ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Rule 5.3 and Your IT Vendor: Supervising Nonlawyer Help

Model Rule 5.3 addresses supervision of nonlawyer assistance. Here is what that can mean for how your firm selects, contracts with and oversees its IT provider.

3 min readBy Counsel Cyber Team

Most law firms hand a great deal of sensitive access to their IT provider: administrator rights to email, file servers, document management and backups. That provider sees the same client information the lawyers do. Yet many firms manage the relationship with little more than a monthly invoice and a phone number.

ABA Model Rule 5.3 addresses a lawyer's responsibilities regarding nonlawyer assistance, and the ABA has linked it to outside technology vendors, including in Formal Opinion 477R on securing communications and Opinion 498 on virtual practice. This post explains the idea in plain English and turns it into practical steps. It is not legal advice, so confirm how your state has adopted the rule with your state bar.

What Rule 5.3 says, in general terms

The rule is directed at lawyers with managerial authority and those who directly supervise nonlawyers. In broad terms, it expects partners to make reasonable efforts to have measures in place that give reasonable assurance that nonlawyers' conduct is compatible with the lawyer's professional obligations. Supervising lawyers are expected to make reasonable efforts to see that the nonlawyer's conduct is compatible with those obligations.

The ABA's Comments to the rule discuss using nonlawyers outside the firm, which can include technology providers. The Comments mention factors such as the nature of the services, the experience and reputation of the provider and the terms of any agreement about confidentiality. In other words, the more access a vendor has, the more care you are generally expected to take.

Questions to ask before you hire or renew

Treat vendor selection as a due diligence exercise, not a price comparison.

  • How long has the provider worked with law firms, and can it speak to legal-specific needs like conflict walls and retention?
  • Who at the provider will have access to our systems, and are they background-screened?
  • What security controls does the provider apply to its own environment, such as MFA, endpoint protection and logging of administrator activity?
  • Will the provider sign a confidentiality agreement that covers client information?
  • What are the notification terms if the provider has a security incident?

Contract terms worth having in writing

A handshake and a friendly relationship are not a control. Look for these items in the agreement.

  1. Confidentiality. An explicit duty to protect client information and limit use to delivering the services.
  2. Breach notification. A commitment to notify you promptly, with a defined timeframe, if they suspect an incident touching your data.
  3. Access scope. A statement of what the provider can reach and a process for revoking access.
  4. Subcontractors. Disclosure of any third parties who might touch your environment, with equivalent obligations.
  5. Data return. What happens to your data and credentials when the relationship ends.
  6. Insurance. Whether the provider carries coverage that addresses its own errors or security failures.

Ongoing oversight, not a one-time check

Supervision is a continuing activity. Build a simple rhythm.

  • Meet quarterly with your provider to review open tickets, patch status, backup results and any security alerts.
  • Ask for a list of administrator accounts the provider holds in your systems, and confirm each one is still needed and protected by MFA.
  • Request a short written summary after any significant incident.
  • Keep a file with the contract, due diligence answers and meeting notes. If a client or insurer asks how you oversee vendors, you can answer with documents.

Common gaps we see

  • A former IT contractor whose credentials were never revoked.
  • Shared administrator passwords stored in a spreadsheet.
  • No one at the firm who can say which systems the provider can reach.
  • Software vendors for practice management or e-discovery with no review at all because they feel like "just software."

That last point matters. The same logic applies to cloud services that hold client files, so consider extending the review to them.

Make one person accountable

Assign a named partner or administrator as the owner of vendor oversight. Without a person, the work drifts. That owner does not need to be technical. They need to ask the questions above and keep the records.

Counsel Cyber works with law firms that want this kind of structure around their own IT relationship, whether or not they use us. If you would like a checklist for reviewing your current provider, we can walk through it with you.