Follow the risk across documents
A Romanian software supplier receives a customer-drafted SaaS agreement. On first reading, its main risk provisions appear workable: there is a liability cap, the indemnity language looks familiar, the data-processing addendum addresses security incidents, and the service levels provide credits for downtime. The difficulty emerges only when the documents are read together. A single security incident could trigger an indemnity, an exclusion from the cap, separate obligations under the addendum, service credits, and a termination right. The material risk sits in the chain connecting those provisions, not necessarily in any one clause.
Effective contract review traces the claims, losses, costs, and remedies that may bypass the supplier's liability cap across the agreement and its related documents.
Define the exposure
Ask which claims, losses, costs, and remedies can bypass the supplier’s contractual liability cap.
Map every connection
Link each triggering event to contractual consequences, source wording, the applicable ceiling, and missing information.
Test real incidents
Use data breaches, prolonged outages, and IP claims to expose cumulative remedies and negotiation priorities.
Cross-document checklist and clause-interaction map
Build a cross-document issue checklist before asking for conclusions. It should cover covered loss, indemnities, exclusions from the cap, any separate subcaps, data-protection liability, service credits, termination rights, and the order of precedence between documents. It should also flag connective wording such as “without prejudice,” “in addition to any other remedies,” and “notwithstanding anything to the contrary.” Those phrases often determine whether apparently limited obligations remain limited when another clause applies.
Next, require an evidence-linked clause-interaction map rather than a collection of isolated comments. Each row should identify a triggering event, the contractual consequence, the relevant wording, the source document, the relationship to the cap, and any missing information. One row might connect a security obligation in the data-processing addendum to an indemnity in the main contract and then to an exclusion for confidentiality breaches. Include enough quoted wording and a precise clause reference for the lawyer to verify the connection against the document.
Personal-data breach and prolonged outage tests
Run a personal-data breach through the map first. Separate investigation and remediation costs, claims by data subjects, claims made by the customer, defence expenses, regulatory exposure, and notification duties. Then ask whether each category falls within the general damages regime, an indemnity, or an exclusion from the cap. If the agreement does not clearly say whether remedies accumulate, record an interpretation issue. Do not let the analysis silently convert ambiguous drafting into a confident legal conclusion.
The second incident test is a prolonged outage. Service credits may initially look like a contained remedy, but the review must establish whether they are exclusive or cumulative with damages and termination. Thresholds matter: the same outage might earn credits during one measurement period, become a material breach after a specified duration, and support termination after repeated failures. A useful memorandum will show that sequence and distinguish consequences stated expressly in the contract from consequences that depend on disputed facts or legal characterisation.
Intellectual-property claim, legal interpretation, and negotiation position
The third test is a third-party intellectual-property claim. Trace who controls the defence, what notice and cooperation the client must provide, whether the supplier may modify or replace the service, and whether the IP indemnity is fully uncapped or subject to a separate ceiling. Check exclusions for customer materials, instructions, modifications, and combinations with other systems. The incident scenario turns abstract language into a practical allocation-of-risk decision and may reveal that a nominally unlimited indemnity is narrower than it first appears—or broader.
Across all three tests, separate explicit contractual consequences from legal interpretation. If the agreement expressly excludes an IP indemnity from the general cap, that is a textual finding. Whether an administrative fine can lawfully be transferred, whether two remedies may be accumulated, or whether a loss falls within an exclusion may depend on governing law, public-policy limits, the nature of the claim, and facts not yet in the file. Label those matters as questions for legal verification and state what additional facts or authorities are required.
Convert the map into a prioritised negotiation position. A critical amendment might introduce an aggregate subcap for security and data-protection obligations. Another might state that service credits are the exclusive financial remedy for downtime that does not amount to material breach. Further drafting could prevent double recovery by confirming that indemnity payments, damages, and response costs arising from the same incident count once against the applicable ceiling. The amendments should also narrow overbroad carve-outs and establish a clear order of precedence between the agreement and its schedules.
Structured analysis and drafting in Wisanna
In Wisanna, the pattern can begin as a concrete legal task inside a private and secure legal-AI workspace built for lawyers: identify every route by which liability may exceed the cap across an agreement and its data-processing addendum. AI Chat can support structured questions about the matter materials, but its outputs are not automatically correct or final. The usefulness of the work comes from the defined objective, the issue checklist, the incident tests, and the requirement to connect every finding to relevant contractual wording.
Once the findings have been checked, the lawyer can develop an editable legal document in Wisanna Draft or continue drafting in Microsoft Word through the Wisanna add-in. The deliverable might be a client memorandum, a clause-interaction table, or proposed amendments for the next negotiation round. The reusable playbook is simple: define the exposure question, map clauses across documents, test concrete incidents, separate text from interpretation, prioritise the resulting risks, and amend the interactions that create exposure—not merely the individual sentences that look unfavourable.
Turn liability pathways into negotiation-ready drafting
Use Wisanna to question matter materials, verify clause interactions, and develop the checked findings into an editable legal document.
See Wisanna's lawyer-controlled workflow