An NDA Review Checklist is a fixed list of items to check, typically seven or eight: whether the confidentiality obligation is one-way or mutual, how long it lasts, whether there's an explicit carve-out for information already public or already known before signing, whether the penalty clause is proportionate, whether it quietly slips in a non-compete or non-solicitation restriction against the other party's clients or staff for the next few years — a common way such clauses get smuggled into an NDA — where the governing jurisdiction is, and the deadline for returning or destroying shared data. This differs from asking Claude to 'take a look and see if this NDA has any problems.' The latter asks for an overall judgment; the former asks for item-by-item verification, where each answer is a plain yes or no that anyone can check without legal training.
The reason this checklist exists is that NDAs get signed constantly in office life but rarely get read carefully. Before a trade show, before a partnership discussion, before interviewing a candidate, an NDA is often the document you sign because the other side sent it — most people never even check whether it's mutual or one-way. The few who do read carefully fall into a different trap: an NDA can read as friendly and standard-format with nothing obviously wrong, because the real risk usually hides in one stretched-out duration or one smuggled non-compete clause, not in some general 'off' feeling about the whole document. When skimming quickly, attention gets pulled toward the familiar boilerplate up front, and the one genuinely different clause slides past. A fixed checklist exists to pre-allocate attention so it isn't dragged around by the document's length or tone.
In practice this runs in two steps. First, save the checklist itself as a fixed comparison instruction — in a Claude Projects knowledge base or as a Prompt Template — reading something like: 'For this document, answer item by item: 1. Is confidentiality one-way or mutual 2. How long is the confidentiality period 3. Is information already public or already known before signing excluded 4. Is there a defined cap on penalty damages 5. Does it contain a non-compete or non-solicitation clause 6. What is the governing law and jurisdiction 7. What is the data return or destruction deadline,' with each answer required to cite the page or paragraph of the original text. Second, upload the NDA awaiting signature and run the checklist once, checking each output against the source yourself — this step is something you can do unaided, because the answer is a textual match, not a legal judgment. Only escalate to legal review when an answer deviates from company standard, such as a non-compete clause being present or the confidentiality period exceeding five years — not every NDA needs to go to legal.
For you, this checklist turns 'did you review the NDA' into 'which of the seven items did you check,' which sharpens the accountability boundary and speeds things up — a standard-format NDA usually clears the checklist and your own verification in under five minutes. Two risks deserve real attention. First, the checklist itself has to stay synced with your company's actual position — if the internal standard for confidentiality period is three years, the checklist should say three years, not leave 'a reasonable period' for Claude to judge on its own. Second, the checklist can only find what deviates from standard; whether to sign remains your call or legal's, and the checklist's job is only to make sure you know what you're deciding.
In April 2024, the U.S. Federal Trade Commission approved a rule that would have banned non-compete clauses against employees nationwide; the rule was subsequently stayed by court litigation, but the episode itself illustrates how contested non-compete clauses remain at the regulatory and judicial level in the United States — which is exactly why checking whether an NDA smuggles in a non-compete or non-solicitation clause cannot be skipped on the checklist: even a clause that's legal today can face enforcement uncertainty later depending on jurisdiction or industry.
The upside is a clear accountability boundary and a review time under five minutes, with results you can verify yourself without waiting on legal. The downside is that the checklist itself must stay synced with the company's actual position, or it will surface false alarms or miss real risk, and it can only catch 'different from standard' — not 'is the standard itself wrong,' which still needs periodic review by legal.