Inherently complex and now heavily standardised, the business world today demands more professional and rigorous contract management & administration than ever.
Complementing ISO 31000 on risk management, ISO 31022 deals more specifically with the control of legal risk. The standard defines a “legal risk” as one linked to law, to regulations, and to contractual and non-contractual obligations.
You will not have failed to notice that this framework is not dedicated solely to contract management, but rather to legal risk as a whole. That said, there is a great deal to be drawn from it when setting up or improving a contract management function within a business. In this article, we explore in practical terms how ISO 31022 can be applied to structure contract management effectively and demonstrate its value.
A. The value-creation factors of contract management
The general principles come from ISO 31000 and are set out in the diagram in Art. 4 of the standard, shown below:

This diagram identifies 8 value-creation levers that transfer perfectly to contract management:
1. Embedding contract management within the company’s operating cycle.
This is not about where the function sits (we covered that in this article) but rather about weaving contract management into every stage of the operating cycle (in particular tender responses, contract negotiation, supply chain relationships, contract execution, and so on).
2. Structuring the contract management function around the company’s risk management policy.
Contract management must be one of the tools the company has at its disposal to control its risks.
3. Adapting contract management practices to the specifics of the company.
Contract management cannot be a set of standardised practices rolled out uniformly. On the contrary, contract management must develop a fine understanding of an organisation’s challenges and specific features, and of its ecosystem of clients, partners and suppliers, in order to adopt the best practices for that environment.
4. Inclusiveness!
The point here is not to make contract management a subject reserved for contract managers, but to involve as many stakeholders as possible in the discipline.
5. Adaptability.
Contract management practices, and contract managers more generally, must be able to adapt their practices and strategies to legislative and regulatory change (we saw this recently with a reversal of case law by the French Cour de cassation on the nullity of a contract for want of a guarantee).
6. The hunt for information.
There can be no effective contract management without up-to-date data and information. It is essential to build a reference base and to equip yourself with the right tools (see our article on CLMs) so that data can be collected and analysed, in real time where possible.
7. Human and cultural factors.
As the pope of management Peter Drucker liked to say: “culture eats strategy for breakfast”. If that holds true for corporate strategy, imagine the sorry fate awaiting contract management when it comes up against a company culture! Contract management must therefore adapt to the corporate culture in order to exist and thrive.
8. Continuous improvement.
Always keep tomorrow’s contract management in your sights by capitalising on mistakes through formal lessons-learned records (retours d’expérience), by exchanging with peers (through the AFCM, for example) in order to share and spread best practices, and more generally by monitoring contract management practices and tools, in France but also across the Channel and across the Atlantic.
B. Best practices in contract negotiation
Some companies have Golden Rules and other guidelines or instructions for contract negotiation. For those that do not, or that wish to benchmark theirs against another framework, ISO 31022 provides in an annex an example table listing the essential clauses to analyse at the contract review stage. This table contains 28 items, ranging from delivery terms to payment, taking in liability and warranties along the way. Although generic, this document gives companies without Golden Rules, or those wishing to update them, a concise example listing the points to watch, together with a description and best practices.
Here is an extract from that table:

Formalising these best practices gives the stakeholders in a negotiation a reference framework setting out what is acceptable and what is not, and also, where there is a deviation from those best practices, enables them to identify it so that its development and probability of occurrence can be tracked during contract execution.
C. Risk assessment and analysis methods
Here the standard reminds us that risk assessment and analysis must be both qualitative (impact should the risk occur) and quantitative (probability of occurrence), and that once this work is done, actions must be implemented. Having set out these (admittedly general) principles, ISO 31022 offers some further guidance.
i. On risk assessment
As regards risk assessment, ISO 31022 invites you to take several factors into account, all of which apply to contract management:
o The organisation’s objectives and priorities
o Relationships with third parties (suppliers, partners, clients, etc.)
o Tolerance of certain risks, or of certain probabilities of occurrence, depending on the circumstances
o The various risk categories (contractual, legal, regulatory, etc.)
The standard then invites you to identify the various sources, factors and/or causes likely to generate risk, along with their potential consequences, and points out that risk assessment and analysis work must be proportionate to the size, structure and complexity of the organisation and its projects.
Finally, it notes that putting in place a methodology and a process to keep this risk analysis updated frequently is one of the “must-haves” of risk management.
ii. On risk analysis
The standard first points out that risk analysis (that is, analysis of the probability of occurrence and of the impact should the risk arise) is not an exact science.
ISO 31022 then offers some avenues for refining this analysis: the use of historical data, expert opinion, simulation, BI (business intelligence) tools and now even artificial intelligence. It then points out that different risks may interact (or produce domino effects). Risk analysis must therefore take in the interdependencies and correlations between risks.
ISO 31022 then provides clarifications that are useful to the contract manager on:
o Methods for assessing the probability of occurrence, providing an example table (Annex C) including a scoring matrix from 1 to 5:

o Methods for assessing the impact should the risk occur, likewise providing an example table (Annex D) including a scoring matrix from 1 to 5:

Cross-referencing these scores can produce a ranking of risks and allow the contract manager’s action plan to be prioritised, taking into account the various factors identified in (i) above.
Also among the best practices, ISO 31022 recommends putting KRIs (Key Risk Indicators) in place. These may be raw data (contract value, penalty amounts, delay, etc.), but above all ratios derived from cross-referenced data. The standard gives the example of the liability cap against the contract value. More generally, it offers general recommendations on the KRIs to put in place that may be of interest to the contract manager:
o Taking the organisation’s risk management policy into account
o Taking a cost/benefit analysis into account
o Taking into account the availability of resources to mitigate the probability of occurrence or the impact of the risk
o Taking into account the organisation’s level of maturity in the face of certain risks
Conclusion
Whether or not your organisation is directly concerned by ISO 31000 and/or ISO 31022, the latter is a valuable resource to consider when setting up, structuring or even continuously improving a contract management function.
This framework is genuinely useful for refining the contract manager’s positioning, scope and playing field, and also for formalising robust contract management methods and processes.
Applying legal risk management best practices to contract management departments will unquestionably help them increase their integration into the organisation and their impact on the company’s bottom line.
