Drafting an Internal Risk Explanation Memo: How to Use Generative AI
Hello, I'm Noriaki Asato, Representative Attorney at LegalAgent.
The role of the legal team in reviewing a contract is not limited to finding unfavorable clauses. It is expected to convey the risks it finds clearly to the business division and decision-makers, with an explanation that lets the decision-maker judge whether to proceed with the contract or change the terms. For example, even if you notice during the review of a service agreement that no cap on liability for damages has been set, simply listing article numbers and legal terms will not tell the decision-maker "how dangerous it actually is, and what needs to be decided."
With tools such as ChatGPT, Claude and Gemini, you can delegate the groundwork of rewriting the issues you have identified into the format of "risk, impact, proposed response." However, even where a contract has no liability cap, the full amount of damages claimed is not automatically awarded. This is because whether damages are owed and their scope are determined by the legal framework under Articles 415 and 416 of the Civil Code, such as the requirements for non-performance of obligations, the scope of ordinary and special damages, and foreseeability. The absence of a cap in a contract is distinguished from a "liquidated damages" provision that fixes the amount of damages in advance (Article 420 of the Civil Code). Based on such legal assessments and the company's circumstances, which option to adopt is decided by people in accordance with the company's approval authority.
Translating Technical Clauses and the Premises for Decisions
In sharing risks internally, rather than quoting the wording of clauses as is, presenting them broken down into three elements, "risk," "impact" and "proposed response," allows decision-makers to judge quickly.
For example, suppose the terms of use of a cloud service (SaaS) include a clause allowing the service provider to suspend the service unilaterally for its own reasons. In this case, organize it as follows: risk (the possibility of service suspension at the provider's discretion), impact (the risk of business interruption if the service is used as a business system), and proposed responses ((a) requesting a prior notice period and alternative measures, (b) limiting use to operations that would not be disrupted by a suspension, (c) accepting the terms as they stand only for low-risk operations).
Preparing multiple options, such as avoidance through operations or acceptance of the risk, rather than narrowing the proposed response to a single point of "negotiate with the counterparty," helps move decision-making forward in practice. The legal team presents the legal options, and the company's decision-makers decide the final course of action, taking into account the transaction value, the relationship with the counterparty and whether alternatives are available.
Points of Focus Depending on the Nature of the Transaction and the Company's Position
Even for the same type of contract, the risks to emphasize differ depending on whether the company is the outsourcing party or the contractor. In a service agreement, the outsourcing party's main concerns are the quality guarantee for deliverables, clarity of the acceptance inspection procedure and ownership of intellectual property rights. For the contractor, the central issues are preventing endless revision requests, the scope of liability for damages and the freedom to subcontract. In a non-disclosure agreement (NDA) as well, the points to check change depending on whether the company is the disclosing party or the receiving party, and whether both parties or only one owe confidentiality obligations.
In addition, the size of a risk cannot be measured solely by the contract amount. Even a small contract worth only tens of thousands of yen can have serious consequences from data leaks or business interruption if it involves handling customers' personal data or relates to core operations. It is important to judge the priority of issues according to the magnitude of their actual impact, without being bound by the size of the amount.
A Prompt for Drafting a Risk Explanation Memo
First, here is a basic prompt that has the AI extract the three elements of risk, impact and proposed response from a contract and create the skeleton of an internal memo.
Please create a draft risk explanation memo for internal decision-makers on the following contract. Our position is "contractor (the party performing the services)." For each risk, please use the following three points: (1) the content of the risk (in one sentence, avoiding technical terms), (2) the impact if it occurs (on our operations and finances), (3) possible responses (list several: negotiate / avoid through operations / accept).
Please list them in order of importance. This is a draft for internal consideration, and the final decision will be made by a person. Please clearly mark as "to be confirmed" any uncertain points or points that cannot be judged from the contract alone.
[Paste the contract or issue memo here]
Internal circumstances and facts that cannot be known from the contract are not filled in by guesswork but displayed as "to be confirmed." The order of importance in the output is also reviewed in light of the impact that would actually arise on operations and finances.
Developing It into a Report for Decision-Makers
This is a prompt for drafting an internal report email to a decision-maker such as the head of a business division, based on the organized risk memo. Check the content before sending and make any necessary revisions.
Based on the risk memo we organized earlier, please draft an internal report email addressed to the head of the business division. Since it is an internal document, it can be frank, but please avoid being overly definitive and write it in a way that presents the material needed for the decision.
- Make the "conclusion (whether we can proceed with signing / whether negotiation is needed)" clear in the first three lines
- In the body, narrow it down to the three most important risks, in the order of risk, impact and proposed response
- At the end, list two or three "points on which we would like your decision" as bullet points
When creating a report with this prompt, do not let the AI decide the conclusion at the beginning on its own; either instruct it with a policy that a person has confirmed in advance, or set it up as "to be confirmed" so that a person can choose. Also, because internal report memos record the company's risk tolerance and its fallback positions in negotiation, manage them clearly separately from the proposed contract revisions sent to the counterparty.
Common Gaps in Understanding in Practice
Even if part of a contract appears to say "no cap on damages," another clause may contain a different provision or an exclusion of liability. It is essential not to take the AI's output at face value but to check the cited article numbers and wording against the entire original. In addition, AI tends to make observations premised on general contract types, so a person needs to re-evaluate whether the risks presented fit the company's specific transaction and business operations.
When entering contracts or internal memos, follow the company's internal standards for information management, use an approved environment, and confirm the scope of information that may be entered. Also check the service's data storage and use conditions against the company's internal rules.
- Checking the seriousness and context of risks against the clauses of the entire original
- Assessing data leak and business interruption risks without being swayed solely by the transaction value
- Clearly separating decision memos for internal discussion from revision proposals to the counterparty
- Confirming the management of confidential information based on the usage environment approved by the company