ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Rule 5.3 and Your IT Vendor: Supervising Nonlawyer Technology Help

ABA Model Rule 5.3 on supervising nonlawyer assistance, and how it can apply to outside IT vendors, cloud providers and consultants handling client data.

3 min readBy Counsel Cyber Team

When a firm hires an outside company to run its network, host its documents or manage its email, that company's people often see more client information than most of the firm's own staff. Yet vendor oversight is one of the least-discussed parts of legal technology compliance.

ABA Model Rule 5.3 deals with a lawyer's responsibilities regarding nonlawyer assistance. This post explains what it says in general terms, how the ABA has connected it to technology vendors, and what practical steps a firm administrator can take. This is not legal advice; individual states adopt their own versions of the rules, so confirm specifics with your state bar.

What Rule 5.3 says, in general terms

Rule 5.3 has three broad parts. Partners and lawyers with managerial authority should make reasonable efforts to have measures in place giving reasonable assurance that nonlawyers' conduct is compatible with the lawyer's professional obligations. Lawyers with direct supervisory authority over a nonlawyer should make reasonable efforts to ensure that person's conduct fits those obligations. And a lawyer can be responsible for a nonlawyer's conduct in certain circumstances, such as ordering or ratifying it.

The commentary has long recognized that "nonlawyer assistance" includes people outside the firm, and the ABA has discussed this in the context of cloud services and other outside vendors. The ABA's formal opinions on securing communications (477R) and on virtual practice (498) both point lawyers toward understanding and supervising the technology and the people behind it.

Why this matters for IT vendors specifically

Think about what your managed IT provider can do: reset passwords, read mailboxes if needed, restore backups, install software on every attorney's laptop. Your document management host stores the work product of every matter. Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized disclosure of client information, and vendor access is part of that picture.

A practical vendor oversight checklist

Before you hire

  • Ask for a written description of the provider's security practices: access controls, MFA for their own technicians, background screening, logging
  • Ask whether they have worked with law firms and understand confidentiality duties
  • Ask about their insurance coverage
  • Review whether the contract includes confidentiality terms covering client information

In the contract

  1. A confidentiality clause that explicitly covers client data
  2. Notice requirements if the vendor has a security incident
  3. Clear data ownership and return-of-data terms at the end of the relationship
  4. A restriction on subcontracting without your knowledge
  5. Information about where data is stored and who may access it

During the relationship

  • Keep a vendor inventory: who they are, what data they touch, what the contract says, when it renews
  • Ask each critical vendor annually for updated security information
  • Review who has administrator access to your systems and remove accounts that are no longer needed
  • Make sure former staff of the vendor no longer hold credentials to your environment

At the end

  • Confirm in writing that your data was returned and then deleted
  • Change shared passwords and revoke vendor accounts the same day

Assigning responsibility inside the firm

Supervision is easier when one person owns it. Many firms assign a partner as the point of accountability and an administrator to keep the vendor inventory. Without that, reviews tend to happen only after something goes wrong.

Mistakes we see often

  • Treating "the vendor is a big, well-known company" as the entire due diligence
  • Giving a vendor permanent administrator access with no review
  • Never asking what happens to data when the contract ends
  • Letting staff sign up for free file-sharing or AI tools that nobody at the firm vetted

That last one matters: informal tools are vendors too, and they need the same questions asked.

Where Counsel Cyber fits

As a managed provider ourselves, we expect to be asked these questions. If you would like help building a vendor inventory or reviewing the security terms in your current agreements, we can walk through it with your administrator.