contract risk assessment

How to Do Contract Risk Assessment (With or Without AI)

Adira EditorialLegal AI desk13 min read

A contract risk assessment is the process of working out, before you sign, which parts of a contract can actually hurt you and how much attention each one deserves. Most teams either skip this (skim, sign, hope) or do it backwards, reading start to finish and flagging whatever feels wrong that day. Neither approach repeats reliably past a handful of contracts a month. The one thing almost everyone gets wrong is treating "risk" as a single number instead of separate dimensions with separate answers: how much money is exposed, who bears it, when the relationship can end, who owns what gets built, whether personal data is involved, and whether this counterparty can actually pay if something goes wrong.

Adira, which publishes this guide, sells contract risk scoring and CLM software. This page is written to work entirely by hand, because a real risk assessment needs a checklist, a set of weights, and a decision rule, not a subscription. If any of it helps, good; if you never buy anything from us, the process below still works.

Step 1: Define your risk dimensions

Before you can score anything, decide what you are actually scoring. Seven dimensions cover most commercial contracts:

  • Financial exposure and liability cap. What you could owe, and whether a cap actually limits it. See limitation of liability clauses.
  • Indemnity. Who pays for third-party claims, and whether that promise is capped or carved out of the liability cap. See indemnity clauses.
  • Termination. How fast either side can exit, and what survives.
  • IP. Who owns what gets created, under what default if the clause is silent. See IP assignment clauses.
  • Data and DPDP. Whether personal data is processed, and what that triggers under India's data law. See data protection clauses.
  • Compliance. Sector rules, tax, labour classification, anything that turns a bad clause into a regulatory problem.
  • Counterparty. Whether the other side can actually stand behind its promises.

Writing these down as seven separate lines, even in a spreadsheet, does more for review quality than any scoring tool, because it forces a reviewer to check each dimension instead of stopping once something obviously bad catches the eye.

Step 2: Score each dimension against your playbook

For each dimension, compare the contract's actual language against your team's pre-agreed fallback position, not an abstract sense of "fair." A playbook that says "liability cap must not go below 12 months' fees" gives a clean pass or fail; without that written position, a reviewer negotiates the same point differently every time, depending on mood and deadline pressure.

This is the mechanism behind both rule-based and AI-based scoring tools. Contract Risk Scoring: What It Is and What It Misses covers how scoring engines work, what they get right, and where they break, including the India-specific enforceability gap covered below. Read that before trusting a green or red label on its own; a score is a starting point for this assessment, not a replacement for it.

Step 3: Weight by deal size

The same clause carries different real risk depending on what is at stake. An uncapped indemnity in a ₹40,000 pilot and the same clause in a ₹4 crore enterprise contract are not the same problem, even though the language is identical. Weighting fixes this by scaling scrutiny to deal value:

  • Below roughly ₹5 lakh: treat flags as informational. A checklist pass is usually enough; escalate only for a bright-line legal issue (see the India-specific checks below), regardless of value.
  • ₹5 lakh to ₹50 lakh: score every dimension, and have a named reviewer sign off on anything scoring red.
  • ₹50 lakh to ₹1 crore: the top two or three flagged dimensions get a full manual read, not just a scored pass.
  • Above ₹1 crore, or any deal with uncapped exposure: full review, including counterparty and compliance dimensions a value cutoff alone would under-weight.

These bands are a starting point; a business selling ₹8 lakh average deals should shift them down, one doing ₹5 crore deals should shift them up. What matters is that the bands exist in writing and get applied consistently, not decided fresh for each contract.

Step 4: Decide the review depth accordingly

Weighting from Step 3 should map directly onto how much human time a contract gets, not just how worried a score makes someone feel. A light-touch pass means a checklist run against the seven dimensions, roughly 15 to 20 minutes, similar to the sweep in How to Check a Contract for Red Flags. A full review means a lawyer reads the flagged clauses against the India-specific checks below and negotiates before signature. Most teams struggling with review are not failing at either step alone; they apply full-review depth to every contract regardless of size, burning out the team on the small, low-risk deals that never needed it. If intake does not already route requests by size before review starts, Contract Intake covers building that upstream.

A practical risk checklist by clause

Run this checklist against every contract above your light-touch threshold. Each row is a specific, checkable question, not a vibe.

ClauseWhat to checkWhere to read more
IndemnityMutual or one-sided? Inside or outside the liability cap?Indemnity clauses
Liability capA real number, or "fees paid," which shrinks on a low-fee pilot? Any carve-outs (IP infringement, confidentiality, gross negligence)?Limitation of liability
TerminationExit for convenience, or only for cause? Notice period, and what survives?Termination for convenience
IP assignmentSays "assign," not "licence"? States a period and territory, or relies on silence?IP assignment clauses
Non-compete or non-solicitDoes any restraint operate after the relationship ends, in any form?Are non-compete clauses enforceable in India?
Data and DPDPNames specific obligations (breach notification, data minimisation), or just "comply with applicable law"?Data protection clauses
Counterparty capacityInsurance or a parent guarantee backing its promises, or is the entity thinly capitalised?Insurance clauses, Guarantee clauses
StampingStamped, and dated before or at execution, not after?See the India-specific checks below

How AI helps, and where it does not

AI-assisted review earns its place at triage: reading a 40-page MSA in seconds and flagging which clauses deviate from a standard template is a genuine time saving across a large batch, where speed matters more than any single answer being perfect.

Where it misses is consistent across tools, not one vendor's quirk. It does not know why this deal differs from the deal a playbook was written for, a fact that lives in your CRM, not the contract text. It also defaults to structural, reasonableness-spectrum thinking, checking whether a restraint "looks moderate," on fact patterns where Indian law asks a binary yes-or-no question instead. That gap deserves its own section, because getting it wrong is not a near miss, it is a legal error dressed up as a green score.

India-specific risks to always check, regardless of what a score says

Three categories of Indian law turn a moderate-looking clause into a legally void or unusable one, and none show up on a structural, how-extreme-does-this-look pass.

Void non-competes. Section 27 of the Indian Contract Act, 1872 states plainly:

"Every agreement by which any one is restrained from exercising a lawful profession, trade or business of any kind, is to that extent void."

Read the section on India Code or Indian Kanoon. Unlike a reasonableness test asking whether duration and geography are fair, Section 27 asks one binary question: does the restraint operate after the relationship ends? If yes, it is void, no matter how narrow it looks. The Delhi High Court applied exactly this in Varun Tyagi v Daffodil Software Private Limited (FAO 167/2025, judgment dated 25 June 2025), quashing an injunction against a departing employee because a post-termination restrictive covenant cannot be enforced under Section 27 regardless of how it is framed. A risk assessment that scores a moderate, India-only non-compete as low risk because it "isn't the worst version" has the legal question backwards.

The Section 19(5) IP trap. If an IP assignment clause does not state a duration, Section 19(5) of the Copyright Act, 1957 does not read that silence as "forever." It reads it as five years:

"If the period of assignment is not stated, it shall be deemed to be five years from the date of assignment."

The Delhi High Court's Division Bench confirmed this is applied literally in Pine Labs Private Limited v Gemalto Terminals India Private Limited (2011), holding that Sections 19(5) and 19(6) were "inevitably triggered" once a Master Service Agreement's assignment clause left period and territory unstated. Read Section 19 on Indian Kanoon. A checklist that only asks "does this assign IP to us" misses the real exposure: an unstated period quietly expires the assignment on a clock nobody was watching.

Unstamped admissibility. Section 35 of the Indian Stamp Act, 1899 says that an instrument chargeable with duty:

"...shall be admitted in evidence for any purpose by any person having by law or consent of parties authority to receive evidence... unless such instrument is duly stamped."

Read the section on Indian Kanoon. A perfectly negotiated contract, every clause scored green, is close to useless in court if it is not properly stamped; most defects can be cured on payment of duty and a penalty, but the check belongs on every assessment, not just the ones a lawyer remembers to raise.

A test you can run right now: open your last three signed contracts and Ctrl+F "assign" in the IP clause. If the sentence does not also contain "period," "term," "perpetuity," or a date range, Section 19(5)'s five-year default is quietly running on all three, whether anyone intended it or not.

Red flags across a risk assessment

NormalRed flagWhy it matters
Each of the seven dimensions is scored separatelyOne overall "risk score" with no breakdownA single number can hide one catastrophic dimension inside five fine ones
Review depth scales with deal value, in writingEvery contract gets the same review regardless of sizeSmall deals get over-reviewed; large ones can get under-reviewed if nobody checks value first
A moderate non-compete still scores as high riskIt scores green because duration and geography look reasonableSection 27 is binary, not a spectrum; a narrow restraint is exactly as void as a broad one
IP checklist asks about period and territory specificallyChecklist only asks "does this assign IP to us"Silence triggers the s.19(5) five-year and s.19(6) India-only defaults
Stamping is checked on every contract above a small thresholdStamping is assumed and never actually checkedAn unstamped instrument is inadmissible until cured, a pass/fail fact, not a judgment call
Counterparty capacity is checked for high-value dealsOnly the contract text is reviewed, never who is on the other sideA well-drafted indemnity is worthless against a counterparty that cannot pay it
Weighting bands are written down and applied consistentlyWeighting happens informally, "this one feels important"Inconsistent depth is how a genuinely risky deal slips through next to ten fine ones

Bad clause, better clause: the liability cap

Bad: "Neither party's liability under this Agreement shall exceed the fees paid in the preceding twelve months."

What is wrong: on a low-fee pilot, this cap can be smaller than the cost of one serious breach, and it says nothing about carve-outs, so it may unintentionally cap even IP infringement or confidentiality claims a business would normally want uncapped.

Better: "Except for claims arising from a party's breach of confidentiality, infringement of intellectual property rights, or gross negligence or wilful misconduct, neither party's aggregate liability under this Agreement shall exceed the greater of fees paid in the preceding twelve months or ₹25,00,000. The carve-outs in this clause shall not themselves be subject to any cap."

What changed and why: the floor ("greater of... or ₹25,00,000") protects against a cap that shrinks to near nothing on a low-fee deal, and naming specific carve-outs stops the general cap from silently swallowing claims a business actually needs uncapped, closing the exact gap a structural, cap-exists-so-it's-fine score would miss.

Free tool for the checklist step

You do not need software to run Steps 1 and 2 by hand; a shared spreadsheet with seven columns and a playbook covers most teams. For a faster first pass, paste a contract into Weave, Adira's free browser-based contract tool, and check it against the dimensions above without setting anything up first.

US and global contrast

Risk assessment methodology, dimensions, playbooks, weighting by deal size, travels well across markets. What does not travel is the assumption, common in US-style playbooks, that most risk questions sit on a reasonableness spectrum: is the duration fair, the geography reasonable, the cap adequate. Indian law answers several of these with a bright-line rule instead. Section 27 does not ask whether a non-compete is reasonable, it asks whether it operates post-termination at all; Section 35 does not grade a stamping defect on a scale, it makes the document inadmissible until cured. An assessment built for a jurisdiction that only asks "how extreme is this" will misjudge exactly the clauses where Indian law asks a binary question first.

FAQ

How is a risk assessment different from a risk score? A risk score is one output, usually a colour, from comparing a clause to a playbook. An assessment is the full process: defining dimensions, scoring each one, weighting by deal size, and deciding review depth. A score can feed an assessment; it is not the assessment itself.

Do I need software to do this properly? No. A spreadsheet with the seven dimensions as columns, a written playbook, and the weighting bands in Step 3 cover most teams up to a few hundred contracts a year. Software earns its place once volume outgrows what a spreadsheet can reliably track.

What is the single biggest mistake teams make here? Applying the same review depth to every contract regardless of value, which burns out the team on small deals and can under-review a large one. Weighting by deal size, written down and applied consistently, fixes most of this on its own.

Can a contract score "low risk" overall and still be legally void in part? Yes, most often with post-employment restraints. A non-compete can look moderate on every structural signal and still be void under Section 27, because Indian law asks a binary question, not a structural one.

How often should the playbook behind this assessment be updated? At minimum whenever a major deal type changes, a new jurisdiction is added, or a relevant case shifts how settled an area is, Varun Tyagi's 2025 non-compete ruling being a recent example.

Does a good risk assessment replace the need for a lawyer? No. It replaces guesswork about where limited review time should go first. Whether a flagged clause holds up under Indian law on your facts is a judgment call this process narrows down, not one it makes for you.

This guide gives you a repeatable structure, dimensions, scoring, weighting, review depth, and the India checks a generic playbook tends to miss. It does not tell you whether a specific clause, in your specific deal, will hold up if tested. For a contract above your own high-value threshold, or wherever the India-specific checks above raise a real question, get a lawyer to look before you sign. This is not legal advice.

Frequently asked questions

How is a risk assessment different from a risk score?
A risk score is one output, usually a colour, from comparing a clause to a playbook. An assessment is the full process: defining dimensions, scoring each one, weighting by deal size, and deciding review depth. A score can feed an assessment; it is not the assessment itself.
Do I need software to do a contract risk assessment properly?
No. A spreadsheet with seven risk dimensions as columns, a written playbook, and weighting bands by deal value cover most teams up to a few hundred contracts a year. Software earns its place once volume outgrows what a spreadsheet can reliably track.
What is the single biggest mistake teams make in contract risk assessment?
Applying the same review depth to every contract regardless of value, which burns out the team on small deals and can under-review a large one because nobody explicitly raised its priority. Weighting by deal size, written down and applied consistently, fixes most of this on its own.
Can a contract score 'low risk' overall and still be legally void in part?
Yes, most often with post-employment restraints. A non-compete can look moderate on every structural signal, duration, geography, scope, and still be void under Section 27 of the Indian Contract Act, 1872, because Indian law asks a binary during-or-after question, not a structural one.
How often should the playbook behind a risk assessment be updated?
At minimum whenever a major deal type changes, a new jurisdiction is added, or a relevant case shifts how settled an area of law is, the Delhi High Court's 2025 ruling in Varun Tyagi v Daffodil Software on post-employment non-competes being a recent example.
Does a good risk assessment replace the need for a lawyer?
No. It replaces guesswork about where limited review time should go first. Whether a specific flagged clause actually holds up under Indian law on your facts is a judgment call the process narrows down, not one it makes for you.
Was this useful?

See how Adira drafts in your voice and reads contracts from your side.

Explore the showroom

Working through a contract like this? Weave is Adira’s free tool to read, mark up, and connect any contract in your browser — no account needed.

Try Weave — free