Engagement letters typically cover scope, fees and responsibilities. Fewer address technology, even though clients' information moves through email, cloud services and sometimes AI tools from the first day. Setting expectations in writing can prevent misunderstandings and supports the firm's duties of communication and confidentiality.
This post outlines topics a firm may want to discuss with counsel when updating its engagement letter. It is not legal advice, and wording should be reviewed by someone familiar with your state's rules.
The Rules in the Background
Several ABA Model Rules bear on these choices:
- Rule 1.4 concerns communicating with clients, including keeping them reasonably informed and explaining matters enough for informed decisions.
- Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized disclosure of client information.
- ABA Formal Opinion 477R discusses securing communications, noting that reasonable precautions depend on the sensitivity of the information and that some situations may call for client consultation about methods of communication.
- ABA Formal Opinion 512 addresses generative AI and discusses when informing clients, or obtaining informed consent, may be appropriate.
- ABA Formal Opinion 498 covers virtual practice.
The opinions describe reasonableness, not a script. State bar opinions vary, so confirm your jurisdiction's position.
Topics to Consider
How the firm communicates
Explain which channels you use, such as email, client portal, phone and text. If clients have heightened sensitivity, offer encrypted options. Ask clients to tell you if they prefer a particular method or have restrictions, for instance if they share an email account with someone else or use an employer's system.
Warnings about shared and employer devices
Clients who use work email or a shared computer may unintentionally expose privileged communications. A short plain-language caution can help.
Wire fraud protection
State that the firm will never change wire instructions by email, and ask clients to call a known number to confirm any payment details. Tell them to be suspicious of messages that appear to come from the firm with changed instructions. This is one of the most valuable clauses for any firm handling funds.
Cloud and third-party services
Say that the firm stores information with reputable third-party providers that are subject to confidentiality obligations. Avoid promising specific technical measures the firm cannot guarantee.
Use of AI tools
If your firm uses generative AI on client matters, decide whether and how to disclose it. Opinion 512 discusses considerations, including that general boilerplate may not be enough when client information is entered into certain tools. Some clients prohibit AI use in outside counsel guidelines, so check for those restrictions. Counsel should decide the right approach for your practice.
Recording and transcription
If you record calls or use transcription tools, say so and obtain agreement.
Security incidents
Explain generally that if the firm learns of unauthorized access to client information, it will notify the client as required. Avoid promising specific timelines unless you can meet them.
Client responsibilities
Clients can help protect their own information. Suggest strong passwords, MFA on their email, caution with phishing, and prompt notice if they suspect their account is compromised.
Retention and return of files
Explain how long you keep files, how they are returned, and how electronic data is handled at the end of the matter.
Outside counsel guidelines and client requirements
Large corporate clients may impose security and data handling terms. Review them at intake, track them in a central list, and make sure operations match what you agree to.
Drafting Tips
- Use plain English and short paragraphs
- Avoid overpromising, such as "absolute security"
- Do not describe controls you do not have
- Keep the technology section modular so it can be updated as practices change
- Review annually, and after adopting new tools
Making It Operational
A letter is only as good as the practice behind it. Make sure intake staff know what the letter says, that IT can support the commitments made, and that someone owns updates.
Support From Counsel Cyber
Counsel Cyber does not draft legal documents, but we help firms confirm that the technical practices described in engagement letters and client guidelines are actually in place. If you are updating your letter, we can review the security commitments with your counsel.