In procurement, the lowest-priced supplier does not always offer the most commercially favourable contract.
A supplier may accept the specification and price model while proposing changes to payment terms, liability, warranties, service levels, termination rights, intellectual property, data protection or other important conditions.
These deviations can change the total risk and commercial value of the supplier’s proposal. They must therefore be identified, evaluated and resolved before the contract is signed.
A Contract Review Document, often shortened to CRD, gives the procurement team a structured way to perform this review. It documents the differences between the buyer’s preferred contract position and the supplier’s proposal, explains the potential consequences and records the final decision.
An AI agent supported by retrieval-augmented generation, or RAG, can make the preparation of a CRD faster and more consistent. However, the AI agent should support the review process—not replace the professional judgment of the buyer, legal specialist or authorised decision-maker.
LHTS Procurement Framework
Primary procurement role: Tactical
Supporting role: Procurement management
Procurement process: RFQ preparation, supplier evaluation, negotiation, contract approval and contract award
Learning level: Advanced
Related online course: Sourcing Process 2b – RFQ
Quick Answer: What Is a Contract Review Document?
A Contract Review Document compares a supplier’s proposed contract terms with the buyer’s approved contract position.
The CRD identifies deviations, assesses their commercial or operational consequences, proposes actions and records the final decision.
An AI agent can prepare a first draft of the CRD by retrieving relevant clauses, policies and approved fallback positions from a controlled knowledge base. The final analysis must still be reviewed and approved by the appropriate procurement, legal and management representatives.
Why Is a Contract Review Document Needed?
A supplier’s proposal consists of more than price.
Contract terms determine how risks, responsibilities, costs and rights are divided between the buyer and the supplier. Two suppliers may offer similar prices but very different contractual positions.
For example, one supplier may accept the buyer’s standard liability clause, while another limits liability to a small percentage of the annual contract value. One supplier may accept payment in 45 days, while another requires payment in 15 days. One supplier may accept termination rights linked to repeated service failure, while another allows termination only following a serious and unresolved breach.
These differences can affect:
- the total commercial value of the proposal;
- the buyer’s operational and financial exposure;
- the ability to manage poor supplier performance;
- the cost of changing or terminating the supplier;
- compliance with internal policies;
- the need for insurance or other risk mitigation;
- the negotiation strategy; and
- the final supplier selection.
Without a structured review, important deviations may remain hidden in contract wording or be discussed without a documented decision.
The CRD gives the sourcing team a common structure for identifying, evaluating, negotiating and approving these differences.
What Is the Purpose of a CRD?
The purpose of a Contract Review Document is to create a traceable link between the supplier’s proposed contract, the buyer’s preferred position and the final approved agreement.
A well-designed CRD should help the sourcing team answer the following questions:
- What has the supplier changed (in our std contract provided in RFQ?
- How does the proposed wording differ from the buyer’s standard position?
- Is the difference material?
- What commercial, operational, legal or compliance consequences could arise?
- Can the deviation be accepted?
- Should it be clarified or negotiated?
- Is an approved fallback position available?
- Does the issue need to be escalated?
- Who has the authority to approve the final position?
- Why was the deviation ultimately accepted or rejected?
The CRD is therefore both a working document and a decision record.
During evaluation and negotiation, it helps the sourcing team organise outstanding contract issues. At the end of the sourcing process, it records the reasoning behind the approved contract.
What Should a Contract Review Document Contain?

The exact structure depends on the organisation, category and contract risk. However, a useful CRD normally includes the following fields.
Clause and contract reference
Identify the relevant clause number, schedule or appendix in the supplier’s proposed contract.
This makes it possible for the reviewer to locate and verify the wording.
Buyer’s standard position
Describe or reference the organisation’s preferred contract clause.
The source could be a model contract, clause playbook, procurement policy or approved contract standard.
Supplier’s proposed position
Record the wording or commercial position proposed by the supplier.
The CRD should distinguish clearly between the buyer’s position and the supplier’s position.
Description of the deviation
Explain the substantive difference.
The purpose is not only to highlight different words. The reviewer must understand whether the supplier’s wording changes the rights, obligations, remedies or allocation of risk.
Potential consequence
Describe what the deviation could mean in practice.
The consequence may be financial, operational, legal, commercial, technical, reputational or compliance-related.
Initial risk assessment
Apply the organisation’s approved risk methodology.
The assessment may consider the probability of the issue occurring, the potential impact and the buyer’s ability to manage or mitigate the risk.
Proposed action
The recommended action could be:
- accept;
- clarify;
- negotiate;
- propose alternative wording;
- mitigate through another contractual mechanism;
- request specialist review; or
- escalate for approval.
Approved fallback position
Where available, include the organisation’s approved alternative position.
A fallback clause helps the buyer negotiate within agreed boundaries without requesting approval for every individual wording change.
Source and supporting evidence
Identify the source used for the comparison.
This could include the model contract, clause playbook, internal policy, risk guideline or approved precedent.
Responsible reviewer
Identify the person or function responsible for reviewing the issue.
Depending on the clause, this may be procurement, legal, finance, information security, data protection, quality, operations or another specialist function.
Final decision and rationale
Record the approved decision and the reason behind it.
This is essential when a deviation is accepted. Future contract managers should be able to understand why the position was approved.
Where Does the CRD Fit in the Procurement Process?
The CRD is primarily used during the tactical sourcing process, but preparation should begin before supplier proposals are received.
RFQ preparation
During RFQ preparation, the buyer defines the proposed contract structure, mandatory requirements and important commercial positions.

The buyer should also decide how supplier contract deviations will be submitted and evaluated.
Suppliers can, for example, be instructed to:
- accept the proposed contract;
- submit all reservations in a specified format;
- explain the reason for each requested change;
- provide proposed alternative wording; and
- confirm the commercial effect of each reservation.
This creates a more structured evaluation process.
Supplier response and evaluation
When supplier proposals are received, the buyer reviews the submitted contract reservations.
Material deviations should be included in the commercial evaluation rather than treated as an administrative issue after supplier selection.
A low price may not compensate for unacceptable contractual risk.
Negotiation
The CRD becomes an important negotiation tool.
It gives the negotiation team a structured list of outstanding issues, preferred positions, fallback positions, risk assessments and approval requirements.
It also helps the team avoid negotiating clauses independently without considering the total commercial package.
Contract approval and award
Before contract signature, all material deviations should be resolved or formally approved.
The completed CRD records the final contract position, the decision-makers and the rationale behind accepted deviations.
The approved CRD should be stored together with the final signed contract.
Contract management
The CRD can also support the contract manager after award.
It explains which issues were negotiated, which exceptions were accepted and which clauses may require special attention during contract implementation and supplier management.
How Does the CRD Connect to the Tactical Procurement Role?
The CRD is mainly a tactical procurement tool because it is closely connected to supplier evaluation, commercial negotiation and contract formation.
The tactical buyer is responsible for bringing together different perspectives.
Legal may assess legal exposure. Finance may assess payment and financial risk. Information security may review security obligations. Operations may assess service continuity and implementation risk.
The tactical buyer must combine these perspectives with:
- the sourcing strategy;
- the supplier market;
- the value of the contract;
- the availability of alternative suppliers;
- the negotiation position;
- the business requirement; and
- the overall value of the supplier’s proposal.
Procurement management may be involved when a deviation exceeds the buyer’s authority or affects the organisation’s risk appetite.
The CRD creates the structure needed to support this cross-functional decision.
Can an AI Agent Create a Contract Review Document?
An AI agent can help create a Contract Review Document, but it is important to define what “create” means.
The AI agent can prepare a first draft.
It can:
- read and divide the contract into relevant clause categories;
- identify apparent differences between documents;
- retrieve the organisation’s approved contract position;
- compare the supplier’s wording with the approved position;
- populate the CRD structure;
- suggest clarification questions;
- identify missing information;
- propose possible negotiation points;
- flag issues for specialist review; and
- prepare a summary for the sourcing team.
The AI agent should not independently approve contract deviations or decide that a legal or commercial risk is acceptable.
Contract risk depends on factors such as:
- the value and duration of the contract;
- the category and business requirement;
- the supplier’s role in the operation;
- the availability of alternative suppliers;
- the relevant jurisdiction;
- insurance coverage;
- possible business interruption;
- regulatory requirements;
- the buyer’s negotiating position; and
- the organisation’s risk appetite.
These factors require professional judgment.
The recommended operating principle is therefore:
AI prepares and explains. Humans review, decide and approve.
Why Is a CRD Still Needed When AI Can Review a Contract?
AI does not remove the need for a Contract Review Document.
It makes the structure and governance provided by the CRD even more important.
An answer generated in an AI chat interface is not automatically a controlled procurement decision. It may be difficult to determine:
- which contract version was reviewed;
- which internal source was used;
- whether the source was current;
- which clauses were excluded;
- who verified the conclusion;
- who approved the deviation; and
- why the final position was accepted.
The CRD converts the AI-supported analysis into a governed decision record.
It defines which information must be reviewed, how deviations should be described, which evidence must be presented and who is responsible for the final decision.
The CRD is therefore not replaced by the AI agent. It becomes the controlled output of the AI-supported contract review process.
What Is RAG in Contract Review?
RAG means retrieval-augmented generation.
A general-purpose language model generates answers based on its training and the information provided in the current prompt. It does not automatically know the organisation’s latest model contract, clause playbook, approval rules or category-specific contract positions.
A RAG solution retrieves relevant information from an approved knowledge base and supplies that information to the AI model when it performs the review.
For example, when the agent identifies a supplier liability clause, the RAG system may retrieve:
- the organisation’s standard liability clause;
- an approved fallback clause;
- relevant risk-rating guidance;
- applicable insurance requirements; and
- the approval threshold for accepting a lower liability cap.
The AI model can then use these retrieved sources when preparing the CRD entry.
A practical distinction is:
RAG provides the relevant approved knowledge. The AI agent manages the review steps.
What Should the RAG Knowledge Base Contain?
The quality of an AI-supported CRD depends heavily on the quality of the knowledge base.
The knowledge base should contain controlled and approved information rather than every previous contract available to the organisation.
Relevant sources may include:
- the current model contract;
- approved standard clauses;
- approved fallback clauses;
- the contract clause playbook;
- procurement policies;
- contracting policies;
- delegation-of-authority rules;
- risk-rating criteria;
- insurance requirements;
- information-security requirements;
- data-protection requirements;
- category-specific contract guidance;
- approved legal guidance;
- previous approved CRDs;
- approved negotiation positions; and
- the supplier’s proposal and submitted reservations.
Each source should have clear metadata.
This may include:
- document owner;
- approval status;
- effective date;
- version number;
- applicable category;
- applicable jurisdiction;
- confidentiality level; and
- date for the next review.
Old agreements and previous compromises should not automatically be treated as approved precedents.
A clause may have been accepted in an earlier contract because of a unique commercial situation. That does not necessarily mean it represents the organisation’s preferred or approved position.
How Can an AI Agent Prepare the CRD?
An AI-supported contract review process can be structured into seven steps.
Step 1: Receive and validate the review package
The agent receives the relevant documents.
These may include:
- the supplier’s proposed contract;
- the buyer’s model contract;
- the RFQ;
- the specification;
- supplier reservations;
- pricing assumptions;
- service-level requirements;
- contract appendices; and
- relevant internal policies.
The agent should verify that the review package is complete.
If the contract refers to a missing appendix, policy or schedule, the agent should flag the missing document. It should not assume what the missing content says.
Step 2: Identify and classify the clauses
The agent divides the contract into the organisation’s approved clause categories.
These may include:
- scope and deliverables;
- pricing;
- payment terms;
- delivery;
- acceptance;
- warranties;
- service levels;
- intellectual property;
- confidentiality;
- data protection;
- information security;
- liability;
- indemnities;
- insurance;
- subcontracting;
- audit rights;
- change control;
- termination;
- force majeure;
- governing law; and
- dispute resolution.
The classification should follow the organisation’s contract structure or clause taxonomy.
Step 3: Retrieve the approved position
For each relevant supplier clause, the RAG system retrieves the appropriate internal sources.
The retrieved information may include:
- the preferred clause;
- an approved fallback position;
- risk guidance;
- approval requirements; and
- related internal policies.
The CRD should show which source and version were used.
Step 4: Compare the commercial effect
The agent compares the supplier’s proposed wording with the buyer’s approved position.
The comparison should focus on the commercial and operational effect, not only on textual differences.
Two clauses can use different words while creating a similar outcome. They can also appear similar while containing an exception that materially changes the allocation of risk.
The AI agent should therefore explain:
- what is different;
- which party benefits from the difference;
- which obligation, right or remedy is affected; and
- what the possible consequence could be.
Step 5: Populate the CRD
The agent prepares a first draft containing:
- clause reference;
- buyer’s standard position;
- supplier’s proposed position;
- description of the deviation;
- potential consequence;
- initial risk rating;
- proposed action;
- available fallback position;
- supporting sources;
- responsible reviewer; and
- decision status.
The agent should separate extracted facts from generated assessments.
The exact supplier wording and the exact internal source should be clearly distinguishable from the agent’s interpretation.
Step 6: Flag uncertainty and escalate
The agent should not be forced to produce a conclusion when the available information is insufficient.
It should flag situations where:
- the relevant standard cannot be found;
- sources conflict;
- an important appendix is missing;
- the supplier’s wording is ambiguous;
- the risk depends on missing commercial information;
- the issue falls outside the approved use case;
- specialist review is required; or
- the proposed deviation exceeds an approval threshold.
The ability to report uncertainty is an important control.
Step 7: Complete human review and approval
The tactical buyer reviews the commercial context and verifies the agent’s output.
Specialist functions review issues within their areas of responsibility. These may include legal, finance, information security, data protection, quality, operations or compliance.
The authorised decision-maker approves material exceptions according to the organisation’s delegation rules.
The completed CRD should record:
- which contract version was reviewed;
- which findings were generated by the agent;
- which findings were changed by a human reviewer;
- who reviewed each material issue;
- who approved each exception;
- when the approval was given; and
- which final contract version was signed.
Practical Example of an AI-Supported CRD
Assume that the buyer’s model contract contains the following positions:
- payment in 45 days;
- supplier liability capped at three times the annual contract value;
- a right to terminate following repeated service-level failure; and
- prior approval before critical services can be subcontracted.
The supplier proposes:
- payment in 20 days;
- liability limited to fees paid during the previous three months;
- termination only following an uncured material breach; and
- unrestricted use of subcontractors.
The AI agent identifies the four deviations.
For each issue, the RAG system retrieves the relevant model clause, approved fallback position and risk guidance.
The agent then prepares four draft CRD entries.
Payment terms
The agent identifies that the supplier requests payment earlier than the buyer’s standard position.
It explains the potential working-capital effect and recommends including payment terms in the commercial negotiation.
Liability
The agent identifies that the supplier’s proposed liability cap is significantly lower than the buyer’s approved position.
It retrieves the applicable fallback clause and flags the issue for legal and commercial review.
Termination
The agent identifies that the supplier’s wording may reduce the buyer’s ability to terminate following repeated performance failure.
It recommends reviewing the clause together with the service-level and remediation provisions.
Subcontracting
The agent identifies that unrestricted subcontracting could reduce the buyer’s control over critical service providers.
It retrieves the relevant security, compliance and supplier-control requirements and routes the issue to the appropriate reviewers.
The AI agent has now prepared the analysis and organised the evidence.
It has not decided whether the deviations should be accepted.
The tactical buyer and relevant specialists must consider the total contract value, operational dependency, supplier market, available alternatives, insurance coverage and negotiation position before recommending a final decision.
Controls Required Before Using an AI Agent
Contracts often contain confidential commercial information, personal data, supplier intellectual property and security-related requirements.
An AI-supported contract review process should therefore only be used within an approved technical and governance environment.
Important controls include:
Controlled access
Users and AI services should only be able to retrieve documents they are authorised to access.
Source approval
The knowledge base should distinguish between approved standards, draft documents, previous agreements and superseded clauses.
Version control
The system should retrieve the current applicable version of each contract clause, policy and approval rule.
Source traceability
Each material CRD conclusion should show the contract wording and internal sources used in the analysis.
Human approval
Material contract deviations should remain subject to human review and formal approval.
Escalation rules
The organisation should define which clauses, risk ratings and financial thresholds require specialist or management review.
Testing
The AI-supported process should be tested against contracts and CRDs that have already been reviewed by experienced professionals.
Monitoring
Incorrect, incomplete or unsupported findings should be recorded and used to improve the knowledge base, instructions and review process.
Confidentiality
The organisation should define which contracts and documents may be processed, where the information is stored and whether external systems are permitted to use the data.
Common Mistakes When Using AI to Create a CRD
Treating the AI output as approval
The AI agent can prepare an assessment. It cannot provide organisational approval to accept a contract deviation.
Using an uncontrolled knowledge base
Old contracts, draft clauses and one-off compromises should not be mixed with approved standards without clear status information.
Reviewing wording without reviewing consequences
The important question is not only whether the wording is different. The buyer must understand how the difference changes rights, obligations, costs and risks.
Allowing the AI agent to invent the risk model
Risk criteria and escalation thresholds should be defined by the organisation.
The agent should apply the approved methodology rather than create new risk rules during the review.
Failing to provide sources
A conclusion is difficult to verify if the reviewer cannot see the supplier wording, standard clause and policy used by the agent.
Ignoring missing information
An agent should identify missing schedules, referenced documents and commercial assumptions rather than silently completing the analysis.
Automating an unclear process
AI will not solve an undefined contract-review process.
The organisation should first define:
- the CRD structure;
- clause ownership;
- standard positions;
- fallback positions;
- risk criteria;
- escalation routes; and
- approval authority.
The agent can then support a controlled and repeatable workflow.
Frequently Asked Questions
What does CRD mean in procurement?
CRD means Contract Review Document. It is used to identify, assess and document differences between the buyer’s preferred contract position and the supplier’s proposed terms.
When should a CRD be created?
The CRD structure should be prepared during RFQ development. It should then be populated during supplier evaluation, updated during negotiation and completed before contract approval and signature.
Who is responsible for the CRD?
The tactical buyer will often coordinate the CRD. Individual clauses may require input from legal, finance, information security, operations, compliance or other specialist functions.
Can a CRD be used to compare suppliers?
Yes. Contract deviations can be included in the commercial evaluation of supplier proposals.
However, the organisation should use a consistent and transparent evaluation method. Contract risk should not be converted into an arbitrary score without defined criteria.
Can AI create a CRD?
An AI agent can prepare a first draft by extracting clauses, retrieving approved positions, comparing wording and populating the CRD structure.
Human reviewers must verify the findings and approve the final decisions.
What is RAG in contract review?
RAG retrieves relevant information from an approved knowledge base and provides it to the AI model as context.
This allows the agent to use the organisation’s current model clauses, policies, fallback positions and approval rules.
Does RAG prevent incorrect AI output?
No.
RAG can improve the relevance and traceability of the analysis, but the retrieved sources and generated conclusions must still be verified.
Should previous contracts be included in the RAG knowledge base?
Previous contracts can provide useful context, but they should not automatically be treated as approved standards.
Their status, category, jurisdiction and reason for any accepted deviation should be clear.
Does an AI contract review replace legal review?
No.
The AI agent can identify and structure issues, but legal specialists and other authorised functions remain responsible for professional assessment and approval.
Should the CRD be stored with the contract?
Yes.
The approved CRD should be archived together with the final signed contract so that future contract managers can understand the accepted deviations and the reasoning behind them.
Conclusion
A Contract Review Document gives the procurement team a structured way to compare supplier terms, assess deviations, prepare negotiations and document the final contract decision.
It helps the buyer evaluate more than price. It makes the contractual and commercial consequences of the supplier’s proposal visible before the contract is signed.
An AI agent supported by RAG can improve this process by retrieving approved contract positions, identifying apparent deviations and preparing a traceable first draft of the CRD.
The value of the AI agent is not that it makes the final decision.
Its value is that it performs repeatable analysis, organises the evidence and helps procurement professionals focus their time on material risks, negotiation choices and business judgment.
The strongest operating model is therefore:
AI prepares and explains. Procurement and authorised specialists review, decide and approve.
To learn how contract preparation, supplier evaluation, negotiation and contract award connect within the sourcing process, continue with the Learn How to Source course Sourcing Process 2b – RFQ.
You may also find the LHTS articles about contract clauses and the AI procurement mentor useful as the next step in your learning.
