on Indian Kanoon. A perfectly negotiated contract, every clause scored green, is close to useless in court if it is not properly stamped; most defects can be cured on payment of duty and a penalty, but the check belongs on every assessment, not just the ones a lawyer remembers to raise.
A test you can run right now: open your last three signed contracts and Ctrl+F "assign" in the IP clause. If the sentence does not also contain "period," "term," "perpetuity," or a date range, Section 19(5)'s five-year default is quietly running on all three, whether anyone intended it or not.
Red flags across a risk assessment
| Normal | Red flag | Why it matters |
|---|---|---|
| Each of the seven dimensions is scored separately | One overall "risk score" with no breakdown | A single number can hide one catastrophic dimension inside five fine ones |
| Review depth scales with deal value, in writing | Every contract gets the same review regardless of size | Small deals get over-reviewed; large ones can get under-reviewed if nobody checks value first |
| A moderate non-compete still scores as high risk | It scores green because duration and geography look reasonable | Section 27 is binary, not a spectrum; a narrow restraint is exactly as void as a broad one |
| IP checklist asks about period and territory specifically | Checklist only asks "does this assign IP to us" | Silence triggers the s.19(5) five-year and s.19(6) India-only defaults |
| Stamping is checked on every contract above a small threshold | Stamping is assumed and never actually checked | An unstamped instrument is inadmissible until cured, a pass/fail fact, not a judgment call |
| Counterparty capacity is checked for high-value deals | Only the contract text is reviewed, never who is on the other side | A well-drafted indemnity is worthless against a counterparty that cannot pay it |
| Weighting bands are written down and applied consistently | Weighting happens informally, "this one feels important" | Inconsistent depth is how a genuinely risky deal slips through next to ten fine ones |
Bad clause, better clause: the liability cap
Bad: "Neither party's liability under this Agreement shall exceed the fees paid in the preceding twelve months."
What is wrong: on a low-fee pilot, this cap can be smaller than the cost of one serious breach, and it says nothing about carve-outs, so it may unintentionally cap even IP infringement or confidentiality claims a business would normally want uncapped.
Better: "Except for claims arising from a party's breach of confidentiality, infringement of intellectual property rights, or gross negligence or wilful misconduct, neither party's aggregate liability under this Agreement shall exceed the greater of fees paid in the preceding twelve months or ₹25,00,000. The carve-outs in this clause shall not themselves be subject to any cap."
What changed and why: the floor ("greater of... or ₹25,00,000") protects against a cap that shrinks to near nothing on a low-fee deal, and naming specific carve-outs stops the general cap from silently swallowing claims a business actually needs uncapped, closing the exact gap a structural, cap-exists-so-it's-fine score would miss.
Free tool for the checklist step
You do not need software to run Steps 1 and 2 by hand; a shared spreadsheet with seven columns and a playbook covers most teams. For a faster first pass, paste a contract into Weave, Adira's free browser-based contract tool, and check it against the dimensions above without setting anything up first.
US and global contrast
Risk assessment methodology, dimensions, playbooks, weighting by deal size, travels well across markets. What does not travel is the assumption, common in US-style playbooks, that most risk questions sit on a reasonableness spectrum: is the duration fair, the geography reasonable, the cap adequate. Indian law answers several of these with a bright-line rule instead. Section 27 does not ask whether a non-compete is reasonable, it asks whether it operates post-termination at all; Section 35 does not grade a stamping defect on a scale, it makes the document inadmissible until cured. An assessment built for a jurisdiction that only asks "how extreme is this" will misjudge exactly the clauses where Indian law asks a binary question first.
FAQ
How is a risk assessment different from a risk score? A risk score is one output, usually a colour, from comparing a clause to a playbook. An assessment is the full process: defining dimensions, scoring each one, weighting by deal size, and deciding review depth. A score can feed an assessment; it is not the assessment itself.
Do I need software to do this properly? No. A spreadsheet with the seven dimensions as columns, a written playbook, and the weighting bands in Step 3 cover most teams up to a few hundred contracts a year. Software earns its place once volume outgrows what a spreadsheet can reliably track.
What is the single biggest mistake teams make here? Applying the same review depth to every contract regardless of value, which burns out the team on small deals and can under-review a large one. Weighting by deal size, written down and applied consistently, fixes most of this on its own.
Can a contract score "low risk" overall and still be legally void in part? Yes, most often with post-employment restraints. A non-compete can look moderate on every structural signal and still be void under Section 27, because Indian law asks a binary question, not a structural one.
How often should the playbook behind this assessment be updated? At minimum whenever a major deal type changes, a new jurisdiction is added, or a relevant case shifts how settled an area is, Varun Tyagi's 2025 non-compete ruling being a recent example.
Does a good risk assessment replace the need for a lawyer? No. It replaces guesswork about where limited review time should go first. Whether a flagged clause holds up under Indian law on your facts is a judgment call this process narrows down, not one it makes for you.
This guide gives you a repeatable structure, dimensions, scoring, weighting, review depth, and the India checks a generic playbook tends to miss. It does not tell you whether a specific clause, in your specific deal, will hold up if tested. For a contract above your own high-value threshold, or wherever the India-specific checks above raise a real question, get a lawyer to look before you sign. This is not legal advice.
Frequently asked questions
- How is a risk assessment different from a risk score?
- A risk score is one output, usually a colour, from comparing a clause to a playbook. An assessment is the full process: defining dimensions, scoring each one, weighting by deal size, and deciding review depth. A score can feed an assessment; it is not the assessment itself.
- Do I need software to do a contract risk assessment properly?
- No. A spreadsheet with seven risk dimensions as columns, a written playbook, and weighting bands by deal value cover most teams up to a few hundred contracts a year. Software earns its place once volume outgrows what a spreadsheet can reliably track.
- What is the single biggest mistake teams make in contract risk assessment?
- Applying the same review depth to every contract regardless of value, which burns out the team on small deals and can under-review a large one because nobody explicitly raised its priority. Weighting by deal size, written down and applied consistently, fixes most of this on its own.
- Can a contract score 'low risk' overall and still be legally void in part?
- Yes, most often with post-employment restraints. A non-compete can look moderate on every structural signal, duration, geography, scope, and still be void under Section 27 of the Indian Contract Act, 1872, because Indian law asks a binary during-or-after question, not a structural one.
- How often should the playbook behind a risk assessment be updated?
- At minimum whenever a major deal type changes, a new jurisdiction is added, or a relevant case shifts how settled an area of law is, the Delhi High Court's 2025 ruling in Varun Tyagi v Daffodil Software on post-employment non-competes being a recent example.
- Does a good risk assessment replace the need for a lawyer?
- No. It replaces guesswork about where limited review time should go first. Whether a specific flagged clause actually holds up under Indian law on your facts is a judgment call the process narrows down, not one it makes for you.
Sources
- Section 27, Indian Contract Act, 1872, agreements in restraint of trade void (Indian Kanoon)
- Section 19, Copyright Act, 1957, mode of assignment, five-year and India-only defaults on silence (Indian Kanoon)
- Section 35, Indian Stamp Act, 1899, instruments not duly stamped inadmissible in evidence (Indian Kanoon)
- Varun Tyagi v Daffodil Software Private Limited, Delhi High Court, FAO 167/2025, judgment dated 25 June 2025 (Indian Kanoon)
- Pine Labs Private Limited v Gemalto Terminals India Private Limited, Delhi High Court, Division Bench, 2011 (Indian Kanoon)
- The Indian Contract Act, 1872 and the Copyright Act, 1957, full text (India Code)
See how Adira drafts in your voice and reads contracts from your side.
Explore the showroomWorking through a contract like this? Weave is Adira’s free tool to read, mark up, and connect any contract in your browser — no account needed.
Try Weave — free