Direct answer

Start with the actual service and order form, then record a business position for every promise that can affect delivery, data, money, ownership, or exit. A checklist is useful only when each issue has a fact owner, a proposed position, and a fallback; it does not validate the final contract.

Preparation sequence

  1. Identify the contracting parties, users, order documents, service scope, implementation dependencies, acceptance process, and order of precedence.
  2. Record fees, usage metrics, taxes, currency, invoicing, payment, price changes, term, renewal, and suspension triggers.
  3. Map customer data, personal-data roles, subprocessors, transfer locations, security evidence, incident notice, retention, export, and deletion.
  4. Set positions for background IP, licence scope, customer data, generated output, feedback, confidentiality, service levels, support, and credits.
  5. Assign approval owners for warranties, indemnities, liability caps and exclusions, insurance, termination, transition assistance, governing law, forum, and notices.

Decisions to record

What exactly is being bought?

Connect the order form to named services, users, environments, implementation work, dependencies, acceptance, support, and any document that overrides another.

What happens to customer and personal data?

Record the parties' roles, permitted purposes, locations, subprocessors, transfer basis, security evidence, incident route, return, deletion, and audit support.

Where can financial exposure exceed the fees?

Compare warranties, service credits, indemnities, liability caps, excluded losses, insurance, suspension, renewal, and exit costs against the operating scenario.

Can the customer leave in practice?

Test notice dates, export format and timing, transition help, deletion evidence, outstanding fees, access after termination, and any continuing terms.

Evidence to organize

  • Draft agreement, order form, statements of work, and document hierarchy
  • Product description, implementation plan, dependencies, support model, and service-level evidence
  • Data-flow map, DPA, subprocessor list, transfer locations, security measures, and incident process
  • Pricing model, renewal calendar, liability exposure, insurance evidence, and approval matrix
  • Export format, deletion process, transition dependencies, and termination owner

Example decision record

Issue: renewal. Business fact: procurement needs 45 days for approval. Proposed position: renewal notice at least 60 days before the deadline. Fallback: 45 days with a named calendar owner. Escalate if the supplier can change price after the cancellation deadline.

Use the result responsibly

This guide does not select a legal mechanism, determine compliance, validate a contract, calculate a legal deadline, or predict an outcome. Laws, procedures, facts, and provider terms change. Check the official sources and obtain qualified advice where the business decision requires it.

Official reference points

Reviewed 2026-09-02. These sources are starting points, not a complete statement of applicable law. The UNIDROIT Principles are non-binding general principles unless the parties choose them or another applicable rule gives them relevance.