Stop Missing Contract Clauses with Automated Review

Stop Missing Contract Clauses with Automated Review

Summary

  • Azure Document Intelligence’s prebuilt-contract model extracts clauses from PDF, Word, Excel, and image files; the free F0 tier truncates contracts at two pages, while S0 supports up to 2,000 pages.
  • Logic Apps Standard with private endpoints keeps Azure OpenAI contract review inside your Azure environment, with Azure OpenAI data privacy commitments including no training on your data and no sharing with OpenAI.
  • Microsoft Graph writes flagged deviations back to SharePoint, but replacing Purview-labeled files requires delegated authentication rather than application-only authentication.
  • Every Logic Apps run produces an audit trail; sending diagnostics to Azure Monitor, Storage, or Event Hubs makes the review defensible to regulators.
  • Start with one contract type, define the playbook, and measure flag rate against a manual baseline; Jinba Flow can orchestrate this end-to-end.

Legal and operations teams at banks and insurers review contracts manually. That means a different person applies a different standard to every NDA and vendor agreement that lands in the queue. One reviewer catches a non-standard liability cap. Another does not. The cost of the miss is not abstract: it shows up in disputes, regulatory findings, and indemnity exposure.

The volume makes the problem structural. When a team processes hundreds of vendor agreements and NDAs each quarter, first-pass review becomes a triage exercise rather than a thorough check. Fatigue sets in, playbook adherence drifts, and clause-level inconsistencies accumulate.

The integration challenge compounds this further. Many AI contract tools require manual upload and download, which sits outside the systems legal teams already use. The analysis happens in isolation, with no connection to approval tracking, document status, or the source file in SharePoint. The workflow problem remains even when the model performs well.

This article describes a structured pipeline that addresses both. It uses Microsoft Graph for SharePoint workflow automation, Azure Document Intelligence for clause extraction, and a private Azure OpenAI deployment for deviation analysis. Jinba orchestrates the end-to-end process, writing flagged results back to the source document and maintaining a complete audit log.

Step 1: Ingest Contracts from SharePoint via Microsoft Graph

The pipeline starts where contracts already live: a SharePoint document library.

Microsoft Graph downloads a document's bytes with a single authenticated request:

GET /sites/{site-id}/drive/items/{item-id}/content

Variants exist for different SharePoint structures, including /drives, /groups, /me, /users, and /shares. The least-privileged permissions for this operation are Files.Read for delegated access or Files.Read.All for application access.

To avoid reprocessing files that have not changed, send the if-none-match header with the file's eTag on each request. An HTTP 304 Not Modified response signals that the document is unchanged and the workflow can skip it. This keeps processing costs predictable as the contract library grows.

For regulated financial institutions, the entire pipeline, including Microsoft Graph and Azure OpenAI, runs within sovereign cloud environments: US Gov L4/L5 (DOD) and China 21Vianet. For teams where cloud residency is a procurement gate, this is a confirmed capability rather than a roadmap item.

Step 2: Extract Clauses with Azure Document Intelligence

Once the document bytes are in the pipeline, the next stage is structured extraction.

Azure Document Intelligence's prebuilt-contract model (model ID: prebuilt-contract, generally available in v4.0 / API version 2024-11-30) uses OCR to extract key fields including Parties, Jurisdictions, Contract ID, and Title. It returns structured JSON that flows directly into the analysis stage. The model currently supports English-language documents.

Supported input formats include PDF, Word (DOCX), Excel (XLSX), and common image types such as JPEG, PNG, and TIFF. No pre-conversion is required for documents stored in SharePoint.

Service tier is a critical production consideration. The free F0 tier processes only the first two pages of a document and enforces a 4 MB file size limit. The paid S0 tier processes up to 2,000 pages for PDF and TIFF files, with a 500 MB file size limit. A pilot that passes on the F0 tier will silently truncate real, multi-page contracts in production. Teams planning to move from proof-of-concept to production must provision the S0 tier before testing against full-length agreements.

Step 3: Flag Deviations with a Private Azure OpenAI Model

The extracted clause data moves next to an Azure OpenAI model, which compares each clause against the organisation's standard playbook and flags deviations for review.

The hosting model for the Azure OpenAI workflow automation determines whether contract data stays within the organisation's private network. This is the decision that matters most for legal and compliance sign-off.

Azure Logic Apps provides first-party connectors for Azure OpenAI, exposing chat-completion and embeddings actions. The connector type controls data boundaries:

  • Consumption (multitenant): Uses a managed, shared Azure OpenAI connector.
  • Standard (single-tenant, ASE v3, or hybrid): Uses a built-in service-provider connector that reaches Azure OpenAI resources inside virtual networks and behind firewalls via private endpoints.

The Standard tier is the mechanism for a true private-model pipeline. Contract content never transits a shared connector layer; it moves directly from the workflow runtime to the privately deployed model.

Azure OpenAI's data privacy commitments underpin the compliance case for using the service in regulated industries:

  • Microsoft does not use customer prompts, completions, embeddings, or training data to train or improve any models.
  • Data is not shared with OpenAI or other third parties.
  • Models are stateless; no prompts or completions are stored in the model itself.
  • Processing remains within the customer-specified geography.
  • All data processing is governed by the Microsoft Products and Services Data Protection Addendum (DPA).

These are contractual commitments, not product marketing claims. They are the basis on which legal and information security teams can approve the deployment.

The model receives the structured JSON from the extraction stage alongside the playbook definition. The output is a structured list of flagged clauses, each identified with the deviation type, the extracted text, and the expected standard. This output is deterministic: the same clause against the same playbook produces the same flag on every run.

Step 4: Write Deviations Back to SharePoint and Audit Everything

Flagging deviations inside the pipeline is not sufficient. The results must reach the people who act on them, in the document they already work with.

Microsoft Graph writes the annotated contract back to SharePoint in a single call. To replace the original file:

PUT /sites/{site-id}/drive/items/{item-id}/content

To create a new annotated copy alongside the original:

PUT /sites/{site-id}/drive/items/{parent-id}:/{filename}:/content

Both operations are scriptable end-to-end using the PowerShell SDK: Get-MgDriveItemContent for the read step and Set-MgDriveItemContent for the write step.

One constraint applies to the write-back step and is non-obvious enough to derail a production deployment. Replacing the content of a file protected with a Microsoft Purview sensitivity label is not supported with application-only authentication. For documents carrying sensitivity labels, the write-back step must run in a delegated context, authenticated as a user rather than as a service principal. Teams using Purview labels across their contract library need to account for this before designing the authentication model.

The Audit Log

Every workflow execution in Azure Logic Apps generates a run history record. This records the trigger attempt status (Succeeded, Skipped, or Failed), along with the inputs and outputs for each action in the run. The result is a per-contract evidential trail that captures what the system processed, what it flagged, and when.

For compliance-grade retention, configure Logic Apps to send diagnostic data to Azure Monitor. Trigger, run, and action events can be stored in Azure Storage or streamed to Event Hubs and queried using Kusto Query Language (KQL). Azure Alerts can be configured to fire when operational thresholds are breached, for example, when more than five contract reviews fail within a one-hour window.

This log is not a supplementary report. It is the mechanism by which the automated review process becomes auditable and defensible to regulators.

From Manual Review to Auditable Assurance

The workflow described here replaces an inconsistent, fatigue-prone process with one that applies the same playbook to every contract, every time. The integration with SharePoint means legal and ops teams work within familiar systems rather than uploading files to a separate tool. The private-model deployment means contract content stays within the organisation's Azure environment. The run history means every review decision has a traceable record.

The practical recommendation for teams evaluating this approach is to start with a single, well-defined contract type: NDAs or a specific category of vendor agreements. Define the playbook criteria for that type, run the pipeline against a sample set, and measure the flag rate against a manual baseline. That comparison provides the evidence needed to extend the workflow to additional contract categories.

This is not a replacement for legal judgment. It is a first-pass review system that applies consistent, documented rules at scale, so that human reviewers spend their time on the flagged deviations that require judgment rather than on reading every page of every agreement to find them.

The next step is scoping the pilot: identify the document library, define the playbook, and confirm the Logic Apps hosting model required for your network and data governance requirements.

Frequently Asked Questions

How do you automate contract review with Azure OpenAI and SharePoint?

Use Microsoft Graph to ingest contracts from SharePoint, Azure Document Intelligence prebuilt-contract to extract clauses, a private Azure OpenAI model to compare them against your playbook, and Microsoft Graph again to write flagged deviations back. Jinba orchestrates the end-to-end workflow, including audit logs.

Is Azure OpenAI contract review private and compliant for banks?

Yes, when configured on Azure Logic Apps Standard (single-tenant) with private endpoints, contract data stays within your Azure environment. Azure OpenAI also carries contractual data privacy commitments: no training on your data, no sharing with OpenAI, stateless models, and processing within your chosen geography under the Microsoft DPA.

What does Azure Document Intelligence prebuilt-contract extract from contracts?

It extracts structured fields including Parties, Jurisdictions, Contract ID, and Title from PDF, Word, Excel, and common image formats. The model uses OCR and returns JSON, supports English-language documents, and requires the paid S0 tier for contracts longer than two pages—the free F0 tier silently truncates beyond that.

Can Microsoft Graph write back annotated contracts to SharePoint automatically?

Yes, using PUT /sites/{site-id}/drive/items/{item-id}/content to replace the original or PUT /sites/{site-id}/drive/items/{parent-id}:/{filename}:/content to create a copy. However, replacing files protected with Microsoft Purview sensitivity labels requires delegated authentication rather than application-only authentication.

How do you audit AI contract review decisions in Azure Logic Apps?

Every Logic Apps run generates a run history with trigger status and action inputs/outputs. For compliance-grade retention, configure diagnostic settings to send logs to Azure Monitor, Azure Storage, or Event Hubs, and set Azure Alerts for failures. This creates a per-contract evidential trail that regulators can inspect.

What is the best way to start an AI contract review pilot?

Start with one well-defined contract type, such as NDAs. Define the playbook criteria for that type, run the pipeline against a sample set, and compare flag rates to manual review. This limited scope provides the evidence needed to expand to other contract categories.

Which Azure Logic Apps tier should I use for private Azure OpenAI contract review?

Use Logic Apps Standard (single-tenant, ASE v3, or hybrid). It provides a built-in service-provider connector that reaches Azure OpenAI resources inside virtual networks and behind firewalls via private endpoints, keeping contract content off shared connector infrastructure.

What role do human reviewers play in AI contract analysis?

Human reviewers handle flagged deviations that require legal judgment. The AI system performs consistent first-pass review against documented rules, so reviewers spend their time on exceptions rather than reading every page of every agreement.

人馬一体のワークフロー構築を体験せよ

エンタープライズ組織を支えるAI基盤

無料で始める