Every law firm depends on people and companies who are not lawyers: IT providers, cloud platforms, e-discovery vendors, shredding services, outsourced billing, answering services. Many of them see or can reach client information. ABA Model Rule 5.3 addresses a lawyer's responsibilities regarding nonlawyer assistance, and ABA Formal Opinion 477R and Formal Opinion 498 both discuss applying supervision principles when lawyers rely on outside technology providers.
This post explains in practical terms how a firm can approach vendor supervision. It describes ABA guidance and general practice, and it is not legal advice. Confirm your state's version of the rules with your bar.
What Rule 5.3 is about
In general terms, Rule 5.3 asks lawyers with managerial authority to make reasonable efforts to ensure that the firm has measures giving reasonable assurance that nonlawyer conduct is compatible with the lawyer's professional obligations. It also addresses supervision of individual nonlawyers working under a lawyer. The ABA has said that this framework extends to outside service providers, and the degree of diligence depends on the circumstances, including the sensitivity of the information and the vendor's access.
Build a vendor inventory
Start with a list. For each vendor, record:
- What service they provide
- What client or firm data they can access or store
- Who at the firm owns the relationship
- Contract dates and renewal terms
- Whether they hold subcontractors
- The last date you reviewed them
You will likely find vendors nobody remembered, often small cloud tools adopted by individuals.
Tier them by risk
Not every vendor needs the same scrutiny. A simple three-tier scheme works:
- High: Systems with broad access to client data or your network, such as your IT provider, document management, email platform and backup provider.
- Medium: Vendors that handle limited client information, such as e-signature, court reporting or e-discovery tools.
- Low: Vendors with no meaningful data access.
Spend your diligence effort in proportion.
What to review for high-tier vendors
Before signing
- Confidentiality terms covering client information
- Where data is stored and who can access it
- Security controls, such as multi-factor authentication, encryption and logging
- Independent assessments or reports the vendor can share, and their scope
- Breach notification commitments, including how quickly they will tell you
- Data return and deletion terms when the relationship ends
- Insurance coverage the vendor carries
During the relationship
- Annual review of access and permissions
- Review of any reported incidents
- Confirmation that staff with access are screened and trained
- Check that the vendor's own use of multi-factor authentication covers the accounts that reach your systems
At exit
- Written confirmation of data return and deletion
- Removal of all vendor accounts and credentials
- Rotation of any shared passwords or keys
Give vendors clear instructions
Supervision includes telling vendors what you expect. A short vendor security addendum can state that client data must be kept confidential, used only for the services, not used for training AI models without permission, and that incidents must be reported promptly.
Document your diligence
Keep a folder with each vendor's contract, questionnaire responses, review notes and dates. If a client, insurer or regulator asks how you oversee vendors, you can show a process instead of describing an intention.
Common mistakes
- Assuming a big-name vendor needs no review
- Accepting default terms without reading confidentiality language
- Letting vendors keep administrator access indefinitely
- Reviewing only at purchase and never again
- Forgetting vendors used by individual attorneys on personal subscriptions
A hypothetical illustration
Consider a hypothetical firm whose outsourced transcription service stores recordings in a cloud folder with a shareable link. Nobody at the firm ever asked how links are secured or who at the vendor can open them. A basic vendor review would have raised those questions before any matter files were uploaded.
Getting started
Begin with your top five vendors and complete the review items above. Counsel Cyber helps firms build vendor inventories and security questionnaires, and, as an IT provider ourselves, we are happy to answer the same questions we recommend you ask of anyone else.