In a previous article, “The five ingredients of a great supplier contracting policy”, we looked at how to go about creating a supplier contracting policy that minimises friction for your business colleagues.

However, a good policy is only as good as the knowledge resources that support it. Without them, it’s difficult for both your lawyers and your internal clients to consistently apply the policy.

So, how can your legal team make the most of organisational knowledge to take supplier contracting policies to the next level? We’ll be diving into what we’ve learnt at Tacit Legal to share some tips.

Understand your high level process first

It is much easier to start writing your knowledge if you have a clear understanding of: 

  1. The problem(s) you are trying to solve
  2. Where the start and finish line are

Without this, it is easy to lose focus on what you are trying to achieve. 

For example, in our case Tiller’s purpose is:

  • To deal with supplier contracts on supplier provided paper;
  • Enable negotiation via issues lists rather than mark-up; 
  • Provide in-house teams with oversight of the risks they want to know about pre-signature; and
  • Provide in-house teams and their stakeholders the ability to analyse contract risk across the organisation at a granular level.

With that in mind, we broke down the entire Tiller user journey into five high level steps, and then mapped out what knowledge we needed at each step.

A screenshot of a computer

Description automatically generated

In the rest of this article, we’ll provide you with a blueprint for your own knowledge based off our process, which we hope will help get the ball rolling when you come to supercharging your own supplier contracting policy.

Defining your risk policy

As a recap on risk policies from our previous article:

  • A risk policy outlines the risks that you care about;
  • You might have a single policy, or separate policies that apply based on contract type, risk tier, etc; and
  • You should be clear whether a policy is finite (“only look for these risks”), or more of a minimum reporting level.

From a knowledge perspective, this is a case of pulling together a list of the risks that you should review for. 

All further knowledge we’ll talk about in this article should map back to one of these risks.

Whilst the menu on our Tiller platform covers just about every risk you might want to select, we are not believers in having playbooks that look at everything under the sun on every contract.  

In general, it makes for a better experience for everyone if you focus your playbook on the issues that matter most to your organisation, given the contract type, purchasing category, risk tier, etc.

Reviewing against policy (input knowledge)

The next step is to figure out your input knowledge. Think of this as the guidance and instruction given to the person (or perhaps AI service) carrying out a contract review.

We break down input knowledge into: 

  • Information needed from the business; and
  • Legal knowledge to structure and guide the reviewer.

Things you need from the business 

It’s important to consider what you need from the business upfront to reduce the back and forth (and therefore turnaround time), and make the output of your review more useful.  The type of things to consider here for this  would be:  pricing methodology, expected term, renewal and termination rights.

Once you’ve compiled a list of things you’ll need, you can add these to an instruction form to be completed by the business when submitting the contract for review.

Whilst chronologically from a review process perspective you’d collect this comes before you apply the legal knowledge, we’d suggest you put pen to paper on what you need from the business do it after you have pulled together your legal knowledge, as you’ll have a much clearer picture of what information is missingit is usually easier to think about once you’ve expanded on the risk.

If you’re thinking it would be difficult to even get the business to engage upfront,  you could skip this step. But, given how much more useful it makes the output, we think it is worth pushing.

Legal knowledge

How extensive your legal knowledge bank needs to be will depend on who will be doing the review:

  • If a lawyer, the more senior the lawyer the less technical help they’ll need; and
  • If using large language models, the more guidance you give it on how to answer the question, the better (we generally start with “what would a paralegal need to know”)?

For us, each contract risk is made up of at least:

  • A question to be answered of the contract; and
  • Whether that risk is a black, red, amber or green (this may vary by contract type).

If needed, we’ll also add some guidance to help the reviewer identify the issue.

Report on exceptions (output knowledge)

Conversely, to report on exceptions clearly and consistentlyhere you need output knowledge. Think standard form drafting, guidance and templates the reviewer uses to compose their response to the business.

What exactly this looks like for your legal team will depend on how you expect the business to use it. For example, we’ve optimised Tiller for negotiating on supplier paper, so for us this looks like:

  • Re-using the “questions to ask of the contract” from our input knowledge, along with the reviewer’s answer;
  • Guidance to help the business decide whether the legal risk is acceptable or not (the “so what”, possible mitigations and whether its market); and
  • Resources to help the business resolve the risk (e.g. standard form requests back to the counterparty, example drafting, negotiation talking points, etc.).

Manage exceptions 

As much as we can standardise things, there will always be exceptions. To manage exceptions, you will need to add further knowledge to what you already have.

First, we suggest adding “red, amber, green” ratings to your risk policy and reviewer knowledge. We add two other options – “do not sign” and “for information”.

Second, you might consider adding approval matrixes to your risk policy. These might be generic (e.g. “red risks require legal approval, amber require business director” etc.) or specific (e.g. “data protection requires DPO approval”).

Reporting

Whilst you may be some way off wanting to put together detailed reporting, it becomes much harder to do if you didn’t think about it from the start.

This step involves combing back over your reviewer knowledge to ensure the questions you are asking of the contract, and their possible answers, are in a  structured format (i.e. questions that lead to finite outcomes).

That isn’t always possible, but it’s worth doing where you can as free text becomes very difficult to work with later.

Organisation knowledge is vital for the supplier contracting policy. But how can you  leverage knowledge as a legal team when creating your policy? In-house legal teams need to consider areas like defining the risk strategy, structuring input knowledge, managing exceptions and thinking ahead to reporting. By following these steps to introduce organisational knowledge, legal teams can create a policy that minimises friction for business colleagues and enables efficient supplier contract management.


This article was written by Chris Bridges, Partner & COO at Tacit Legal

Tacit Legal is a law firm that doesn’t believe in throwing the traditional model at every problem. For supplier contract reviews, they’ve designed and built their “Tiller” platform to power their managed review service. Helping their clients set, manage, use, enforce and report on their supplier contract risk policies in a business-friendly way.


Crafty Counsel is the UK’s most dynamic and fast-growing legal Community. With members from across the globe, the Community is a hub for sharing experiences, learning together, and forming invaluable connections. Join for free to access the Community Hub App.