The Vendor Contract Risk Scanner: Flag Risky Clauses and Get a Negotiation Script

Why this prompt matters
Rubber-stamping a contract under deadline pressure is how companies end up locked into auto-renewal clauses that convert to full annual commitments, liability caps that leave them exposed after a vendor's data breach, or unilateral price-increase language that turns a $30,000 contract into a $45,000 one at the next renewal with no negotiation required. Catching these terms before signing takes 15 minutes with a prompt like this one; catching them after signing means a renegotiation, a legal escalation, or living with the bad terms until the next renewal cycle a year later.
What we use it for
Your company's project management SaaS vendor sends a 22-page renewal agreement three business days before the auto-renewal deadline. Legal review normally takes a week, but you need to know today whether anything in the contract needs to be pushed back on before you sign or let the renewal window close.
Prompt
You are a senior commercial contracts attorney with 15 years of experience reviewing SaaS and vendor agreements for mid-market companies. CONTEXT: I'm about to sign a vendor contract and need a risk assessment before I commit. Company: [YOUR COMPANY NAME]. Vendor: [VENDOR NAME]. Contract type: [SAAS SUBSCRIPTION / SERVICES AGREEMENT / SOW / OTHER]. Our leverage: [WE'RE A NEW CUSTOMER / WE'RE RENEWING / WE'RE A LARGE ACCOUNT FOR THEM / WE HAVE COMPETING OFFERS]. Below is the full contract text: [PASTE CONTRACT TEXT HERE] TASK: 1. Read the entire contract and identify every clause that creates risk, cost exposure, or an unfavorable obligation for [YOUR COMPANY NAME]. 2. For each risky clause, classify its severity as HIGH, MEDIUM, or LOW based on financial and legal exposure. 3. For each HIGH and MEDIUM clause, draft a specific redline — the exact replacement or added language — that would make it acceptable. 4. For each redline, write one sentence of negotiation talking points I can say to the vendor's rep to justify the ask. 5. Flag whether each clause is a hard dealbreaker or just worth pushing on. CONSTRAINTS: - Do not flag standard, market-typical clauses as risks just because they exist (e.g., a standard 30-day payment term is not a red flag). - Focus on: auto-renewal terms, liability caps and indemnification, data ownership and deletion rights, unilateral price-increase clauses, termination rights, SLA remedies (or lack thereof), and IP assignment. - If the contract text is incomplete or a section is missing, say so explicitly instead of guessing. - Keep each redline to 2-3 sentences maximum — I need language I can paste into a redlined document, not a legal memo. OUTPUT FORMAT: For each flagged clause: ## [Clause name] — [HIGH/MEDIUM/LOW] **What it says:** [1-sentence summary] **Why it's a problem:** [1-2 sentences] **Suggested redline:** [exact replacement language] **Negotiation talking point:** [1 sentence] **Dealbreaker?** [Yes/No] End with a 3-bullet summary: total clauses flagged, how many are dealbreakers, and your overall recommendation (sign as-is / sign with redlines / walk away).
Result
## Auto-Renewal Term — HIGH
What it says: The agreement automatically renews for a full 12-month term unless either party provides written notice of non-renewal at least 90 days before the current term ends.
Why it's a problem: A 90-day notice window is unusually long for a mid-market SaaS contract (30-60 days is standard), and missing it locks you into another full year at current or increased pricing with no exit option.
Suggested redline: "This Agreement shall automatically renew for successive 12-month terms unless either party provides written notice of non-renewal at least thirty (30) days prior to the end of the then-current term."
Negotiation talking point: "A 30-day notice window is standard across the vendors we're evaluating — we'd like to align this term with market practice."
Dealbreaker? No
## Unilateral Price Increase — HIGH
What it says: Vendor may increase subscription fees by up to 15% annually upon renewal with 30 days' notice, at its sole discretion.
Why it's a problem: There's no cap tied to CPI or a negotiated ceiling, and no right for you to terminate without penalty if you reject the increase — you're locked in even if the new price is unacceptable.
Suggested redline: "Vendor may increase fees upon renewal by no more than the greater of 5% or the annual CPI increase, and Customer may terminate without penalty within 30 days of receiving notice of any increase exceeding this cap."
Negotiation talking point: "We need price predictability for budgeting — capping increases to CPI or 5%, whichever is greater, is standard in our other vendor agreements."
Dealbreaker? No
## Limitation of Liability — MEDIUM
What it says: Vendor's total liability under the agreement is capped at the fees paid in the prior three months, and excludes all indirect and consequential damages including data loss.
Why it's a problem: A three-month cap is thin relative to the potential cost of a data breach or extended outage affecting your operations, and the blanket exclusion of data loss damages is aggressive even for a SaaS agreement.
Suggested redline: "Vendor's liability cap shall be the greater of twelve (12) months of fees paid or $250,000, and shall not apply to breaches of Vendor's data protection or confidentiality obligations."
Negotiation talking point: "Given the volume of customer data this platform will process, we need the liability cap to reflect that exposure, particularly excluding data protection breaches."
Dealbreaker? No, but worth escalating if vendor refuses
Summary: 7 clauses flagged (3 HIGH, 3 MEDIUM, 1 LOW). 0 hard dealbreakers identified. Recommendation: sign with redlines — none of the flagged terms are unusual enough to walk away over, but the auto-renewal window, price-increase cap, and liability cap should all be pushed back on before signing, particularly given this is a multi-year commitment.
Most "review this contract" prompts fail the same way: they produce a plain-language summary of what the contract says, which is not the same thing as telling you what to actually do about it. A summary confirms you read the document. A risk scanner tells you which three clauses to push back on before you sign, and gives you the exact words to use when you do.
Why this prompt is structured the way it is
The prompt opens by assigning a specific role — a senior commercial contracts attorney — rather than a generic "helpful assistant" framing. This matters because it anchors the model's judgment calls (what counts as a risky clause, what's market-standard) to a specific professional perspective instead of a vague, overly cautious one that flags everything as a potential concern.
The constraints section does most of the real work. Without an explicit instruction not to flag standard clauses, general-purpose prompts tend to produce a wall of low-value flags — a standard 30-day payment term, a routine confidentiality clause — that buries the two or three terms that actually matter under noise. Naming the seven specific risk categories to focus on (auto-renewal, liability caps, data ownership, price increases, termination rights, SLA remedies, IP assignment) keeps the output concentrated on the clauses that create real financial or legal exposure in vendor contracts specifically, rather than trying to be a general legal review tool.
The redline requirement is what makes this useful, not just informative
Most contract-review prompts stop at identifying problems. This one requires a specific redline — exact replacement language — for every flagged clause above LOW severity. That's a deliberate design choice: a flagged risk without proposed replacement language just creates more work, because now you have to draft the fix yourself. Requiring the model to draft usable redline text turns the output into something you can paste directly into a tracked-changes document rather than a list of homework.
The negotiation talking point for each redline exists for a different reason: contract negotiation isn't just about having the right legal language, it's about having a plausible, non-confrontational justification to say out loud to a vendor's account rep who is often not a lawyer themselves. "Standard across vendors we're evaluating" and "needed for budget predictability" are framings that get redlines accepted without escalating to a legal standoff.
The dealbreaker flag prevents the most common failure mode
Without an explicit instruction to distinguish dealbreakers from negotiable points, contract-review prompts tend to either treat every flag as equally urgent or bury the genuinely serious issues among routine pushback items. Asking the model to explicitly mark Yes/No on dealbreaker status forces a judgment call up front, so the summary at the end can give an honest sign/negotiate/walk-away recommendation instead of a noncommittal "here are some things to consider."
Where this prompt is weakest, and how to compensate
This prompt is not a substitute for actual legal review on high-value or unusual contracts — it's a triage tool for catching common, well-understood risk patterns quickly, particularly under time pressure. For contracts above a materiality threshold your company should already have, or for genuinely unusual clauses the model flags as ambiguous, route to actual counsel. The prompt is explicitly instructed to say when contract text is incomplete rather than guess, which helps surface when a fuller review is warranted — but that instruction only works if you read past the headline recommendation to the caveats.
Adapting it for your situation
The bracketed leverage field — new customer, renewal, large account, competing offers — changes what the model should suggest as realistic asks. A new customer with competing offers has genuine leverage to push back hard on price-increase caps; a small account renewing with a dominant vendor has less room, and the negotiation talking points should reflect that instead of suggesting asks that will simply get ignored.