BlogContract Operations13 min read

Contract Review Checklist Before Signing: 2026 Guide

Use this checklist to review parties, authority, pricing, scope, liability, privacy, IP, renewal, termination and signing evidence before you sign a contract.

Zettaura Editorial

Zettaura Innovations

Share
Contract Review Checklist Before Signing: 2026 Guide

A contract review checklist before signing should answer four questions: who is bound, what each side must do, what it costs, and what happens if things go wrong. Before you sign, check party names, signer authority, scope, payment terms, taxes, renewal, termination, liability, indemnity, confidentiality, data protection, intellectual property, dispute resolution, governing law, and signature validity. Then record the approval trail and store the final signed copy where finance, legal and operations can find it. This is not legal advice. Use the checklist below to catch business and legal issues early, then confirm high-risk terms with counsel.

Contract review checklist before signing: the one-page version

Use this first as a quick pass. If any answer is unclear, pause signing and route the contract for review.

AreaWhat to checkRed flag before signing
PartiesCorrect legal names, registered addresses, tax IDs and group entityContract names a brand, trade name or wrong group company
AuthoritySigner has authority under board approval, delegation matrix or roleSales, HR or procurement signs without approval
ScopeDeliverables, service levels, acceptance criteria and exclusionsVague phrases like as required or best efforts only
PriceCurrency, taxes, invoicing cycle, payment due date and late feesPrice in email differs from contract or order form
TermStart date, end date, renewal and notice periodAuto-renewal with long notice window missed by operations
LiabilityCap, exclusions, consequential loss and carve-outsUnlimited liability for ordinary service failure
IndemnityWho covers third-party claims and for what conductOne-sided IP, data or tax indemnity without limits
DataPersonal data, processor/controller roles, security and breach noticeNo data processing terms where personal data is handled
IPOwnership of pre-existing IP, work product, feedback and licencesCustomer gives away core product IP accidentally
ConfidentialityDefinition, exclusions, term and permitted disclosuresConfidentiality ends too early for sensitive information
TerminationConvenience, cause, cure period, refund and transition supportNo exit right despite long lock-in
DisputesGoverning law, courts, arbitration, venue and escalationForeign venue for a small-value local contract
SignaturesValid e-sign method, audit trail and stamping where applicableContract type may require wet ink, notarisation or registration

For India-specific electronic contract rules, also read IT Act Section 10A: Electronic Contracts in India. For clause-level extraction before review, see AI Clause Extraction from Contracts: Practical Guide.

Step 1: confirm the basics before reading clauses

Start with the facts. Many contract disputes begin with simple administrative errors.

Check these items first:

  • The full legal name of each party.
  • The registered office or principal business address.
  • CIN, LLPIN, GSTIN, PAN, EIN or other business identifier where relevant.
  • The correct contracting entity in a group structure.
  • Whether the person signing has authority.
  • Whether the contract refers to the right proposal, statement of work, purchase order or order form.
  • Whether all exhibits, schedules and annexures are attached.

If you are an Indian company, the basic enforceability of agreements sits within the contract law framework under the Indian Contract Act, 1872 on India Code. If you are signing in the US, state law and the Uniform Commercial Code may also matter for sale of goods and commercial terms. Confirm legal interpretation with counsel, especially for large commitments or regulated work.

A practical operating rule: do not approve a contract if the signature block, order form and invoice entity do not match. Fix the entity mismatch before signing, even if the commercial terms look correct.

Step 2: review commercial terms in numbers, not words

Commercial review should be numerical. Rewrite the deal in a small table before approving it.

TermQuestion to answerExample check
Base feeWhat is the fixed amount?INR 1,80,000 per year or USD 24,000 per year
Variable feeWhat triggers extra charges?Per employee, per document, per API call, per site
TaxesWho pays GST, withholding, sales tax or VAT?Fee is exclusive of GST, customer pays applicable GST
Payment dateWhen does cash leave the business?Net 15 from invoice date, not from receipt date
Late feeIs it reasonable and lawful?1.5 percent per month may need finance approval
Price increaseIs there a cap?Renewal price can rise by 7 percent, not uncapped
ExpensesAre travel or out-of-pocket costs pre-approved?Expenses require written approval and receipts

Worked example: Indian SaaS purchase

Assume your startup is buying an HR tool for INR 2,40,000 per year plus GST. The order form says annual upfront payment. The master agreement says prices may increase at renewal and the contract auto-renews unless cancelled 60 days before the renewal date.

Before signing, calculate the cash and operational impact:

  • Year 1 cash outflow: INR 2,40,000 plus applicable GST.
  • Renewal risk: if notice is missed, the business may owe another year.
  • Approval required: finance for budget, HR for business owner approval, legal for auto-renewal and liability.
  • Calendar action: add renewal review 90 days before expiry, not 60 days.

The issue is not whether the software is useful. The issue is whether the contract lets you stop, renegotiate or reduce seats before the renewal commitment is triggered.

Worked example: US customer agreement

Assume your company sells a USD 36,000 annual SaaS subscription to a US customer. The customer paper includes net 60 payment, unlimited service credits, broad indemnity, New York law, and a requirement to comply with all customer policies.

Before signing, ask:

  • Can your cash flow handle net 60, or do you need net 30?
  • Are service credits capped, for example at one month of fees?
  • Does the indemnity apply only to third-party IP claims, or to any loss?
  • Have you received and reviewed the customer policies incorporated by reference?
  • Does your insurance cover the contractual obligations?

If the customer has strong bargaining power, you may still accept some terms. But the decision should be visible and approved, not buried in a signed PDF.

Legal review does not mean rewriting every sentence. Focus on clauses that change your risk profile.

ClauseWhat good looks likeWhat to escalate
Limitation of liabilityClear cap tied to fees paid or payableUnlimited liability or cap exclusions that swallow the cap
IndemnityLimited to defined third-party claimsBroad indemnity for all losses, penalties and costs
WarrantiesSpecific promises you can actually meetAbsolute promises such as error-free, uninterrupted or compliant with all laws
TerminationTermination for cause with cure period and clear post-termination dutiesNo cure period or immediate termination for minor breach
ConfidentialityStandard exclusions for public information, prior knowledge and compelled disclosureNo exclusions or perpetual obligations for non-sensitive data
Non-solicitNarrow people, time and geographyApplies to all employees, contractors and affiliates worldwide
Audit rightsReasonable notice, business hours, confidentiality and frequency limitsCustomer can audit systems any time without limits
AssignmentAllows assignment in merger, acquisition or restructuringConsent needed for any internal reorganisation

For US electronic records and signatures, the federal ESIGN Act provides that a signature, contract or record may not be denied legal effect solely because it is electronic, subject to exceptions and consent rules. You can read the official text in the Electronic Signatures in Global and National Commerce Act on GovInfo.

For India, electronic contracts are recognised under the Information Technology Act framework, with important exclusions for certain document types and formalities. See the Information Technology Act, 2000 on India Code and confirm your specific document type with counsel.

Step 4: review data, security and privacy obligations

If the contract involves personal data, customer data, employee data, financial data, health data or confidential business data, do a separate data review.

Check:

  • What data is shared, accessed, stored or processed.
  • Whether each party is a controller, processor, fiduciary, processor, service provider or independent business depending on the applicable law.
  • Whether a data processing agreement is required.
  • Where data is hosted and whether cross-border transfers apply.
  • Security controls, incident notice timelines and audit rights.
  • Deletion or return obligations after termination.
  • Whether subcontractors can be used without approval.

For EU personal data, Article 28 of the GDPR sets out processor contract requirements. Use the official regulation text on EUR-Lex for Regulation (EU) 2016/679 as the primary source and get counsel to map it to your contract.

For US financial institutions and certain covered businesses, vendor security obligations may also be affected by the FTC Safeguards Rule. The FTC explains business obligations in its Safeguards Rule guidance.

A practical rule for business teams: if the contract mentions personal data but has no data processing terms, do not sign until legal or privacy reviews it.

Step 5: check tax, payment and vendor onboarding documents

Contract review should connect to finance operations. A signed contract that cannot be invoiced, taxed or paid cleanly creates avoidable work.

For India deals, check:

  • GSTIN and place of supply.
  • Whether GST is included or extra.
  • TDS position, if applicable.
  • Billing milestone and invoice format.
  • Purchase order requirement.
  • Bank account details and vendor verification.

For US vendor or contractor payments, finance may need tax forms before payment. The IRS provides official instructions for Form W-9, commonly used to request a US taxpayer identification number and certification.

Add a rule to your checklist: if finance cannot tell when and how the contract will be billed or paid, the commercial review is incomplete.

Step 6: verify signing method, stamping and evidence

Before signing, confirm that the chosen signature method fits the document, jurisdiction and internal policy.

Check these items:

  • Is an electronic signature allowed for this document type?
  • Does the signing method capture signer identity, consent, timestamp and document hash or tamper evidence?
  • Is an audit trail generated and stored with the final document?
  • Does the contract need stamp duty, registration, notarisation or witnesses?
  • Are all signers signing the same final version?
  • Are initials required on schedules, annexures or handwritten changes?

In India, some documents may need wet ink, registration or special formalities even when ordinary commercial contracts can be electronically executed. In the US, ESIGN and state UETA rules often support electronic signatures, but exceptions exist. Confirm edge cases with counsel before relying on e-signature alone.

For contract and e-signature operations, ZiaSign helps teams understand, approve, sign and track agreements in one secure workflow, with audit trails and contract lifecycle management in one workspace. Use any tool you choose, but make sure the evidence file travels with the signed contract.

Step 7: create an approval record before signature

A contract is ready to sign only when the right people have approved the right version.

Use this approval matrix as a starting point:

Contract typeBusiness ownerFinanceLegalSecurity or privacyLeadership
Low-value NDARequesting teamNot requiredIf non-standardNot requiredNot required
Vendor SaaS under budgetDepartment headYesIf vendor paper or high riskIf data access existsIf multi-year
Customer MSASales leadFor payment and taxYesIf customer data involvedIf liability exceeds policy
Employment or contractor agreementHRFor compensationYesIf data or IP sensitiveAs per delegation matrix
Strategic partnershipBusiness sponsorYesYesUsually yesYes

Approval records should show:

  • Contract name and version.
  • Counterparty.
  • Value and term.
  • Key deviations from standard terms.
  • Approvers and timestamps.
  • Final signed copy location.
  • Renewal owner.

Do not rely on scattered email replies such as looks fine. Ask approvers to approve a named version with a date.

Step 8: final pre-signature red flag list

Stop and escalate if you see any of these:

  • The contract value is higher than the approved budget.
  • The term is longer than expected.
  • Auto-renewal notice is shorter than your internal review cycle.
  • Liability is unlimited or much higher than contract value.
  • Indemnity covers first-party losses, regulatory fines or broad negligence without review.
  • The contract includes documents by link that no one has read.
  • The other party can change terms unilaterally.
  • You must comply with policies that are not attached.
  • The contract grants broad IP ownership over your tools, templates, software or know-how.
  • Personal data is processed but no data protection terms exist.
  • The signer is not authorised.
  • The document type may require stamping, registration, witnesses or wet ink.

If a red flag appears, the answer is not always no. The right answer may be price adjustment, narrower wording, additional approval, insurance confirmation or a side letter.

FAQ

Who should review a contract before signing?

The business owner should review scope and deliverables. Finance should review price, tax, invoicing and payment. Legal should review liability, indemnity, IP, termination, dispute terms and signing validity. Security or privacy should review contracts involving sensitive data or system access.

Can I use the same checklist for vendor and customer contracts?

Yes, but the emphasis changes. For vendor contracts, focus on cost, renewal, data access, service levels and exit rights. For customer contracts, focus on payment, acceptance, liability, indemnity, support obligations and whether your team can perform what the contract promises.

What is the biggest mistake before signing?

The biggest mistake is reviewing only the commercial page and not the incorporated documents. Order forms, statements of work, online terms, policies, data processing addenda and schedules can contain obligations that matter as much as the main agreement.

Is an electronic signature enough?

Often yes for ordinary commercial contracts, but not always. The answer depends on jurisdiction, document type, consent, evidence, stamping, registration and any sector-specific rule. Check the applicable law and confirm with counsel for high-value or unusual documents.

How long should contract review take?

Simple low-risk contracts can be reviewed quickly if you use standard templates and an approval matrix. High-value, regulated, cross-border or non-standard contracts need more time. Track turnaround by stage: business review, legal review, counterparty negotiation, approval and signature.

Closing note

A good contract review checklist before signing is not a legal formality. It is an operating control that protects cash flow, delivery teams, customer relationships and future fundraising or diligence.

Start with the one-page checklist, adapt it to your approval limits, and make every signed contract easy to find later. For high-risk terms, regulated data, unusual signing requirements or cross-border disputes, use this guide as preparation and confirm the final position with counsel.

From the Zettaura team: Zettaura builds AI employees for business workflows, including contracts, events, AI assistants and brand operations. For contract review, e-signature and lifecycle tracking, see ZiaSign.

  • Contract Operations
  • Legal Operations
  • Business Contracts
  • E-Signature
Share

Keep reading