Guides preparation of a risk-tiered issues memo for an enterprise SaaS agreement review in a regulated-data context where privacy compliance, security controls, service levels, and contractual terms must be assessed against the vendor's representations.
Scanned 9/11/2026
Install to Claude Code
npx -y skills add sunyifeisb-art/legalwork --skill review-enterprise-saas-agreement --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Review Enterprise Saas Agreement?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sunyifeisb-art-review-enterprise-saas-agreement)More formats (shields.io, HTML) on the badges page.
---
name: review-enterprise-saas-agreement
task_id: corporate-ma/review-enterprise-saas-agreement
description: Guides preparation of a risk-tiered issues memo for an enterprise SaaS agreement review in a regulated-data context where privacy compliance, security controls, service levels, and contractual terms must be assessed against the vendor's representations.
activates_for: [planner, solver, checker]
---
# Skill: Enterprise SaaS Agreement Review (Healthcare)
## 1. Subject-matter triage
- Treat the review as a side-by-side contract-and-diligence comparison, not a standalone contract read.
- Identify all operative source documents first, then map them by function: governing agreement, order form or statement of work, privacy/data-processing addendum, security exhibit, assurance materials, internal risk memo, vendor responses, and pre-signature communications.
- If multiple products, regions, entities, or service lines are in scope, enumerate them before analysis and assess each independently; do not collapse distinct risk profiles into one pass.
- If the record is missing a document needed to confirm a key obligation, flag the gap as an issue rather than assuming the missing term is benign.
## 2. Failure modes the skill is correcting
- Reviewing service levels, liability caps, and indemnity in isolation from the vendor’s actual control posture, which can make the memo formally accurate but commercially misleading.
- Treating privacy language as sufficient without checking whether the contract actually matches the regulated-data use case, the processing role, and the operational safeguards described in diligence materials.
- Ignoring inconsistencies between pre-signature statements and the signed paper, even where those statements may affect negotiation posture or legal risk.
- Listing problems without tying each one to the surrounding clause set, the supporting diligence source, and a concrete negotiation ask.
- Using descriptive labels like “urgent” without a consistent severity scale.
- Stating legal conclusions without naming the rule, statute, regulation, or contractual convention that supports them.
## 3. Legal frameworks / domain conventions that apply
- Read the agreement as a commercial SaaS stack: master terms govern the relationship, commercial order documents set scope and price, and privacy/security addenda control data handling and safeguards.
- For regulated health or clinical analytics data, verify that the privacy framework matches the customer’s regulatory posture and the vendor’s role as processor, service provider, business associate, or equivalent under the applicable regime.
- Check whether the contract’s use, disclosure, safeguard, subcontractor, incident notice, and return/destruction provisions are consistent with the governing privacy framework and any required downstream flow-down obligations.
- Assess service-level commitments for specificity: uptime measurement, exclusions, maintenance windows, reporting mechanics, remedies, and whether credits are the exclusive remedy.
- Assess liability allocation against the real risk envelope created by outages, data incidents, privacy failures, and continuity disruptions; a cap that is structurally disconnected from those risks is a material issue.
- Confirm that customer data ownership, permitted use, retention, export, and deletion terms are operationally workable and aligned with the diligence record.
- Confirm termination rights, suspension rights, and exit assistance against business continuity and regulatory needs; the customer should not be trapped in a failed service without a workable exit path.
- For any legal proposition, cite the controlling authority or contractual source relied on; do not leave the memo at the level of conclusion-only commentary.
## 4. Analytical scaffolds
- Build the memo issue-by-issue from the source set, using the agreement as the baseline and the diligence materials as the factual check.
- For each issue, state the governing clause or source document, the relevant factual mismatch or omission, the risk tier, the practical consequence for the client, and the requested contract change.
- Tie every issue to at least one concrete source anchor: a clause, schedule, exhibit, assurance finding, risk response, or pre-contract statement.
- Where a risk depends on scale, identify the scale from the source record before drawing the conclusion; use the transaction’s own exposure, service scope, term, data sensitivity, or operational dependency rather than invented benchmarks.
- Where a provision interacts with another provision, read them together and state the combined effect; do not analyze liability, service levels, data rights, and exit rights as isolated silos.
- When diligence materials describe controls or exceptions, test whether the contract actually requires those controls or leaves the customer dependent on non-binding assurances.
- Use an ordinal severity scale consistently across the memo, defined once and applied uniformly.
## 5. Vertical / structural / temporal relationships
- Compare pre-signature representations to the final contract to identify any gap between what was promised and what was actually bound.
- Compare privacy, security, and continuity obligations vertically: the privacy addendum may look adequate, but the security exhibit or incident clause may undermine it.
- Compare the service description against the data-processing model: if the platform handles sensitive clinical or operational data, the agreement should reflect that sensitivity in access controls, notice timing, audit rights, and subcontractor restrictions.
- Track temporal obligations separately: notice periods, response windows, renewal timing, cure periods, retention periods, deletion deadlines, and any post-termination transition support.
- Compare limitation-of-liability language against indemnity, confidentiality, security incident, and data-protection carve-outs to determine whether the remedies stack coherently or collapse into an inadequate cap.
## 6. Output structure conventions
- Produce a single risk-tiered issues memorandum in a professional M&A / commercial contracting style.
- Open with a short executive summary that identifies the highest-risk themes and the overall negotiation posture.
- Define the severity scale once near the front, then apply it consistently to every issue.
- For each issue, include: severity; issue title; the operative clause or source reference; why the current position is risky; the supporting diligence or communications source; the downstream consequence for the client; and the proposed negotiation fix.
- Every issue must close with three explicit moves: anchor the scale of the issue to the source record; cross-reference the related clause or diligence source; and state the client consequence.
- End with a Recommendations / Next Steps section that assigns action verbs, responsible internal roles, and timing tied to the transaction or diligence timeline.
- Use industry-conventional sectioning rather than a rubric-shaped checklist; do not mirror any hidden evaluation outline.
- Keep the memo concise but complete: write only operative analysis and recommended deal language, not background exposition.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!