Contract review process flowchart: intake to agreed terms
Contract review process flowchart: intake, value and risk triage, a playbook fast track, redlining, finance and risk review, negotiation rounds and handover.
How it works
Rename the lanes to the functions you actually have
Replace Requester / business owner, Legal, Finance, Risk / compliance and Counterparty with your real roles. Smaller organisations fold risk and compliance into Legal, and some route everything through a legal operations or contract manager lane before it reaches a lawyer. Use one lane per decision-maker rather than per person, so the chart survives someone changing job.
Write the intake form fields onto the request step
Intake quality determines everything downstream. List on the step exactly what the form must capture: counterparty, what is being bought or sold, value and term, whether personal data or systems access is involved, the deadline and the reason for it, and the document in an editable format. Then decide what the "Request pack complete?" gate actually tests, so returns are predictable rather than a matter of individual judgement.
Define what standard means before you rely on the fast track
The "Standard terms?" decision only works if the playbook behind it is written down: which template, which clauses are material, and which pre-approved fallback positions a non-lawyer may accept. Keep the material clause list short enough that people read it, and review it whenever a negotiated deviation becomes routine.
Agree who reviews payment, liability and risk, and in what order
This template runs Legal, then Finance, then Risk / compliance in sequence so the counterparty receives one consolidated set of redlines. If your reviews genuinely run in parallel, redraw them as a fork and add the step where someone reconciles the comments, because unreconciled parallel review is what produces contradictory positions in the same document.
Set the risk appetite thresholds and name the waiver owner
Put your actual limits next to "Deviation within risk appetite?": liability cap position, indemnity scope, governing law, data processing terms, whatever your organisation has agreed. Then name the individual role that can grant a waiver at "Risk owner grants waiver?". A waiver route with no named owner defaults to the drafter, which is exactly the outcome the decision exists to prevent.
Cap the negotiation rounds and define the handover pack
Decide how many exchanges the "Outstanding issues?" loop runs before the open points escalate to the budget holder as a commercial decision. Then specify what "Record review summary and risks" must contain: the final position, accepted deviations, waivers granted and who granted them. That record is what the approver signs against, and it is the audit trail if anyone asks later why a term was accepted.
Frequently asked questions
What is the difference between contract review and contract approval?
Review is a legal and commercial assessment: are these terms acceptable, which deviations from the playbook are present, and what has to change before the organisation should sign? Approval is an authority question: is the person committing the organisation authorised to do so at this value and risk level, under the delegation of authority schedule? They need different people and produce different records. Running them as one step is how a lawyer's comment gets treated as sign-off, or a budget holder's signature gets treated as legal clearance. This flowchart ends at "Hand over to contract approval", which is where the approval and signature process starts.
What does legal actually review in a contract?
In practice a review is a comparison against a playbook rather than a fresh reading. The recurring items are scope and deliverables, term and termination rights, payment terms, liability caps and exclusions, indemnities, intellectual property ownership, confidentiality, insurance, warranties and service levels, data protection, and governing law and dispute resolution. Which of those are material is an organisational decision, and writing that list down is what makes the fast track defensible. Where the counterparty will process personal data on your behalf, UK and EU GDPR Article 28 require a written contract setting out a defined list of matters, which is why the data protection screen sits inside the review rather than after signature.
How long should a contract review take?
There is no statutory or standard turnaround, so the useful move is to set your own target by contract type and then measure against it. Publish separate targets for fast-tracked standard contracts and for negotiated non-standard ones, because averaging the two hides both. When you measure, measure how long each lane holds the file rather than the end-to-end elapsed time. In most teams the review itself is short and the waiting is long: the request pack is incomplete, the file sits in a queue, or the counterparty takes a fortnight to return comments. Only the first two are yours to fix.
Which contracts can skip a full legal review?
Those the playbook can decide without judgement: your own template signed unamended, a renewal on identical terms, or a low-value engagement on the counterparty's standard paper with no change to the clauses you have designated as material. In this chart those take the "Standard" branch to a fast-track playbook check and go straight to the review record. Keep two rules attached to it. The fast track is a check, not an absence of one, so the result is still recorded. And anything involving personal data, systems access or an uncapped liability leaves the fast track regardless of value.