ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Model Rule 5.3 and Your IT Vendors: Supervising Nonlawyer Help

Learn how ABA Model Rule 5.3 applies to IT providers, cloud vendors and other outside services, and what practical steps a firm can take to supervise them.

3 min readBy Counsel Cyber Team

Law firms rely on many people who are not lawyers and do not work for the firm: IT providers, cloud platforms, e-discovery vendors, copier technicians, shredding services and cloud-based AI tools. Model Rule 5.3 addresses a lawyer's responsibility for nonlawyer assistance, and the ABA has applied it to outside service providers.

This article explains the idea in plain English and gives practical steps. It is general information, not legal advice. State versions of the rules vary, so confirm with your state bar.

What Rule 5.3 Says in Substance

Rule 5.3 broadly asks lawyers with managerial authority to make reasonable efforts to ensure the firm has measures giving reasonable assurance that nonlawyers' conduct is compatible with the lawyer's professional obligations. Supervising lawyers have similar duties regarding the nonlawyers they direct. In certain circumstances, a lawyer may be responsible for a nonlawyer's conduct if it would be a violation if engaged in by a lawyer.

The comments to the rule discuss outside service providers. They speak of giving appropriate instruction and assuring that the services are provided in a manner compatible with the lawyer's obligations, taking into account factors such as the provider's reputation, the nature of the services, and the terms of the arrangement.

ABA Formal Opinion 477R, on securing communication of protected client information, and Formal Opinion 498, on virtual practice, both reflect these supervisory themes, as does Formal Opinion 512 in the context of AI tools.

Why It Matters for IT

An IT provider often has administrator-level access to email, documents and backups. A cloud practice-management vendor holds your matter files. If either mishandles data, the firm's confidentiality duties under Rule 1.6 are implicated, even though the failure happened outside the office.

A Reasonable Vendor Supervision Program

1. Keep a vendor inventory

List each vendor that touches client information, what data it handles, who at the firm owns the relationship and when the contract renews.

2. Do due diligence before signing

Ask questions such as:

  • How do you protect client data, and can you show independent assurance such as a SOC 2 report?
  • Who at your company can access our data?
  • Do you use subcontractors, and where is data stored?
  • How do you handle and report security incidents?
  • What are your backup and recovery practices?

3. Put it in the contract

Look for confidentiality commitments, breach notification timing, limits on data use, data return or deletion at termination and cooperation during incidents. Have counsel review significant agreements.

4. Limit access

Give vendors only the access they need, and use separate named accounts with MFA rather than shared credentials. Remove access when the engagement ends.

5. Monitor and review

Supervision is ongoing.

  • Request periodic reports and attestations.
  • Review who has access at least annually.
  • Track vendor security incidents in the news and ask whether you are affected.
  • Reassess when services change or contracts renew.

6. Plan for the vendor's failure

Know how you would get your data back and operate if a vendor suffered an outage or closed. Keep an independent export or backup of critical data when possible.

Special Cases

AI and software-as-a-service tools

Staff may adopt tools without approval. Establish a simple review process so nothing touches client data until approved.

Contract attorneys and temporary staff

Provide confidentiality agreements, role-limited accounts and security training, and remove access promptly.

Court reporters, interpreters and experts

They handle sensitive materials. Include confidentiality terms and secure file-transfer methods.

Physical-world vendors

Shredding companies, cleaning crews, offsite storage and copier lessors can all touch client information. Use reputable providers, locked bins and wipe or destroy copier drives at lease end.

Document What You Do

A vendor register, due-diligence notes, signed agreements and review dates create a record that shows reasonable efforts. They also answer client security questionnaires quickly.

Instruct and Communicate

Rule 5.3's language about instruction means telling vendors what the firm requires. Give a short onboarding briefing: the data is privileged, access is limited and incidents must be reported immediately.

Counsel Cyber works as a vendor to law firms and expects to be held to this standard. We provide reporting, documentation and clear contract terms, and we help firms review their other technology vendors. If you would like to build or refresh a vendor register, we can help.