✒️ Blog / Practice notes

Building a Clause Playbook: How to Make AI Review Your Firm's Way

An AI review tool is only as good as the standard you give it. Here's how to build a clause playbook that turns your firm's judgment into reusable rules — and how to write those rules so the machine can actually check them.

Every firm has a way of reviewing contracts. The problem is that most of the time it lives in someone's head. The senior associate knows the firm's position on limitation of liability; the partner knows the walkaway line on indemnities; the paralegal knows which clauses the client's CFO will never accept. None of it is written down, none of it is consistent, and none of it can be delegated — to a junior, to a sales team, or to an AI.

The fix is the thing legal operations people have been building for years: a contract playbook. It is the missing ingredient in AI contract review, because the machine's job is to compare every contract against your standard — and if your standard doesn't exist as written rules, the machine has nothing to compare against. This article walks through what a playbook is, how to build one, and how to write it so an AI can actually audit against it.

What a playbook is — and what it isn't

A playbook is not a template library or a giant legal encyclopedia. It is a rulebook for exceptions: a written record of how your firm handles the clauses that recur in every deal. In the framing used by modern legal operations teams, a playbook does two jobs:

  • The routing layer. Which contracts get reviewed by whom — by dollar value and risk tier. A low-risk NDA with a known counterparty may need no legal review; a high-value MSA with heavy liability exposure always does.
  • The position layer. For every recurring clause, the preferred position, the acceptable fallbacks, and the walkaway line. This is the layer an AI can consume.

Together they make judgment reusable instead of re-litigated on every deal. That is the entire point.

The anatomy of one playbook entry

For each clause type you care about, a good entry has five parts:

  1. The baseline. Your preferred position — what your standard template says, or the language you would write if you could.
  2. Tiered fallbacks. Pre-approved alternatives, ordered by how much they move the risk. Tier one: acceptable without escalation. Tier two: requires a named approver. Each tier makes negotiation faster without losing control.
  3. The walkaway line. The hard boundary — the position so far outside your risk tolerance that the deal must be declined or escalated to a decision-maker.
  4. The escalation owner. Who decides when a request goes beyond the fallbacks. Payment-term exceptions go to finance; liability-cap changes go to the general counsel; never "legal" as an anonymous blob.
  5. The rationale. One line on why the position exists. This is what keeps the playbook alive — a new reviewer can understand why before they negotiate what.

Which clauses to start with

You do not need a playbook for every clause in the Uniform Commercial Code. The negotiation battles concentrate in a small set — the practical "dirty dozen" that drive nearly all the risk and nearly all the back-and-forth:

  • Indemnification (and its interplay with the cap)
  • Limitation of liability
  • Force majeure
  • Termination rights and cure periods
  • Assignment and change of control
  • Confidentiality and data security
  • Intellectual property ownership and licenses
  • Warranties and disclaimers
  • Payment terms and pricing adjustments
  • Auto-renewal and evergreen terms
  • Governing law and dispute resolution
  • Non-compete and exclusivity

Start with the six that matter most for your deal flow — for a SaaS firm that is typically indemnification, limitation of liability, confidentiality, IP, auto-renewal, and payment terms. Two or three agreement types, six clauses, done well, beats twelve clauses done vaguely.

Writing rules an AI can actually check

This is the step that separates a playbook from a policy document. A machine cannot check "liability should be reasonable." It can check a rule with four parts:

  • The clause type. Limitation of liability, force majeure, indemnification.
  • The condition. What you're checking for — the cap amount, the event list, the reciprocal obligation.
  • The acceptable range. The number or wording that counts as passing.
  • The severity. How bad a deviation is — high, medium, low.

Concrete examples of checkable rules:

  • Limitation of liability must cap damages at one times annual fees paid, with carve-outs for IP indemnity, confidentiality and data security breaches, and gross negligence. (Severity: high if the cap is missing or the carve-outs are absent.)
  • Force majeure must expressly include pandemic or epidemic and governmental orders, require notice within 14 days, and must not excuse the payment of money.
  • Indemnities for IP infringement and confidentiality must be mutual, with notice, tender of defense, and cooperation obligations.
  • Termination for convenience requires at least 30 days' notice; auto-renewal requires at least 60 days' notice before the renewal date.

Notice what these rules have in common: they name a clause, a condition, a threshold, and a consequence. That is exactly the format an AI review tool consumes — it classifies each clause in the document, compares it against the rules, and returns a list of deviations rated by severity.

Building it from your real deals

The biggest mistake is drafting the playbook from templates and theory instead of from what your firm actually negotiates. The practical method:

  1. Mine the record. Pull the last 60–90 days of executed contracts. Note every clause where the final language differed from your standard, every redline you accepted, and every exception that was approved.
  2. Interview the deal team. Ask the partners and senior associates what they push back on, what they always concede, and what makes them walk away. The answers become your baselines and walkaway lines.
  3. Involve the business. Sales, procurement, finance, and security see contracts from angles legal doesn't. Payment-term positions belong to finance; data-security requirements belong to security. A playbook built in a legal silo fails in production.
  4. Write in plain English. The playbook is read by lawyers, legal ops, and business reviewers. If a clause position needs three paragraphs to explain, simplify the rule before you ship it.
  5. Version it. Date every revision and record what changed and why. The playbook is a living document; without a version trail it becomes a rumor.

Governance: one owner, regular review

Playbooks fail for a consistent reason: no owner. The standard guidance from legal operations teams is blunt — shared ownership means no ownership, and the playbook rots into a private notebook of exceptions. The rules that work name one person: usually a legal operations lead or a senior lawyer, whose job includes:

  • Running a regular review — quarterly is the common cadence — where exceptions approved since the last review are promoted into the playbook if they're recurring.
  • Keeping an override log, so that when someone goes outside the fallbacks, the reason is recorded rather than lost.
  • Watching the metrics that matter: contract turnaround time, deviation rate from standard clauses, and where approvals bottleneck.

The review loop is what keeps the playbook honest. A rule that gets overridden three times in a quarter is either wrong or undocumented; the review decides which.

Common failure modes — and the fix

  • Too long. A 200-page rulebook is a reference manual, not a playbook, and nobody reads it. Keep entries to what a reviewer needs in the moment.
  • Too vague. "Reasonable," "commercially acceptable," and "industry standard" are not checkable. Convert them into thresholds.
  • No escalation owners. A fallback without a named approver is a dead end that stalls every deal it touches.
  • Never updated. A playbook that doesn't reflect what the firm actually accepted last quarter teaches reviewers to ignore it.
  • Built from templates, not deals. The playbook should be a transcript of your firm's real judgment, not a copy of someone else's.

The AI payoff

With the playbook written as checkable rules, the review workflow — covered in our look at how AI reads a contract and the clauses it actually flags — becomes an audit: classify every clause, compare against the rules, return a rated exception list. The machine guarantees completeness and consistency; the playbook guarantees the comparison means something; the lawyer verifies the flags and judges the materiality. The compounding effect is real: the more matters you run through the same playbook, the more consistent your firm's risk tolerance becomes across deals — which is exactly what clients pay for.

Two caveats from the earlier articles apply unchanged: a flag from the machine is a hypothesis until you open the source passage, and the confidentiality of the contracts depends on the tool you run them through. Grounded review tools and local processing handle both.

How Lawyer Assistant implements this

This is the exact design of Lawyer Assistant's compliance playbook scan. You define the rules above in plain language — no code — and the app classifies every clause in the document and checks each one against your playbook. Findings come back with severity ratings and explanations, and each finding links to the source text so your verification step is a click away. Because it runs locally on your machine, the standards and the contracts stay on your hardware. Set the rules up once, and running the same scan across the next portfolio takes minutes.

A starter playbook to adapt

Eight rules to begin with — adjust the numbers to your firm's actual risk tolerance:

  1. Force majeure must expressly include pandemic or epidemic and governmental orders, require notice within 14 days, and must not excuse the payment of money.
  2. Limitation of liability: cap at one times annual fees, with carve-outs for IP indemnity, confidentiality and data security, and gross negligence.
  3. Indemnities must be mutual for IP infringement and confidentiality breaches, and must include notice, tender of defense, and cooperation obligations.
  4. Termination for convenience requires at least 30 days' notice; termination for cause requires a 30-day cure period.
  5. Assignment requires prior written consent, not to be unreasonably withheld.
  6. Confidentiality survives for at least three years, or indefinitely for trade secrets.
  7. Auto-renewal requires notice of at least 60 days before the renewal date.
  8. Governing law and venue must be our home jurisdiction, or a neutral alternative agreed in advance.

Start with these, run them against your last twenty contracts, and watch which ones your own record contradicts. Those are the rules that need the conversation.

The bottom line

The AI in your review tool is a comparator, and a comparator needs a standard. A clause playbook turns the judgment your firm has always exercised — inconsistently, in people's heads — into written, checkable rules that every reviewer and every machine can apply the same way. Build it from your real deals, write it in checkable form, give it one owner, and review it quarterly. Do that, and the AI stops being a demo and becomes the enforcement arm of your firm's actual standards.

"The playbook is the standard. The AI is the auditor. The lawyer is the judge."

Sources & further reading

This article is general information about technology and professional practice. It is not legal advice for any specific matter, and rules vary by jurisdiction — verify against the authority applicable to your matter.

Questions, answered

The key questions from this article, answered plainly.

What is a contract review playbook?

A written rulebook that captures how your firm handles recurring contract clauses. For each clause type it names the preferred position, pre-approved fallback language, the walkaway line, and who owns each escalation — so a reviewer (human or AI) knows what to accept, what to push back on, and what to escalate without re-deciding every deal.

What should a playbook contain for each clause?

Five things: the baseline or preferred position, tiered pre-approved fallbacks, the hard walkaway line, the escalation owner, and a one-line rationale for why the position exists. Build it for the clause types that carry the risk in your deal flow — typically indemnification, limitation of liability, force majeure, termination, assignment, confidentiality, IP, and payment terms.

How do you write rules an AI can actually check?

State each rule as a checkable condition: the clause type, the condition you care about, the acceptable range, and a severity. For example, limitation of liability must be at least one times annual fees, with carve-outs for IP indemnity, confidentiality, and gross negligence — or force majeure must expressly include pandemic or epidemic. The AI classifies each clause and compares it against those rules, flagging deviations with severity ratings.

Who should own and maintain the playbook?

One named person — usually a legal operations lead or a senior lawyer. Shared ownership means no ownership, and the playbook rots into a private notebook of exceptions. The owner runs a regular review (quarterly is the common cadence), promotes recurring exceptions into the playbook, and keeps the override log honest so the rules stay in touch with real deals.

Filed under Practice notes · Contract review · Playbooks · Legal ops ← All articles
Next steps

Put it to work on your own documents.

Lawyer Assistant runs entirely on your machine — install it in minutes, read the documentation, or browse more notes from the Legal Desk.