Most law firms rely on outsiders to run part of their technology: a managed IT provider, a cloud practice management vendor, an e-discovery host, a shredding company, a freelance web developer. Each of them may touch client information. The ethics question is whether and how the lawyers supervise them.
ABA Model Rule 5.3 addresses a lawyer's responsibilities regarding nonlawyer assistance. The ABA has discussed in several opinions, including Formal Opinion 477R on securing communications and Formal Opinion 498 on virtual practice, that lawyers who use outside service providers should take reasonable steps to ensure the providers' conduct is compatible with the lawyer's professional obligations. Your state bar's version of the rule and its opinions control, so confirm the specifics with the bar. What follows is a practical way to think about it, not legal advice.
What the rule generally contemplates
In broad terms, Rule 5.3 asks partners and lawyers with managerial or supervisory authority to make reasonable efforts to ensure the firm has measures in place giving reasonable assurance that nonlawyer conduct is compatible with the lawyer's obligations. It also addresses a lawyer's responsibility for a nonlawyer's conduct in certain circumstances. The word reasonable appears repeatedly, which means a sensible, documented process matters more than perfection.
For technology vendors, this usually translates into three activities: choosing carefully, setting expectations in writing, and checking in over time.
Step 1: Choose carefully
Before engaging a vendor that will handle client data, gather basic information:
- Security practices. Ask for a summary of their controls, and request an independent attestation such as a SOC 2 report where applicable.
- Experience. Have they worked with law firms, and do they understand confidentiality, privilege and retention concerns?
- Data location. Where will client data be stored and processed?
- Subcontractors. Who else will have access?
- Incident history and response. How do they handle and report security incidents?
- Financial stability and continuity. What happens to your data if the vendor is acquired or goes out of business?
Write down what you learned and why you decided to proceed. This record is useful if anyone later questions your diligence.
Step 2: Put expectations in writing
A contract is your main supervision tool. Look for:
- Confidentiality obligations covering client information.
- Security requirements, such as MFA for vendor staff and encryption of data.
- Notification of security incidents within a defined window.
- Limits on subcontracting and on using your data for the vendor's own purposes.
- Return and deletion of data at termination, with confirmation.
- Cooperation with client audits and questionnaires.
Large cloud providers may not negotiate their standard terms. In that case, your supervision relies more on selecting a vendor whose standard terms are acceptable and on configuring the service securely.
Step 3: Check in over time
Supervision is not a one-time event. Build a light routine:
- Keep a vendor inventory listing each provider, the type of data it handles, the contract renewal date and the internal owner.
- Review each critical vendor annually: new attestations, changes in terms, security incidents, and subprocessors.
- Revisit access. Remove vendor accounts that are no longer needed and confirm that vendor staff use individual, MFA-protected logins.
- Ask for evidence rather than assurances. A quarterly report from your managed IT provider showing patch status, MFA coverage and backup tests is evidence. A phone call saying "everything is fine" is not.
Special cases
Managed IT and security providers
These vendors hold the keys to your environment. Expect more diligence: background checks for their staff, documented administrative procedures, and clear separation between their access and yours. Ensure you hold ownership of your administrator accounts and domain registrations.
Cloud platforms
Understand the shared responsibility model. The vendor secures its infrastructure, while you configure users, permissions and sharing. Misconfiguration on the firm's side is a common cause of exposure.
Small contractors
A freelance bookkeeper or web designer with access to firm systems should sign a confidentiality agreement and receive the minimum access necessary, with an end date.
AI vendors
Generative AI tools raise the same issues, plus data-use questions about training. ABA Formal Opinion 512 discusses these in the context of existing rules.
Common mistakes
- Treating the IT provider as invisible once the contract is signed.
- Giving vendors shared or permanent credentials.
- Never asking for documentation.
- Having no one inside the firm who owns the vendor relationship.
- Forgetting to remove access when a contract ends.
Making it manageable
A single spreadsheet, an annual review and a one-page vendor intake form will handle most of the above for a small firm. Counsel Cyber helps firms build these processes and, as a vendor ourselves, we are used to answering diligence questions. If you would like help assembling your vendor inventory, we can walk through it with your administrator.