The Vendor Contract Reviewer skill analyses vendor and supplier contracts to identify commercial risks, unfavourable terms, compliance gaps, and negotiation opportunities. It systematically evaluates key contractual provisions including pricing mechanisms, service level commitments, liability frameworks, intellectual property rights, data protection obligations, and exit terms. The skill produces a structured risk assessment with prioritised findings and actionable negotiation recommendations, enabling procurement teams and legal reviewers to focus their attention on the clauses that carry the greatest financial or operational exposure.
-
Identify the contract type and structure. Determine whether the document is a master services agreement, statement of work, software licence, SaaS subscription, data processing agreement, or another contract form. Note the parties, effective date, initial term, and governing law. Identify all schedules, appendices, and incorporated documents referenced in the main body.
-
Analyse the pricing and payment structure. Review the fee schedule, rate cards, volume commitments, and payment terms. Identify price escalation mechanisms (fixed increases, CPI-linked, uncapped), minimum spend obligations, and penalties for early termination or volume shortfalls. Flag any pricing terms that create lock-in or unpredictable cost exposure.
-
Evaluate service level commitments. Examine SLA definitions, measurement methodologies, reporting obligations, and service credit mechanisms. Assess whether SLA targets are measurable and enforceable, whether credits are meaningful relative to fees, and whether the contract includes SLA exclusions that materially weaken the commitments. Check for uptime definitions that exclude scheduled maintenance windows or force majeure events.
-
Review liability and indemnification provisions. Analyse liability caps (per-incident and aggregate), carve-outs from caps (e.g., IP infringement, data breach, wilful misconduct), indemnification obligations, and insurance requirements. Identify any unlimited liability exposure or asymmetric indemnification that disproportionately favours the vendor.
-
Assess data protection and security clauses. Review data processing terms, data location restrictions, sub-processor controls, breach notification timelines, audit rights, and data return/deletion obligations on termination. Compare provisions against applicable regulations (GDPR, CCPA, or as specified) and organisational data governance policies.
-
Examine termination and exit provisions. Analyse termination for convenience rights, notice periods, termination for cause triggers, cure periods, and the consequences of termination including transition assistance, data extraction, and surviving obligations. Identify any vendor lock-in mechanisms such as proprietary data formats, excessive exit fees, or restrictive non-compete clauses.
-
Identify additional risk areas. Review intellectual property ownership and licence grants, change management procedures, dispute resolution mechanisms, assignment and subcontracting rights, force majeure provisions, and confidentiality obligations. Flag any unusual or non-standard clauses that deviate from market norms.
-
Compile findings and recommendations. Produce the risk assessment with each finding categorised by risk level and contract section. Provide specific, actionable negotiation recommendations for each material finding, including suggested alternative language or fallback positions where appropriate.