Back to Blog
Published:
Last Updated:
Fresh Content
Legal AI in the ERPChapter 27

What is third-party paper, and how do you review it?

8 min read
1,800 words
high priority
Ali Ahmed

Ali Ahmed

AI Solutions Engineer, Cognilium AI

TL;DR

Any agreement drafted on the counterparty template rather than yours. It is most of what a mid-market company signs, and it defeats clause-position review.

Third-party paper is any agreement drafted on the counterparty's template rather than your own — and for most mid-market companies it is nearly everything they sign. It defeats review habits built around your own contracts, and the terms it lands in your ERP are the other side's defaults.

What actually counts as third-party paper?

Anything where you did not supply the first draft. A supplier's terms and conditions, a software vendor's order form, a landlord's lease, a funder's grant agreement, a customer's purchase-order terms attached at the bottom of an email.

The distinction that matters is not who wrote it. It is who chose the structure.

Your paperThird-party paper
Where a clause sitsWhere your template puts itWherever their drafter put it
What a blank meansYour standard appliesTheir standard applies
Negotiating postureYou concede from your positionYou claw back from theirs
What review is looking forDepartures from your templateAnything, anywhere

Why it dominates the mid-market: the stronger party supplies the template, and a company with a hundred and fifty agreements is rarely the stronger party. A legal function built to review its own contracts is built for the smaller half of its own workload.

Why is third-party paper harder to review?

Because most review habits are secretly position-based.

An experienced reviewer working on their own template knows the liability cap is in clause 11 and the termination rights are in clause 14. That knowledge is speed, and on someone else's paper it is worth nothing. The cap might be in a schedule, split across two clauses, expressed as a multiple of fees paid, or defined in a linked policy document that was never attached.

Four things go wrong specifically on their paper:

  • Silence is a term. An agreement that says nothing about a liability cap contains nothing limiting your exposure — and a reviewer scanning for a clause that is not there can read the absence as "nothing to flag."
  • Definitions do the work. A perfectly reasonable indemnity can be made severe by the definition of Losses three pages earlier.
  • The dangerous clause is often unremarkable. Automatic renewal with a long notice period reads like boilerplate and behaves like a multi-year commitment.
  • Incorporation by reference. "Subject to our standard support policy, available on request" binds you to a document you have not read and they can change.

This is why [playbook-driven review](/blogs/what-is-playbook-driven-contract-review) matters more on third-party paper than on your own. A playbook states your position, your fallback and your red line by meaningwhat is our exposure ceiling — rather than by location. A position-based habit cannot survive a template change. A meaning-based rule can.

What actually reaches your ERP from their paper?

Their defaults, silently, unless somebody intervenes.

The commercial terms in a third-party agreement — payment terms, delivery terms, prices — are the ones that get typed onto a vendor card and then price real transactions. Microsoft describes the purchase invoice as recording "your agreement with a vendor to purchase products on certain delivery and payment terms", and vendors are registered with a vendor card per supplier.

Two failure modes follow, and neither raises an error:

  • The counterparty's term becomes your record because it was in their draft and nobody pushed back. Thirty-day payment terms that were never negotiated are now what your system pays on.
  • A negotiated concession never arrives. You argued the payment terms to sixty days in an email thread; the vendor card still carries their original thirty.

On the enterprise tier there is at least a mechanism that notices divergence. Applying a purchase agreement copies "the payment terms, delivery terms, and delivery address" to the order header, and if the price is later changed on a line, "the link to the commitment is broken" — a documented, detectable event.

On Business Central the terms simply sit on the vendor card, so nothing compares them to the paper they came from.

And when a new supplier is created from their own invoice, Microsoft's Payables Agent sets the Blocked field to All precisely so a person intervenes — noting that "vendors and their bank accounts are approved by having communication with the vendor and doing human callbacks", and that "in many places, this action is a requirement for a successful audit." The block exists because counterparty-supplied data is not trusted by default. That instinct is right, and it should extend to the terms as well as the bank details.

So how do you review it well?

Review by meaning, escalate on the trigger, and record what you conceded.

  1. Write the playbook in outcomes, not clause numbers. "Liability capped at no less than fees paid in the prior twelve months" survives any template. "Check clause 11" does not.
  2. Make silence an explicit check. For each red line, ask whether the agreement addresses it at all. An unaddressed red line is a finding, not a pass.
  3. Resolve every reference before signing. A linked policy you have not read is a term you have not reviewed.
  4. Escalate on the rule, not on a feeling. A red line hit is an automatic escalation, not a judgement call.
  5. Write the outcome back where it will act. The negotiated payment term has to reach the vendor card, or the negotiation was theatre.

Step five is where most of the value leaks, and it is the step review software rarely owns — a reviewer's job usually ends at signature, and the record is somebody else's problem. That handoff is the gap this whole cluster is about.

What should you check first?

Take your last ten third-party agreements and answer three questions about each:

  1. Is there a liability cap at all? Not "is it acceptable" — is one present.
  2. Does it renew automatically, and what is the notice window?
  3. Do the payment terms on the vendor card match the ones in the document?

The third question is the cheapest and it is usually the one that finds money. It needs no legal judgement — two values, side by side, either equal or not. If they disagree on more than one or two of ten, the problem is systemic and reading the agreements once will not fix it.

About Cognilium Cognilium builds AI optimization apps for Microsoft Dynamics 365 — companion apps that optimize the pricing, inventory, warehouse and planning decisions your ERP manages but can't optimize. Dynamics is your system of record. Cognilium is your system of intelligence. https://cognilium.ai · https://www.linkedin.com/company/37180269/

Legal AI Ops. We transform legal workflows with agentic AI, copilots, agentic workflows and decision intelligence — built into core workflows rather than beside them, to raise productivity and cut operational overhead. Contract Review Copilot is the contract-review app in that family. It ships as Paralegent AI, in production today. How we build Legal AI Ops — custom AI capabilities on top of legal work, against your playbook and your Dynamics 365.

Run the three questions on ten agreements. If the payment terms disagree on more than one, bring the list to a 15-minute call.

Sources

Sources and fact-check
#§ClaimTierPrimary sourceVerdict
11What third-party paper is; the four contrastsT2 — ours, a working definition. No legal authority, standard or jurisdiction invokedPASS — definitional and says so
21The party with more leverage supplies the templateT2 — ours, a commercial observation, no figure or study claimedPASS
32The four failure modes on their paperT2 — ours, mechanismPASS
42"Silence is a term" — no cap clause means no capT2 — ours, stated as a review principle, not as legal advice on any jurisdictionPASS — see the disclosure note below
53A purchase invoice records "your agreement with a vendor to purchase products on certain delivery and payment terms"; vendors registered with a vendor cardT1 — verbatim ×2purchasing-manage-purchasing, fetched 2026-09-10PASS
63Applying a purchase agreement copies "the payment terms, delivery terms, and delivery address"; changing the price means "the link to the commitment is broken"T1 — verbatim ×2purchase-agreements (ms.date 2026-09-08)PASS
73New vendors created by the Payables Agent get Blocked = All; human callbacks; "a requirement for a successful audit"T1 — verbatim ×2payables-agent, fetched 2026-09-10PASS
83"The block exists because counterparty-supplied data is not trusted by default"T2 — ours, a reading of claim 7, labelledPASS
94The five review practicesT2 — ours, methodPASS
105The three-question checkT2 — ours, method with no promised resultPASS

Tier summary: 6 × T1 (all verbatim), 4 × T2 — 0 × T4.

### ⚠️ This article discusses contract terms and is NOT legal advice §1, §2 and §4 are commercial and operational observations, not statements of law. No jurisdiction is named, no statute or case is cited, and nothing here tells a reader what their agreement means. "Silence is a term" is a review discipline — check whether the point is addressed — and not a claim about how any court would construe an omission. This matters more in this cluster than elsewhere, because contract content invites being read as advice. The rule we hold: we describe how review and ERP records behave; a lawyer decides what a clause means.

All three Microsoft sources were fetched on 2026-09-10 before their claims were written.

No figures of ours. No count, no percentage, no time saved. "Nearly everything they sign" in §1 is explicitly our characterisation, not a measurement, and no number is attached to it.

Complement, never compete. Business Central is described as holding terms on a vendor card — its actual job — and the enterprise tier's stronger mechanism is credited plainly.

Share this article

Ali Ahmed

Ali Ahmed

AI Solutions Engineer, Cognilium AI

Ali Ahmed is an AI Solutions Engineer at Cognilium AI.

Applied AI AgentsAgentic SystemsRetrieval-Augmented Generation (RAG)LLM Product Engineering
Next in this series
What is Microsoft Syntex, and can it do contract work?
Chapter 28 · 6 min
In short

Key takeaways

  • Third-party paper is any agreement drafted on the counterparty's template, and for most mid-market companies it is nearly everything they sign.
  • Position-based review habits do not transfer. Knowing where a clause sits in your own template is worth nothing on theirs.
  • Silence is a term. An agreement with no liability cap contains nothing limiting your exposure, and a reviewer scanning for a clause can read its absence as nothing to flag.
  • Their commercial defaults become your ERP record unless somebody intervenes, and no error is raised when they do.
  • A playbook written in outcomes survives any template; one written in clause numbers survives only yours.
What goes wrong

Common mistakes to avoid

  • Reviewing their paper with your template's map. The clause you are looking for may not exist.
  • Treating a missing clause as a clean result. Absence is the finding.
  • Signing around an incorporated document. A policy referenced but not attached still binds you.
  • Ending review at signature. The concession you won has to reach the record that acts on it.

Frequently Asked Questions

Find answers to common questions about the topics covered in this article.

Still have questions?

Get in touch with our team for personalized assistance.

Contact Us

Still have a question this did not answer?

The person who wrote this article answers these. Describe your setup and what you are stuck on — you will get a straight answer, including where we think the approach is wrong.