A contract review checklist before signing should answer four questions: who is bound, what each side must do, what it costs, and what happens if things go wrong. Before you sign, check party names, signer authority, scope, payment terms, taxes, renewal, termination, liability, indemnity, confidentiality, data protection, intellectual property, dispute resolution, governing law, and signature validity. Then record the approval trail and store the final signed copy where finance, legal and operations can find it. This is not legal advice. Use the checklist below to catch business and legal issues early, then confirm high-risk terms with counsel.
Contract review checklist before signing: the one-page version
Use this first as a quick pass. If any answer is unclear, pause signing and route the contract for review.
| Area | What to check | Red flag before signing |
|---|---|---|
| Parties | Correct legal names, registered addresses, tax IDs and group entity | Contract names a brand, trade name or wrong group company |
| Authority | Signer has authority under board approval, delegation matrix or role | Sales, HR or procurement signs without approval |
| Scope | Deliverables, service levels, acceptance criteria and exclusions | Vague phrases like as required or best efforts only |
| Price | Currency, taxes, invoicing cycle, payment due date and late fees | Price in email differs from contract or order form |
| Term | Start date, end date, renewal and notice period | Auto-renewal with long notice window missed by operations |
| Liability | Cap, exclusions, consequential loss and carve-outs | Unlimited liability for ordinary service failure |
| Indemnity | Who covers third-party claims and for what conduct | One-sided IP, data or tax indemnity without limits |
| Data | Personal data, processor/controller roles, security and breach notice | No data processing terms where personal data is handled |
| IP | Ownership of pre-existing IP, work product, feedback and licences | Customer gives away core product IP accidentally |
| Confidentiality | Definition, exclusions, term and permitted disclosures | Confidentiality ends too early for sensitive information |
| Termination | Convenience, cause, cure period, refund and transition support | No exit right despite long lock-in |
| Disputes | Governing law, courts, arbitration, venue and escalation | Foreign venue for a small-value local contract |
| Signatures | Valid e-sign method, audit trail and stamping where applicable | Contract type may require wet ink, notarisation or registration |
For India-specific electronic contract rules, also read IT Act Section 10A: Electronic Contracts in India. For clause-level extraction before review, see AI Clause Extraction from Contracts: Practical Guide.
Step 1: confirm the basics before reading clauses
Start with the facts. Many contract disputes begin with simple administrative errors.
Check these items first:
- The full legal name of each party.
- The registered office or principal business address.
- CIN, LLPIN, GSTIN, PAN, EIN or other business identifier where relevant.
- The correct contracting entity in a group structure.
- Whether the person signing has authority.
- Whether the contract refers to the right proposal, statement of work, purchase order or order form.
- Whether all exhibits, schedules and annexures are attached.
If you are an Indian company, the basic enforceability of agreements sits within the contract law framework under the Indian Contract Act, 1872 on India Code. If you are signing in the US, state law and the Uniform Commercial Code may also matter for sale of goods and commercial terms. Confirm legal interpretation with counsel, especially for large commitments or regulated work.
A practical operating rule: do not approve a contract if the signature block, order form and invoice entity do not match. Fix the entity mismatch before signing, even if the commercial terms look correct.
Step 2: review commercial terms in numbers, not words
Commercial review should be numerical. Rewrite the deal in a small table before approving it.
| Term | Question to answer | Example check |
|---|---|---|
| Base fee | What is the fixed amount? | INR 1,80,000 per year or USD 24,000 per year |
| Variable fee | What triggers extra charges? | Per employee, per document, per API call, per site |
| Taxes | Who pays GST, withholding, sales tax or VAT? | Fee is exclusive of GST, customer pays applicable GST |
| Payment date | When does cash leave the business? | Net 15 from invoice date, not from receipt date |
| Late fee | Is it reasonable and lawful? | 1.5 percent per month may need finance approval |
| Price increase | Is there a cap? | Renewal price can rise by 7 percent, not uncapped |
| Expenses | Are travel or out-of-pocket costs pre-approved? | Expenses require written approval and receipts |
Worked example: Indian SaaS purchase
Assume your startup is buying an HR tool for INR 2,40,000 per year plus GST. The order form says annual upfront payment. The master agreement says prices may increase at renewal and the contract auto-renews unless cancelled 60 days before the renewal date.
Before signing, calculate the cash and operational impact:
- Year 1 cash outflow: INR 2,40,000 plus applicable GST.
- Renewal risk: if notice is missed, the business may owe another year.
- Approval required: finance for budget, HR for business owner approval, legal for auto-renewal and liability.
- Calendar action: add renewal review 90 days before expiry, not 60 days.
The issue is not whether the software is useful. The issue is whether the contract lets you stop, renegotiate or reduce seats before the renewal commitment is triggered.
Worked example: US customer agreement
Assume your company sells a USD 36,000 annual SaaS subscription to a US customer. The customer paper includes net 60 payment, unlimited service credits, broad indemnity, New York law, and a requirement to comply with all customer policies.
Before signing, ask:
- Can your cash flow handle net 60, or do you need net 30?
- Are service credits capped, for example at one month of fees?
- Does the indemnity apply only to third-party IP claims, or to any loss?
- Have you received and reviewed the customer policies incorporated by reference?
- Does your insurance cover the contractual obligations?
If the customer has strong bargaining power, you may still accept some terms. But the decision should be visible and approved, not buried in a signed PDF.
Step 3: check high-risk legal clauses before signing
Legal review does not mean rewriting every sentence. Focus on clauses that change your risk profile.
| Clause | What good looks like | What to escalate |
|---|---|---|
| Limitation of liability | Clear cap tied to fees paid or payable | Unlimited liability or cap exclusions that swallow the cap |
| Indemnity | Limited to defined third-party claims | Broad indemnity for all losses, penalties and costs |
| Warranties | Specific promises you can actually meet | Absolute promises such as error-free, uninterrupted or compliant with all laws |
| Termination | Termination for cause with cure period and clear post-termination duties | No cure period or immediate termination for minor breach |
| Confidentiality | Standard exclusions for public information, prior knowledge and compelled disclosure | No exclusions or perpetual obligations for non-sensitive data |
| Non-solicit | Narrow people, time and geography | Applies to all employees, contractors and affiliates worldwide |
| Audit rights | Reasonable notice, business hours, confidentiality and frequency limits | Customer can audit systems any time without limits |
| Assignment | Allows assignment in merger, acquisition or restructuring | Consent needed for any internal reorganisation |
For US electronic records and signatures, the federal ESIGN Act provides that a signature, contract or record may not be denied legal effect solely because it is electronic, subject to exceptions and consent rules. You can read the official text in the Electronic Signatures in Global and National Commerce Act on GovInfo.
For India, electronic contracts are recognised under the Information Technology Act framework, with important exclusions for certain document types and formalities. See the Information Technology Act, 2000 on India Code and confirm your specific document type with counsel.
Step 4: review data, security and privacy obligations
If the contract involves personal data, customer data, employee data, financial data, health data or confidential business data, do a separate data review.
Check:
- What data is shared, accessed, stored or processed.
- Whether each party is a controller, processor, fiduciary, processor, service provider or independent business depending on the applicable law.
- Whether a data processing agreement is required.
- Where data is hosted and whether cross-border transfers apply.
- Security controls, incident notice timelines and audit rights.
- Deletion or return obligations after termination.
- Whether subcontractors can be used without approval.
For EU personal data, Article 28 of the GDPR sets out processor contract requirements. Use the official regulation text on EUR-Lex for Regulation (EU) 2016/679 as the primary source and get counsel to map it to your contract.
For US financial institutions and certain covered businesses, vendor security obligations may also be affected by the FTC Safeguards Rule. The FTC explains business obligations in its Safeguards Rule guidance.
A practical rule for business teams: if the contract mentions personal data but has no data processing terms, do not sign until legal or privacy reviews it.
Step 5: check tax, payment and vendor onboarding documents
Contract review should connect to finance operations. A signed contract that cannot be invoiced, taxed or paid cleanly creates avoidable work.
For India deals, check:
- GSTIN and place of supply.
- Whether GST is included or extra.
- TDS position, if applicable.
- Billing milestone and invoice format.
- Purchase order requirement.
- Bank account details and vendor verification.
For US vendor or contractor payments, finance may need tax forms before payment. The IRS provides official instructions for Form W-9, commonly used to request a US taxpayer identification number and certification.
Add a rule to your checklist: if finance cannot tell when and how the contract will be billed or paid, the commercial review is incomplete.
Step 6: verify signing method, stamping and evidence
Before signing, confirm that the chosen signature method fits the document, jurisdiction and internal policy.
Check these items:
- Is an electronic signature allowed for this document type?
- Does the signing method capture signer identity, consent, timestamp and document hash or tamper evidence?
- Is an audit trail generated and stored with the final document?
- Does the contract need stamp duty, registration, notarisation or witnesses?
- Are all signers signing the same final version?
- Are initials required on schedules, annexures or handwritten changes?
In India, some documents may need wet ink, registration or special formalities even when ordinary commercial contracts can be electronically executed. In the US, ESIGN and state UETA rules often support electronic signatures, but exceptions exist. Confirm edge cases with counsel before relying on e-signature alone.
For contract and e-signature operations, ZiaSign helps teams understand, approve, sign and track agreements in one secure workflow, with audit trails and contract lifecycle management in one workspace. Use any tool you choose, but make sure the evidence file travels with the signed contract.
Step 7: create an approval record before signature
A contract is ready to sign only when the right people have approved the right version.
Use this approval matrix as a starting point:
| Contract type | Business owner | Finance | Legal | Security or privacy | Leadership |
|---|---|---|---|---|---|
| Low-value NDA | Requesting team | Not required | If non-standard | Not required | Not required |
| Vendor SaaS under budget | Department head | Yes | If vendor paper or high risk | If data access exists | If multi-year |
| Customer MSA | Sales lead | For payment and tax | Yes | If customer data involved | If liability exceeds policy |
| Employment or contractor agreement | HR | For compensation | Yes | If data or IP sensitive | As per delegation matrix |
| Strategic partnership | Business sponsor | Yes | Yes | Usually yes | Yes |
Approval records should show:
- Contract name and version.
- Counterparty.
- Value and term.
- Key deviations from standard terms.
- Approvers and timestamps.
- Final signed copy location.
- Renewal owner.
Do not rely on scattered email replies such as looks fine. Ask approvers to approve a named version with a date.
Step 8: final pre-signature red flag list
Stop and escalate if you see any of these:
- The contract value is higher than the approved budget.
- The term is longer than expected.
- Auto-renewal notice is shorter than your internal review cycle.
- Liability is unlimited or much higher than contract value.
- Indemnity covers first-party losses, regulatory fines or broad negligence without review.
- The contract includes documents by link that no one has read.
- The other party can change terms unilaterally.
- You must comply with policies that are not attached.
- The contract grants broad IP ownership over your tools, templates, software or know-how.
- Personal data is processed but no data protection terms exist.
- The signer is not authorised.
- The document type may require stamping, registration, witnesses or wet ink.
If a red flag appears, the answer is not always no. The right answer may be price adjustment, narrower wording, additional approval, insurance confirmation or a side letter.
FAQ
Who should review a contract before signing?
The business owner should review scope and deliverables. Finance should review price, tax, invoicing and payment. Legal should review liability, indemnity, IP, termination, dispute terms and signing validity. Security or privacy should review contracts involving sensitive data or system access.
Can I use the same checklist for vendor and customer contracts?
Yes, but the emphasis changes. For vendor contracts, focus on cost, renewal, data access, service levels and exit rights. For customer contracts, focus on payment, acceptance, liability, indemnity, support obligations and whether your team can perform what the contract promises.
What is the biggest mistake before signing?
The biggest mistake is reviewing only the commercial page and not the incorporated documents. Order forms, statements of work, online terms, policies, data processing addenda and schedules can contain obligations that matter as much as the main agreement.
Is an electronic signature enough?
Often yes for ordinary commercial contracts, but not always. The answer depends on jurisdiction, document type, consent, evidence, stamping, registration and any sector-specific rule. Check the applicable law and confirm with counsel for high-value or unusual documents.
How long should contract review take?
Simple low-risk contracts can be reviewed quickly if you use standard templates and an approval matrix. High-value, regulated, cross-border or non-standard contracts need more time. Track turnaround by stage: business review, legal review, counterparty negotiation, approval and signature.
Closing note
A good contract review checklist before signing is not a legal formality. It is an operating control that protects cash flow, delivery teams, customer relationships and future fundraising or diligence.
Start with the one-page checklist, adapt it to your approval limits, and make every signed contract easy to find later. For high-risk terms, regulated data, unusual signing requirements or cross-border disputes, use this guide as preparation and confirm the final position with counsel.
From the Zettaura team: Zettaura builds AI employees for business workflows, including contracts, events, AI assistants and brand operations. For contract review, e-signature and lifecycle tracking, see ZiaSign.



