Identify the service and contracting chain

A procurement pack may contain a master agreement, processing addendum, security schedule, model-provider terms, and a separate support policy. Establish which documents apply to the purchased service and which entity signs each one. Keep incorporation and precedence questions visible.

Describe the intended upload and output workflow before reviewing clauses. The same vendor may offer several products with different processing arrangements. A public policy about one service is not evidence that another service has identical terms.

Build questions around observable commitments

Use separate matrix questions for documented instructions, confidentiality, subprocessors, security commitments, assistance, deletion or return, and audit information. Article 28 of the GDPR provides the legal starting point for a processor contract assessment. The review still requires attention to the parties' actual roles and activities.

For every extracted answer, retain the clause and document reference. Add a distinct reviewer conclusion, so a model's description of the language is not confused with acceptance of that language.

Work through a support-access exception

Assume the sales summary promises that customer files are not used for training, while the support schedule allows staff access to investigate incidents. These provisions concern different activities. Ask who can access files, how approval is controlled, where access occurs, and how it is logged.

Do not mark the terms inconsistent merely because support access exists. Equally, do not treat the no-training promise as a complete answer to confidentiality or international-access questions. Obtain the evidence needed for the actual support model.

Test the end of the relationship

Read return, deletion, backup, and account-closure provisions together. Identify what the customer must request and what happens automatically. A clause referring only to active storage may leave the reviewer without an answer about backups or retained logs.

Ask for the available exit procedure and evidence format. Record any retention exception, its stated basis, and the responsible approver. If a legal hold is relevant, refer the conflict to the privacy and matter teams instead of inserting an absolute deletion promise.

Turn exceptions into a decision

Group findings into accepted terms, amendments requested, evidence still needed, and uses excluded from approval. Give each open item an owner. An aggregate risk colour is less useful than knowing which document category cannot yet enter the tool.

Judicio's Review Matrix permits up to 25 questions in one matrix. A focused initial set is easier to validate than a long questionnaire that merges unrelated commitments. Keep the final procurement decision outside the unreviewed extraction.

Worked example and decision record

Illustrative procurement pack: the order form names a contract-review service, a DPA refers to a different product family and a support policy permits remote diagnostic access. A model may return a complete-looking compliance table by finding words in each document, even though it has not established that the documents bind the purchased service.

QuestionEvidence to retainOpen issue
Which service is covered?Order form plus DPA definitionsObtain confirmation of incorporation and scope
Who may access files?Support access terms and approved processIdentify recipients, locations and controls
What happens on exit?Return/deletion wording and retention exceptionsClarify treatment of backups and retained records
What is the reviewer’s decision?Clause references plus counsel’s rationaleSeparate extraction from acceptance

Keep “not found,” “not applicable” and “accepted” distinct. A blank result could mean unreadable text, an omitted schedule or a term the selected files never contained. The procurement owner should be able to reopen the exact evidence behind any accepted answer.

Run a reviewable workflow

Start a Review Matrix with the applicable agreement family. Ask narrow questions with a source requirement: identify the service definition, extract the return/deletion commitment, list stated support-access conditions. Use text or list answers where a yes/no answer would hide an exception.

Judicio Review Matrix question-authoring demonstration with selected questions and editable prompts
Review the proposed questions and answer types before running an extraction. The demonstration uses sample commercial contracts, not an assessed EU processing agreement. Product demonstration with illustrative data; not a customer result or accuracy benchmark. Open the image to inspect it at full size.

The legal starting point for processor terms is GDPR Article 28. Confirm roles and applicability before applying the checklist. The proposed matrix is an evidence-organising method, not a regulatory scoring system.

Open cited clauses, reconcile incorporated documents and add the reviewer’s conclusion to the procurement record. If an answer changes after a vendor clarification, retain both the earlier uncertainty and the document that resolved it. Export with citations and keep restricted assurance documents in their permitted location. Do not upload an auditor’s report to an AI service simply because it arrived in the procurement pack.

Checklist and acceptance criteria

Use this checklist at handover. Record the reviewer, date, source version and unresolved items beside each answer; a tick without evidence does not close the issue.

  • Confirm contracting entities, purchased service and incorporated documents.
  • Extract commitments with clause references and exceptions.
  • Distinguish no-training terms from access and processing permissions.
  • Reconcile return, deletion, backup and retention provisions.
  • Approve conditions through the responsible legal, privacy and security owners.

Download the editable review an ai processor agreement for an eu legal team checklist (Markdown). It includes blank fields for your matter record and can be opened in a text editor or copied into your team’s document system.

Acceptance needs a defined deployment, reconciled contractual evidence and named owners for any conditions. A vendor answer that applies only to another product should remain unresolved for this purchase.

Sources and next steps

This is an editorial workflow guide for legal professionals. The suggested checks are our practical recommendations, not a statement that a regulator requires a particular software workflow.

Explore Review Matrix and Document Review, or review Judicio's regional coverage and limitations. Check the underlying source and your organisation's approved process before relying on an output.