Identify the service and contracting chain
A procurement pack may contain a master agreement, processing addendum, security schedule, model-provider terms, and a separate support policy. Establish which documents apply to the purchased service and which entity signs each one. Keep incorporation and precedence questions visible.
Describe the intended upload and output workflow before reviewing clauses. The same vendor may offer several products with different processing arrangements. A public policy about one service is not evidence that another service has identical terms.
Build questions around observable commitments
Use separate matrix questions for documented instructions, confidentiality, subprocessors, security commitments, assistance, deletion or return, and audit information. Article 28 of the GDPR provides the legal starting point for a processor contract assessment. The review still requires attention to the parties' actual roles and activities.
For every extracted answer, retain the clause and document reference. Add a distinct reviewer conclusion, so a model's description of the language is not confused with acceptance of that language.
Work through a support-access exception
Assume the sales summary promises that customer files are not used for training, while the support schedule allows staff access to investigate incidents. These provisions concern different activities. Ask who can access files, how approval is controlled, where access occurs, and how it is logged.
Do not mark the terms inconsistent merely because support access exists. Equally, do not treat the no-training promise as a complete answer to confidentiality or international-access questions. Obtain the evidence needed for the actual support model.
Test the end of the relationship
Read return, deletion, backup, and account-closure provisions together. Identify what the customer must request and what happens automatically. A clause referring only to active storage may leave the reviewer without an answer about backups or retained logs.
Ask for the available exit procedure and evidence format. Record any retention exception, its stated basis, and the responsible approver. If a legal hold is relevant, refer the conflict to the privacy and matter teams instead of inserting an absolute deletion promise.
Turn exceptions into a decision
Group findings into accepted terms, amendments requested, evidence still needed, and uses excluded from approval. Give each open item an owner. An aggregate risk colour is less useful than knowing which document category cannot yet enter the tool.
Judicio's Review Matrix permits up to 25 questions in one matrix. A focused initial set is easier to validate than a long questionnaire that merges unrelated commitments. Keep the final procurement decision outside the unreviewed extraction.
Worked example and decision record
Illustrative procurement pack: the order form names a contract-review service, a DPA refers to a different product family and a support policy permits remote diagnostic access. A model may return a complete-looking compliance table by finding words in each document, even though it has not established that the documents bind the purchased service.
| Question | Evidence to retain | Open issue |
|---|---|---|
| Which service is covered? | Order form plus DPA definitions | Obtain confirmation of incorporation and scope |
| Who may access files? | Support access terms and approved process | Identify recipients, locations and controls |
| What happens on exit? | Return/deletion wording and retention exceptions | Clarify treatment of backups and retained records |
| What is the reviewer’s decision? | Clause references plus counsel’s rationale | Separate extraction from acceptance |
Keep “not found,” “not applicable” and “accepted” distinct. A blank result could mean unreadable text, an omitted schedule or a term the selected files never contained. The procurement owner should be able to reopen the exact evidence behind any accepted answer.
Run a reviewable workflow
Start a Review Matrix with the applicable agreement family. Ask narrow questions with a source requirement: identify the service definition, extract the return/deletion commitment, list stated support-access conditions. Use text or list answers where a yes/no answer would hide an exception.

The legal starting point for processor terms is GDPR Article 28. Confirm roles and applicability before applying the checklist. The proposed matrix is an evidence-organising method, not a regulatory scoring system.
Open cited clauses, reconcile incorporated documents and add the reviewer’s conclusion to the procurement record. If an answer changes after a vendor clarification, retain both the earlier uncertainty and the document that resolved it. Export with citations and keep restricted assurance documents in their permitted location. Do not upload an auditor’s report to an AI service simply because it arrived in the procurement pack.
Checklist and acceptance criteria
Use this checklist at handover. Record the reviewer, date, source version and unresolved items beside each answer; a tick without evidence does not close the issue.
- Confirm contracting entities, purchased service and incorporated documents.
- Extract commitments with clause references and exceptions.
- Distinguish no-training terms from access and processing permissions.
- Reconcile return, deletion, backup and retention provisions.
- Approve conditions through the responsible legal, privacy and security owners.
Download the editable review an ai processor agreement for an eu legal team checklist (Markdown). It includes blank fields for your matter record and can be opened in a text editor or copied into your team’s document system.
Acceptance needs a defined deployment, reconciled contractual evidence and named owners for any conditions. A vendor answer that applies only to another product should remain unresolved for this purchase.
Sources and next steps
This is an editorial workflow guide for legal professionals. The suggested checks are our practical recommendations, not a statement that a regulator requires a particular software workflow.
Explore Review Matrix and Document Review, or review Judicio's regional coverage and limitations. Check the underlying source and your organisation's approved process before relying on an output.