When lawyers think about supervision, they usually picture a partner reviewing an associate's brief. But ABA Model Rules 5.1 and 5.3 reach further. Rule 5.1 addresses the responsibilities of partners and supervisory lawyers to make reasonable efforts to ensure that the firm has measures giving reasonable assurance that lawyers conform to the Rules. Rule 5.3 addresses lawyers' responsibilities regarding nonlawyer assistance, and its comments discuss using outside service providers, such as cloud storage and IT vendors, who handle client information.
ABA Formal Opinion 477R and Formal Opinion 498 both touch on these duties in the context of securing communications and virtual practice, and Opinion 512 discusses supervision in the context of generative AI. This post is general information, not legal advice. Check your own state's rules and opinions, which may differ.
Who counts as "nonlawyer assistance"
In practice, a firm's technology supervision duties may reach:
- Paralegals, assistants, and administrators who handle client files
- Your managed IT provider and its technicians
- Cloud vendors that store documents, email, or billing data
- E-discovery and document review vendors
- Contract staff, temporary workers, and offshore support
- Software tools and AI products that process client information
The question is not whether these people are employees. It is whether they have access to client information or support the delivery of legal services.
What reasonable supervision can look like
The rules use the word "reasonable," which depends on the firm's size and circumstances. A forty-person firm and a solo practitioner will not have identical procedures. Common elements include policies, training, vendor selection, oversight, and a response process.
For internal staff
- Written policies on confidentiality, acceptable use, device security, remote work, and AI.
- Training at onboarding and at regular intervals, including phishing and wire-fraud awareness.
- Access limits so people can reach only what they need.
- Monitoring appropriate to the firm, such as alerts for unusual file access.
- A reporting path that encourages people to disclose mistakes quickly.
- Consequences that are clear and consistently applied.
For outside vendors
- Due diligence before hiring. Ask about security practices, background checks, subcontractors, insurance, and breach history. Request independent audit reports where they exist, and have someone qualified read them.
- Contract terms. Include confidentiality, data ownership, breach notification timelines, return or destruction of data, and audit or review rights.
- Limiting access. Give vendors only the access they need, with unique accounts, MFA, and logging. Avoid shared credentials.
- Ongoing review. Revisit key vendors annually: has their security posture changed, have they had incidents, do the terms still fit?
- Offboarding. Revoke access and confirm data deletion when a vendor relationship ends.
Assign a responsible person
Supervision diffuses easily. Name an individual, such as a technology partner or administrator, to maintain the vendor list, track reviews, and report to the partnership. For larger firms, a small committee may work.
Build a vendor register
A simple spreadsheet is enough to start. For each vendor, record:
- What the vendor does and what client data it touches
- The contract date, term, and renewal notice date
- Primary contact and security contact
- Date of last review and documents on file
- Whether MFA is enforced for their access to your systems
- Exit plan: how you retrieve data
This register also answers client security questionnaires and cyber insurance applications much faster.
Supervising your own IT provider
Treat your managed IT provider as the vendor with the most access. Ask for:
- A list of their staff with administrative access to your environment
- Logs of administrative actions on request
- Written incident response commitments
- Regular reports on patching, backups, and security alerts
A provider that welcomes this oversight is usually a good sign.
Common gaps
- Vendors added by individual attorneys without any review
- No one knows which tools hold client data
- Contracts without breach notification terms
- Former vendors who still have credentials
- Training offered only to new hires
Documentation is your friend
Keep records of training, vendor reviews, and policy acknowledgments. If a question ever arises about whether the firm made reasonable efforts, a clear record is far more persuasive than recollection.
A closing thought
Counsel Cyber helps firms build vendor registers, review security documentation, and set up the access controls that make supervision practical. If you want a hand starting a vendor review program, we are glad to help.