Legal playbook · AI Employee: Lex

Vendor Legal Review Intake

Vendor legal reviews in 5 days

The problem

Every vendor engagement needs legal review, and every legal review is a black-hole intake. Procurement fills out a form, legal doesn't get pinged, contract sits for weeks. Or legal gets pinged for 40 vendors a week with no context and has to interview each requester before doing anything. The queue never clears; new vendors are onboarded ahead of review because business can't wait; legal discovers post-facto what the company signed up for.

At a glance
Trigger
Form
Approvals
Legal + security approval
What it does
Writes to your systems
Systems
Ironclad · Vanta
How it feels in production

An hour-by-hour walkthrough.

Procurement creates a new-vendor request: "Acme Analytics, data-processing tool, contract value $48K/year." Lex picks up the request within 15 minutes and starts building the review packet: - Vendor: Acme Analytics, published trust page + SOC 2 + DPA on their website - Contract: draft attached (their template MSA) - Data handling: they will process customer PII per procurement's description - Similar vendors reviewed in past 12 months: 3 (comparable scope + terms) - Standard risk categories: data privacy (medium), liability (standard), IP (low), termination (needs review) - Pre-drafted redline: our standard fallbacks applied to the customer's template Legal reviewer opens the packet: sees the vendor's public materials, the draft contract with our standard-position redlines pre-applied, and the specific items requiring judgment (they proposed 24-month term; our standard is 12). Review completes in 30-45 minutes vs. 4-8 hours from scratch. Reviewer approves the redline, adds one condition, and Lex routes back to procurement for vendor negotiation. Full audit trail of what was reviewed and by whom.
How it works

Step by step.

  1. 01

    Detect intake request + assemble packet

    New-vendor request from procurement + draft contract + vendor context. Auto-pull from vendor's public materials.

    Procurement · SafeBase · Vendor trust portals
  2. 02

    Pre-draft redline against standard positions

    Compare vendor's template to our playbook. Apply standard fallbacks. Highlight items requiring judgment.

    Redlining engine · Playbook library
  3. 03

    Route to legal reviewer with the packet

    Packet + pre-drafted redline + judgment-required items in reviewer queue. Priority based on vendor risk + contract value.

    Legal queue · Web UI
  4. 04

    Reviewer approves + adds conditions

    Review in 30-45 minutes typical. Approve, edit, or escalate to GC. Conditions logged with the approval.

    Slack · Teams · Approval flow
  5. 05

    Route to procurement for vendor negotiation

    Approved redline back to procurement. Vendor negotiation continues; Lex tracks the round via the redline-tracking playbook.

    Procurement · Ironclad · Round tracking
Systems and wiring

What you connect to make this run.

Coupa · Ramp · Airbase · Procurement

read+write

New-vendor intake + status. Write legal-review status back so procurement sees progress.

SafeBase · Vanta Trust · Vendor trust portals

read

Vendor public materials: SOC 2, DPA, subprocessor list. Reduces information-request round-trips.

Ironclad · DocuSign CLM · Concord

read+write

Draft contract intake + reviewed-version storage + signed-version filing.

Playbook library

read

Standard-position playbook per contract type. Fallbacks per risk category. Drives auto-redlining.

What changes

Before and after, honestly.

Time from procurement intake to legal review complete
Before
1-4 weeks
After
1-3 business days
Legal hours per vendor review
Before
3-8 hours
After
30-60 minutes
% of vendors reviewed to standard
Before
50-75% (fast-tracked without review)
After
97%+
Post-signature legal surprises
Before
5-15 per year
After
Under 1 per year
Frequently asked

Answers about this playbook.

What if the vendor refuses our standard redlines?

Negotiation continues via the redline-tracking playbook. Escalations per our approval matrix; some fallbacks may require GC signoff.

How does it handle high-risk vendors (PII processors, financial data)?

Risk-tier drives review depth + reviewer level. Tier-1 vendors always go to GC or senior legal; standard vendors to junior legal or paralegal.

What about micro-vendors ($5K/year, low-risk)?

Fast-track path for low-risk / low-value. Simplified template + auto-approval within limits. Full review only above threshold.

How does it coordinate with security-vendor review + finance-vendor onboarding?

Parallel workstreams from single intake. Each function reviews their aspect; coordinated go-live decision requires all three greens.

What about renewals (existing vendor, new term)?

Renewal path with prior review as baseline. Focus on changes (new terms, updated risk profile). Faster than net-new review.

See it run on your data.

Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.