ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Rule 5.3 and Your IT Vendor: Supervising Nonlawyer Assistance

Model Rule 5.3 covers supervision of nonlawyer assistance, including outside IT providers. Learn what to put in contracts and how to oversee vendors reasonably.

3 min readBy Counsel Cyber Team

When a firm hires an outside IT provider, a cloud storage company or a document-shredding service, it hands people who are not lawyers access to client information. Model Rule 5.3 addresses a lawyer's responsibilities regarding nonlawyer assistance. In general terms, it asks partners and supervising lawyers to make reasonable efforts to ensure that the conduct of nonlawyers they employ or retain is compatible with the lawyer's professional obligations.

The ABA has applied this thinking to technology vendors in its formal opinions, including Formal Opinion 477R on securing communications and Formal Opinion 498 on virtual practice. The details vary by state, so use this post as a practical framework and confirm specifics with your state bar.

Why IT vendors deserve special attention

An IT provider with administrator access can read email, copy documents, change security settings and delete backups. That is more access than most employees have. The same is true of a managed security vendor and a cloud practice management platform. Reasonable oversight is therefore proportional to the access granted.

Before you sign: due diligence

Ask questions in writing and keep the answers.

  • Who will have access to our systems and data, and are they background checked?
  • Where is our data stored, and does any of it leave the country?
  • What security certifications or independent audits can you share?
  • How do you protect your own administrative accounts, for example with MFA?
  • What is your process for notifying us of a security incident, and how quickly?
  • Do you carry cyber and professional liability insurance, and at what limits?
  • What happens to our data when the contract ends?

Vendors that handle these questions comfortably are usually better partners. Vague or defensive answers are information too.

What the contract should say

Have counsel review the agreement. Common provisions firms look for include:

  1. Confidentiality. An explicit obligation to keep client information confidential and use it only to provide the services.
  2. Breach notification. A defined time window for telling you about a suspected incident, and a duty to cooperate with your response.
  3. Access limits. Access only by authorized personnel, with logging.
  4. Subcontractors. Disclosure of third parties who may touch your data and flow-down of the same obligations.
  5. Data return and deletion. Return of your data in a usable format and certified deletion when the relationship ends.
  6. Audit or evidence rights. The ability to request security documentation periodically.
  7. Insurance and liability. Terms that match the risk, with realistic limits.

Ongoing supervision

Rule 5.3 is not satisfied by a one-time signature. Build a routine that is modest and sustainable.

Quarterly check-ins

Meet with your provider and review open tickets, patching status, backup test results, user access changes and any incidents. Ask for written reports and keep them.

Annual review

Revisit the contract, request updated security documentation, confirm the insurance certificate is current and ask whether the vendor's subcontractors have changed.

Access reviews

Confirm who at the vendor has access to your environment, remove anyone who no longer needs it and make sure your own admin credentials are held by someone at the firm, not only by the vendor.

Make sure someone at the firm owns the relationship

A common gap is that everyone assumes the vendor is handling it. Designate a partner or administrator as the point of accountability, someone who can answer, "What did we ask, and what did they tell us?"

Plan for the exit

Know how you would move to a different provider. Keep your own copy of the network documentation, domain registrar login, Microsoft 365 global administrator credentials and licensing information. Firms sometimes discover during a dispute that the vendor controls critical accounts.

Training your own staff

Supervision runs both ways. Staff should know which vendors are approved, what information can be shared with them and how to verify that a support caller is really from the vendor, since attackers sometimes impersonate IT support.

A closing thought

This is general information, not legal advice. Your obligations depend on your jurisdiction and circumstances, so involve your ethics counsel where needed.

Counsel Cyber is itself a vendor to law firms, so we expect these questions. We are happy to answer a due diligence questionnaire, provide our reports and meet quarterly. If you want to evaluate your current provider against this list, we can help you do that.