NDAs arrive constantly. Sales gets one from a prospect. Engineering needs one before a partnership conversation. Business development wants to share information with a potential acquirer. Each one lands in your legal inbox, and your team has to decide: Is this standard or is this risky? Most in-house legal teams spend 20 to 30 percent of their time reviewing NDAs, even though the vast majority are low-risk and do not require detailed legal review. This is where triage saves your team weeks every year.
Key takeaways
- Implement a three-tier triage system: GREEN (auto-approve), YELLOW (standard review), RED (full legal negotiation).
- A GREEN NDA is mutual, uses standard language, has reasonable scope and duration, and comes from a low-risk party. Most NDAs fall here.
- YELLOW NDAs have minor deviations from your standard but do not present significant risk. Flag them and move on.
- RED NDAs are unilateral, undefined in scope, heavily weighted to one party, or from high-risk counterparties. These need full review and negotiation.
- Triage is strongest when codified in your CLM system with a checklist that auto-routes based on risk factors.
The three-tier system
GREEN: Standard, auto-approve
A GREEN NDA is one that your team can approve without detailed legal review. These are mutual, use standard language, and do not contain unusual terms or red flags.
GREEN NDA checklist:
- Is the NDA mutual (both parties commit to confidentiality)?
- Does it use your approved NDA template or substantially similar language?
- Is the scope of confidential information clearly defined and reasonable (not “everything”)?
- Is the duration reasonable (typically 3 to 5 years post-termination)?
- Does it include standard carve-outs (publicly available information, independently developed, rightfully received)?
- Is it from a known, low-risk counterparty (customer, partner, vendor you have worked with before)?
- Are there no unusual terms like cross-indemnification, liability limitations, or audit rights?
If all answers are yes, this is a GREEN NDA. Route it to a single approver (could be a non-lawyer if trained) and approve it within 24 hours. Do not bog it down with committee reviews.
Example: A prospective customer wants to discuss a potential deal and needs mutual confidentiality. They send your standard NDA. Green light.
YELLOW: Standard with caveats, schedule review
A YELLOW NDA has one or more deviations from your standard, but the deviations are acceptable with minor tweaks or do not pose significant business risk. These need a review and possibly a light redline, but they do not require escalation to the General Counsel.
YELLOW NDA checklist:
- Unilateral (one-way) NDA from a lower-risk party (e.g., a vendor that wants to protect their own information, but you do not need reciprocal protection).
- Duration is longer than preferred (e.g., 7 years instead of 5) but not unreasonable.
- Scope of confidential information is slightly broad but has clear carve-outs.
- Standard definition and survival period, but includes a minor non-compete or non-solicitation clause (limited in scope).
- The other party has made a few redlines to your template, but none are deal-breakers.
- Counterparty is known but in a different vertical or jurisdiction than usual.
YELLOW NDAs should take 3 to 5 business days to review and redline. Assign to a mid-level lawyer who can make minor adjustments and send back without escalation.
Example: A potential partner in Australia wants mutual confidentiality. They use their template, which includes an audit rights clause you have not seen before. The clause is narrow and reasonable (audit rights limited to once per year, reasonable notice). Yellow. Review it, maybe adjust the notice period, and approve.
RED: Non-standard, risky, or asymmetrical. Full review required.
A RED NDA is one that deviates significantly from your standard, poses material risk, or is heavily weighted to one party. These require full legal review and likely negotiation with the counterparty.
RED NDA checklist:
- Unilateral NDA from a high-risk or unknown party, or heavily weighted to their benefit.
- Scope of confidential information is undefined or overbroad (“all information discussed,” “any communication”).
- Duration is very long (10+ years post-termination) without business justification.
- Includes unusual terms: liability caps, indemnification obligations, specific performance, arbitration, or dispute resolution outside your jurisdiction.
- Counterparty includes rights to your materials (not just their own confidential information).
- The agreement contains non-compete, non-solicitation, or exclusivity clauses.
- Unknown counterparty, high-stakes deal, or sensitive technology/information involved.
RED NDAs should be reviewed by an experienced lawyer or the General Counsel. Plan for 2 to 3 weeks of negotiation. Consider whether the business value justifies the legal risk.
Example: A potential acquirer (RED FLAG: acquisition context) sends a unilateral NDA (RED FLAG: one-way and asymmetrical) that gives them the right to use any information in a “due diligence context” (RED FLAG: overbroad scope) with no time limit on their confidentiality obligations (RED FLAG: one-sided). Full legal review required.
Building the triage checklist
The strongest triage systems are automated. If you use a CLM system, build your NDA triage as a checklist that counterparty fills out (or you fill out) when routing the NDA.
Simple checklist form:
- Is this a mutual or unilateral NDA?
- Is the counterparty known to you? (Known = previous contracts or employee; Unknown = new)
- Is this NDA from your template or substantially similar?
- Is the scope of confidential information clearly defined?
- Is the duration 5 years post-termination or less?
- Does it include standard carve-outs (public information, independently developed)?
- Does it include unusual terms (liability, audit rights, IP ownership, non-compete)?
Scoring:
- 0-1 RED flags = GREEN. Auto-approve.
- 2 RED flags = YELLOW. Schedule review.
- 3+ RED flags = RED. Full legal review.
Your CLM system can automatically route based on this scoring, which means most NDAs never reach a lawyer’s inbox.
Common RED flags
Watch for these issues when triaging:
- Unilateral from unknown party: Asymmetry + unfamiliar = risk.
- Scope is vague: “Any information” or “all communications” is a red flag. Confidential information should be clearly defined.
- Survival period is indefinite or very long: Indefinite obligations are expensive to manage. Anything over 7 years should be questioned.
- Counterparty has rights to your information: Legitimate NDAs protect both parties’ information equally. If they have rights to your info and you do not have equal rights, escalate.
- Includes non-compete or non-solicitation: This is not an NDA anymore. It is a restrictive covenant. Full review required.
- Dispute resolution in an unfamiliar jurisdiction: Especially if the jurisdiction is not English-speaking or your business is not based there.
- Audit rights: The right to audit your systems to verify you are keeping their information confidential is unusual. Standard NDAs do not include audit rights.
Why triage matters
Without triage, your team treats every NDA the same: careful, thorough, slow. With triage, you can:
- Approve routine NDAs in 24 hours instead of a week, keeping sales and partnerships moving.
- Protect your team from review fatigue by letting them focus on NDAs that actually need legal thought.
- Reduce escalations to outside counsel because you are catching genuinely risky NDAs early and handling them systematically.
- Build consistency because GREEN NDAs are always approved on the same terms.
AI and NDA triage
Some CLM platforms now include AI tools that classify NDAs as risky or low-risk. These tools are helpful for triage because they can flag obvious red flags faster than manual reading. However, do not rely on AI alone. Always have a human do the final triage. AI can miss context (e.g., the counterparty is a major customer, so slight asymmetry is acceptable) that a human lawyer would catch.
Managing exceptions
Sometimes a YELLOW or RED NDA comes in, but the business urgently needs to proceed. Document the exception in your CLM system so you have a record. Ask yourself:
- What is the business value of accepting this risk?
- Are there ways to mitigate the risk (e.g., add a specific cap on liability, narrow the scope, shorten the survival period)?
- If we accept this NDA as-is, does it set a precedent that other parties will expect?
Good exception management prevents scope creep where every NDA becomes a negotiation.
FAQ
Can we use a standard NDA template for all counterparties?
Mostly. But be ready to adjust for industry norms and jurisdictional requirements. Tech vendors might expect longer confidentiality periods. International partners might have specific data protection requirements. Carve out 10 to 20 percent flexibility in your template for these reasons. Anything beyond that is a RED triage.
What if a vendor insists their NDA is non-negotiable?
That is often a bluff. If it is YELLOW or worse, ask them: What specific concern does your language address? Often, their “non-negotiable” clause is important to them for a specific reason, and you can find a compromise. If they truly will not budge on a RED issue, you can decline the relationship. But this is rare.
Should we always do mutual NDAs, or is unilateral okay?
Mutual is preferred because it is balanced. But unilateral is acceptable when there is a legitimate reason (you are not sharing sensitive info, or the vendor is a regulated utility that has different obligations). The key is intentional choice, not rounding agreement.
How do we handle NDAs that cover multiple pages of redlines?
If there are more than 3 to 5 substantive redlines, it is likely RED. Route it accordingly. Do not try to be clever by quietly accepting all their changes. If they have concerns, surface them and address them directly.
Can a non-lawyer triage NDAs?
Yes, if they are trained on your checklist. A paralegal or legal operations person can run through the GREEN checklist and route accordingly. This frees up lawyers for YELLOW and RED.
NDA triage is one of the highest-ROI improvements you can make to your legal operations. It converts a time sink into a well-oiled workflow. If your team is spending weeks on routine NDAs, a structured triage system will free up months of capacity per year. We help in-house teams design and implement triage systems within their CLM workflows. Let’s talk.