Contract Review Checklist
Intake and Counterparty Diligence
Identify whether this is a custody / sub-custody agreement, sub-advisor / solicitor agreement, vendor / SaaS MSA, marketing / referral arrangement, or client IAA. Tier as critical, high, moderate, or low based on access to client data, funds, or material business processes — the tier drives EDD depth and CCO sign-off requirements.
Screen the legal entity and any disclosed beneficial owners through Refinitiv World-Check, LexisNexis Bridger, or ComplyAdvantage. Document the screen ID and any near-match adjudications. PEP hits trigger enhanced due diligence before counsel review begins.
Pull current Form ADV (advisors), BrokerCheck / IAPD records (BDs, IARs), state insurance producer licensing, or applicable charter for banks. Confirm registrations are active in every state where the relationship will operate — not just home state.
Common gotcha: producer licensed resident-state but not in states where binding will occur.
Required for any vendor that touches client PII, custody data, or trading systems. Confirm report is current (within 12 months), covers the relevant Trust Services Criteria, and lists no material exceptions affecting our use case. Bridge letter required if last audit period ended more than 90 days ago.
Legal and Regulatory Review
Check the contract substance against the rules that govern this relationship — Advisers Act 206(4)-1 (advertising), 206(4)-2 (custody), 206(4)-3 (solicitors), FINRA 2210 (communications), 3110 (supervision), Reg BI for retail recommendations. Bank-side: TILA / Reg Z, RESPA, ECOA, GLBA where applicable.
Confirm governing law, venue, and arbitration forum (FINRA arbitration if BD-side; AAA / JAMS otherwise). Reject class-action waivers that conflict with state RIA rules. Note: client agreements with mandatory pre-dispute arbitration require ADV Item 11 disclosure.
If the contract introduces a new conflict (revenue share, soft dollar, principal trading, affiliated product), confirm ADV Part 2A Items 5, 10, 11, 12, and 14 will be amended and Form CRS updated. Material changes require interim ADV amendment within 30 days, not annual cycle.
Reject mutual indemnification that exposes the firm to consequential damages from counterparty's gross negligence or willful misconduct. LOL caps below 12 months of fees are typically unacceptable for vendors with PII access. Insurance must back the indemnity — verify in next section.
Financial Terms
For AUM-based fees, document whether billed on average daily balance, period-end, or period-start — these produce materially different invoices. For sub-advisor splits, confirm the breakpoint schedule. Three-way reconciliation logic (invoice, custodian debit, internal calc) must be implementable.
Look for ticket charges, custody fees, platform fees, 12b-1 / sub-TA payments, soft dollar credits, and termination fees buried in schedules or addenda. Anything not disclosed in ADV Item 5 needs to be added before execution.
Confirm pro-rata fee refund, data return / destruction obligations, transition assistance period, and any liquidated damages. For custodian agreements, confirm ACATS support and bulk repapering assistance during transition.
Capture the plain-English fee summary that will go on Form CRS and the engagement letter. If this contract creates a new fee type or new conflict, the CRS must be redelivered to retail clients at next recommendation.
Risk and Insurance
Collect a current COI naming the firm as additional insured where appropriate. Minimums for vendors with client data access: $5M E&O, $5M cyber, $2M general liability. Custodians and sub-advisors typically require $10M+ E&O. Confirm tail coverage on termination.
Force majeure should not excuse failure to maintain books and records, custody safeguards, or breach notification. Confirm the counterparty has a tested BCP / DR program with documented RTO and RPO compatible with our regulatory obligations.
Confirm cure periods, escalation contacts, and step-in rights. For custodian agreements, confirm SLOA safeguards align with the SEC's no-action letter conditions so we don't inadvertently take custody.
Data Security and Privacy
Contract must obligate the counterparty to maintain a written information security program meeting Reg S-P safeguards and the SEC's amended Reg S-P incident response and customer notification requirements. State-level overlays (NY DFS Part 500, MA 201 CMR 17.00) where applicable.
AES-256 at rest, TLS 1.2+ in transit, MFA on privileged access, role-based access, and key management standards documented in the security exhibit. Subcontractor / sub-processor list with flow-down obligations required.
72 hours from discovery is the typical floor; 24-48 hours preferred for vendors handling client funds or non-public personal information. Notification must include enough detail to support our 30-day Reg S-P customer notice obligation and any state AG filings.
If the vendor's reps will communicate with our advisors or clients, the contract must require use of archived channels (Smarsh, Global Relay, MyRepChat) — not personal email or unarchived text. The 2022-2024 SEC enforcement wave (over $2B in fines) makes this non-negotiable.
Performance, Reporting, and Sign-Off
Trade execution timing, NAV / performance reporting deadlines, system uptime, support response, and GIPS-compliant reporting where applicable. Tie SLA misses to fee credits or termination-for-cause triggers.
Advisers Act Rule 204-2 records held by a vendor remain ours — the contract must guarantee access for the firm, our auditors, and SEC / FINRA examiners. Five-year retention minimum (first two years easily accessible). Bank-side: regulator examination access for OCC / FDIC / state DFI.
Critical and high-risk contracts require CCO sign-off plus an additional principal (CEO, COO, or General Counsel). Document the rationale for engaging this counterparty and any negotiated deviations from standard terms.
If the contract is rejected, capture the deal-breaker terms, the proposed redlines, and the renegotiation owner. Re-run this checklist after counterparty returns a revised draft.
Store the fully executed PDF, the COI, the SOC 2 / bridge letter, and this checklist in NetDocuments / Laserfiche under the counterparty's vendor record. Set the renewal / re-diligence reminder per the risk tier (annual for critical, biennial for moderate).
Use this template in Manifestly
- Business Continuity Checklist
- KYC Checklist
- Employee Termination Checklist
- Accounts Receivable Checklist
- Employee Performance Review Checklist
- Quarterly Operations and Compliance QA Review
- Quarterly Financial Reporting Checklist
- RIA Acquisition Due Diligence Checklist
- Credit Risk Checklist
- Daily Operations Checklist
- Client Satisfaction Survey Checklist
- Operational Risk Checklist
- Know Your Customer (KYC) Checklist
- Anti-Money Laundering (AML) Checklist
- Litigation Preparation Checklist
- Contract Review Checklist
- New Hire Onboarding Checklist
- Client Onboarding Checklist
- AML / BSA Compliance Checklist
- Regulatory Compliance Checklist
- Monthly Financial Reporting Checklist
- Regulatory Reporting Checklist
- Practice Process Improvement Review
- Internal Audit Checklist
- Lead Generation Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Month-End Close Checklist
- Disaster Recovery Checklist
- Annual Risk Assessment Checklist
- Advisory Firm Operational Efficiency Review
- Data Security Review Checklist
- Client Risk Profile Checklist
- Quarterly Performance Measurement Checklist
- Financial Services Project Initiation Checklist
- Client Retention Checklist
- Vendor Management Checklist
- Sales Pipeline Checklist
- Campaign Performance Checklist
- Data Protection Checklist
- Investment Due Diligence Checklist
- Asset Allocation Checklist
- Portfolio Management Checklist
- Project Execution Checklist
- Project Planning Checklist
- Project Monitoring Checklist
- Financial Statement Review Checklist
- Cybersecurity Risk Assessment Checklist
- Project Closure Checklist
- Financial Services IT Security Audit Checklist
- Advisor and Staff Onboarding Checklist
- Annual Budget Planning Checklist
- Business Continuity Plan Checklist
- Annual Risk Management Review Checklist
- Internal Controls Checklist
- Client Onboarding Checklist
- Client Communication Checklist
- Annual Client Review Checklist
- Market Risk Checklist
- Marketing Strategy Checklist
- Risk Management Checklist
- Regulatory Compliance Checklist
- Quarterly Internal Control Review Checklist
- Sales Tax Reporting Checklist
- Legal Entity Management Checklist
- Employee File Audit Checklist
- Anti-Money Laundering Compliance Checklist
- SOX Compliance Checklist
- GDPR Compliance Review Checklist
- IT Security Audit Checklist
- HR Compliance Checklist
- Payroll Processing Checklist
- Building Code Compliance Checklist
- Employee Records Management Checklist
- Legal Document Storage Checklist
- Security Audit Checklist
- Property Risk Assessment Checklist
- Property Safety Inspection Checklist
- Cybersecurity Protocol Checklist
- Fair Housing Compliance Checklist
- Legal Compliance Checklist for New Properties
- Lease Agreement Checklist
- Software Licensing Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Legal Compliance Checklist
- HIPAA Compliance Checklist
- MLS Listing Review Checklist
- Real Estate License Renewal Checklist
- GDPR Compliance Checklist
- Real Estate Contract Review Checklist
- Fair Housing Compliance Audit
- Listing Agreement Intake Checklist
- ISO/IEC 27001 Compliance Checklist
- HR Compliance Checklist
- Real Estate Ethics & Compliance Review
- Brokerage Trust Account Management Checklist
- Real Estate Professional Development Checklist
- Brokerage Technology Inventory Audit
- Real Estate Website Audit Checklist
- Continuing Education Checklist
- Employee Termination Checklist
- Employee Records File Audit
- Regulatory Compliance Checklist
- Brokerage HR Policy Compliance Checklist
- Employee Handbook Annual Review
- Employee Termination Checklist
- Data Privacy Compliance Checklist
- Risk Management Checklist
- Insurance Compliance Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Claims Auditing Checklist
- Quarterly Industry Standards Compliance Review
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Manufacturing Regulatory Compliance Checklist
- Training Needs Assessment Checklist
- Skills Development Checklist
- Audit Preparation Checklist
- Network Security Checklist
- Employee Offboarding Checklist
- IT Asset Inventory Management Checklist
- Regulatory Reporting Checklist
- Compliance Audit Checklist
- Insurance Program Initiation Checklist
- Insurance Program Launch Project Monitoring Checklist
- Training Materials Checklist
- Quarterly Risk Monitoring Checklist
- System Backup Checklist
- Employee Benefits Checklist
- Insurance Program Launch Execution Checklist
- Insurance Marketing Campaign Checklist
- Email Compliance Checklist
- Law Firm Compliance Checklist
- Anti-Money Laundering Compliance Checklist
- Law Firm Compliance Checklist
- Professional Responsibility Compliance Review
- Data Privacy Compliance Checklist
- Law Firm Risk Management Checklist
- HR Audit Checklist
- HR Compliance Checklist
- Email Deliverability Checklist
- Law Firm Ethics Compliance Review
- Document Retention Policy Checklist
- Employee File Audit Checklist
- Law Firm Risk Management Checklist
- Cloud Security Checklist
- User Access Review Checklist
- IT Regulatory Compliance Review
- Compliance Audit Checklist
- Security Audit Checklist
- Business Continuity Checklist
- Employee Termination Checklist
- Quarterly Operations and Compliance QA Review
- Expense Management Checklist
- Advisor and Employee Onboarding Checklist
- Client Satisfaction Survey Checklist
- Operational Risk Checklist
- Know Your Customer (KYC) Checklist
- Litigation Preparation Checklist
- Contract Review Checklist
- New Hire Onboarding Checklist
- Client Onboarding Checklist
- Regulatory Compliance Checklist
- Monthly Financial Reporting Checklist
- Regulatory Reporting Checklist
- Intellectual Property Management Checklist
- Internal Audit Checklist
- Lead Generation Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Annual Risk Assessment Checklist
- Data Security Review Checklist
- Quarterly Performance Measurement Checklist
- Financial Services Project Initiation Checklist
- IT Policy Review Checklist
- Data Protection Checklist
- E-commerce Sales Tax Reporting Checklist
- Project Execution Checklist
- Project Planning Checklist
- Project Monitoring Checklist
- Financial Statement Review Checklist
- Quarterly Compliance Monitoring Checklist
- Cybersecurity Risk Assessment Checklist
- Project Closure Checklist
- Financial Services IT Security Audit Checklist
- PCI DSS Compliance Checklist
- Advisor and Staff Onboarding Checklist
- Cybersecurity Incident Response Checklist
- E-commerce Risk Management Checklist
- CRM Data Entry Checklist
- Business Continuity Plan Checklist
- E-commerce Legal Compliance Checklist
- Vendor Contract Review Checklist
- Annual Risk Management Review Checklist
- Risk Assessment Checklist
- Agency Compliance and Risk Management Checklist
- Annual School Compliance Audit
- School First Aid and Emergency Medication Audit
- Motor Carrier TSA Security Compliance Checklist
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Permit and Licensing Renewal Checklist
- New Hire Paperwork Checklist
- Restaurant Policy Update Checklist
- Restaurant New Hire Checklist
- Annual Attorney Professional Conduct Review
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Restaurant Licensing Renewal Checklist
- Marketing Strategy Checklist
- Department of Transportation (DOT) Audit Checklist
- Retail Policy Update and Compliance Checklist
- Vendor Contract Negotiation Checklist
- Vendor Setup and Maintenance Checklist
- Vendor Performance Evaluation Checklist
- Service Contract Renewal Checklist
- Vendor Onboarding Checklist
- Contractor Management Checklist
- New Vendor Onboarding Checklist
- Vendor Management Checklist
- Contract Review Checklist
- IT Vendor Management Checklist
- Vendor Management Checklist
- Vendor Onboarding Checklist
- Vendor Contract Review Checklist
- Supplier and Vendor Evaluation Checklist
- Supplier Onboarding Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
