How to Audit NDA Clauses Against an Internal Playbook in Word
How to Audit NDA Clauses Against an Internal Playbook in Word
For in-house legal teams and outside counsel alike, the volume of incoming nondisclosure agreements can be staggering. Manually comparing each NDA against your firm’s internal playbook—the set of preferred terms, fallback positions, and absolute dealbreakers—is tedious, error-prone, and expensive. Yet failing to catch a bad definition of “Confidential Information” or a missing “no reverse engineering” clause can expose your client to liability for years.
This article provides a practical, clause-by-clause methodology for auditing NDAs in Microsoft Word against a standardized internal playbook, with examples drawn from US Common Law. While the examples here are manual, the logic is directly applicable to any AI tool designed to automate this review.
Step 1: Build Your Playbook as a Structured Reference
Before auditing any NDA, your playbook must exist in a form you can use for comparison. A simple Word document with bullet points is insufficient. Structure your playbook by clause category, with three tiers for each:
- Green (Preferred): Language that matches your standard form exactly.
- Yellow (Negotiable): Acceptable modifications, with the exact boundary stated.
- Red (Dealbreaker): Language that must be removed or rewritten.
Example Playbook Entry – Definition of “Confidential Information”:
Green: “Confidential Information” means all non-public information disclosed by the Disclosing Party, whether in oral, written, or electronic form, that is either marked as confidential or would reasonably be understood to be confidential given the nature of the disclosure.
Yellow: Accepts “written and marked only” definition, but only if the NDA also includes a catch-all for oral disclosures summarized in writing within 30 days.
Red: Any definition that excludes financial projections, source code, or customer lists by name.
Step 2: Perform a Clause-by-Clause Audit in Word
Open the incoming NDA in Microsoft Word. Enable the Reviewing Pane and use “Compare” or simply track changes manually as you go. For each major clause, follow this three-part check:
2.1 Definition of Confidential Information
What to look for: Is the scope reciprocal? Does it cover oral disclosures? Are there carve-outs for information already known or independently developed?
Audit against playbook: If the NDA defines Confidential Information as “all information marked as confidential in writing,” flag it. Under US Common Law, a failure to mark oral information can lead to disputes over whether the information was actually confidential. Your playbook should require a reasonable- person standard or a 30-day written summary requirement.
Practical example: The NDA before you states: “Confidential Information means information disclosed in writing and marked ‘Confidential.’” Your playbook’s yellow tier allows this only if a 30-day oral summary clause is present. It is not. Mark it for negotiation.
2.2 Permitted Use and Non-Disclosure Obligations
What to look for: Does the clause restrict use solely to the “evaluation” or “business relationship” purpose? Does it allow disclosure to “employees” only, or to “representatives” (which can include outside consultants)?
Audit against playbook: Most playbooks require “employees and contractors with a need to know and who are bound by written confidentiality obligations at least as restrictive as this NDA.” If the counterparty’s NDA says “employees only,” you are one contractor away from a breach claim.
Practical example: The NDA says: “Recipient may disclose Confidential Information only to its employees.” Your playbook requires “employees and contractors.” This is a yellow-tier issue. You note the change and propose the broader language.
2.3 Term and Survival
What to look for: How long does the confidentiality obligation last? Two years? Five years? Perpetual? Under US Common Law, a term of 2–5 years is generally enforceable, but perpetual obligations are disfavored in many jurisdictions unless trade secrets are involved.
Audit against playbook: Your playbook green-lights a 3-year term for non-trade-secret information. The counterparty’s NDA states “5 years from the date of disclosure.” This is acceptable (yellow). But if it says “perpetual,” that is a red-tier dealbreaker for routine business information.
Practical example: The NDA has a survival clause of “the later of 5 years or the date the information becomes public.” This is ambiguous. Your playbook requires a fixed term. Flag it for clarification.
2.4 Reverse Engineering and Competitive Use
What to look for: Is there an express prohibition on reverse engineering, decompiling, or using the information to develop competing products? Many playbooks treat this as a mandatory clause.
Audit against playbook: If the NDA is silent on reverse engineering, your playbook’s green tier requires adding a prohibition. Under US Common Law, silence does not automatically grant a right to reverse engineer, but adding the clause removes any doubt.
Practical example: The NDA lacks any mention of reverse engineering. You insert the playbook’s standard clause: “Recipient agrees not to reverse engineer, decompile, or disassemble any materials or information provided under this Agreement.”
Step 3: Generate a Redline and a Summary Memo
After auditing each clause, generate a redlined version of the NDA showing every change against your playbook. Then, draft a brief summary memo in Word that lists:
- Green items: Clauses that match the playbook (no action needed).
- Yellow items: Acceptable modifications with recommended fallback positions.
- Red items: Non-negotiable terms that require deletion or substitution.
This memo becomes your negotiation script. It ensures you never accidentally concede a term that your playbook defines as a dealbreaker.
Why This Method Works (and How AI Can Scale It)
Manual auditing in Word is repeatable and precise, but slow. An AI tool trained on your internal playbook can perform the same clause-by-clause comparison in seconds, flagging every green, yellow, and red issue with citations to your own preferred language. The logic is identical—only the speed changes.
Whether you use manual review or an AI assistant, the foundation remains the same: a well-structured playbook, a rigorous clause-by-clause audit, and a clear output that tells you exactly what to negotiate. Without that discipline, every NDA is a game of chance. With it, you control the outcome.
Audit your next contract in under 15 seconds
Paste any clause into Attyflow. Get a risk score, legal analysis, and a bulletproof redline — instantly.
Request Sandbox Access