Managed IT services for law firms: the due diligence that comes before the quote

A law firm buying managed IT is not buying the same product as an accounting practice or a construction company, and the difference is not technical. It is that a firm carries professional obligations over client information that survive whatever the vendor agreement says. Those obligations decide the questions, and the questions decide the shortlist.

The practical sequence is short. Establish what the regulator requires of you, translate that into contract terms, and only then compare monthly figures.

What makes a firm different from any other small business

Three things, none of which appear on a standard managed services proposal.

Privilege attaches to the material sitting on the file server. A general commercial client whose data is exposed has a commercial problem. A firm in the same position has a professional one, and the analysis runs through conduct rules rather than through the vendor’s liability cap.

Custody is not delegable. A firm remains responsible for client information regardless of who operates the infrastructure. Outsourcing the administration does not outsource the duty, and every regulator that has addressed the point has said so in similar terms.

Conflicts extend to the supplier. A provider serving several firms in the same market, or a firm and its opposing party, raises questions that a hardware vendor never does. It is a fair question to ask and a reasonable one to have answered in writing.

Start with the regulator’s own checklist

The most efficient starting document is not written by a technology vendor. The Law Society of British Columbia’s cloud computing checklist, version 4.0, updated in January 2023, runs to nine parts covering initial review of agreements, compliance requirements, security and risk management, data protection, vendor evaluation, client notification and consent, IT integration, service reliability and fees.

Firms outside British Columbia are not bound by it, and it remains the clearest published articulation of what a regulator expects a practitioner to have thought about. Two of its points deserve emphasis. It notes that due diligence “is not a one-and-done proposition”, meaning the assessment is periodic rather than a procurement step. And it contemplates that a regulator may declare a given provider prohibited, which is a contractual scenario worth having an exit clause for.

Hand the checklist to each provider during the bid. The ones who engage with it are the ones worth continuing with.

Diagram mapping the nine parts of the Law Society of British Columbia cloud computing checklist to whether the firm, the provider or both must answer them.
Three of the nine parts cannot be delegated to a supplier at all, which is the fastest way to sort a bid list.

The breach clock, and why it changes what you contract for

Under federal privacy law, a breach of security safeguards must be reported to the Office of the Privacy Commissioner of Canada where it is reasonable to believe it creates a real risk of significant harm to an individual. That test turns on the sensitivity of the information and the probability of misuse. A firm’s files score high on both by definition.

Affected individuals must be notified directly, and records of every breach must be kept for two years, including ones assessed as not reportable.

Read that against a typical managed services agreement and a gap appears. The report requires the cause, the timing, the categories of information involved, the number of individuals affected and the mitigation steps taken. Almost all of that information lives in the provider’s logs, not the firm’s. If the agreement does not oblige the provider to produce a forensic account within a defined window, the firm is left assembling a regulatory filing from a supplier who is under no contractual pressure to help.

Obligation What the firm must produce Where the information actually lives
Assess real risk of significant harm What was accessed, by whom, for how long Provider’s logs
Report to the Commissioner Cause, timing, categories, numbers Provider’s incident record
Notify individuals Scope of affected client matters Firm’s file system, mapped by the provider
Maintain records for two years A durable account of every incident Neither party, unless specified

Write the log retention period, the forensic support obligation and the response window into the agreement. It is a paragraph, and it is the difference between a filing and a scramble.

Five-step diagram of the breach response sequence: detect, assess, report, notify, retain, annotated with whether the provider or the firm holds the underlying records.
The obligation sits with the firm at every step. The evidence sits with the provider for most of them.

Scoping, and the most common error

A firm that buys general business IT support services and assumes professional-conduct requirements are handled by default has made the mistake this category produces most often. Standard managed IT is scoped around uptime, helpdesk volume and patch compliance. None of those are wrong, and none of them address custody, privilege or the evidentiary trail a regulator will want.

The fix is not a different provider. It is an addendum listing the firm-specific requirements: data residency, log retention, forensic cooperation, access controls on matter folders, restrictions on offshore administration, and notification triggers. Most competent providers will sign it. The ones who will not have told you something useful.

Questions worth putting in writing

Ask the provider Why the answer matters
Where is the data stored, and does any administrative access originate outside the country Residency is a conduct question before it is a technical one
Which of your staff can read client files, and is that access logged and reviewable by us Custody of privileged material remains the firm’s responsibility
What is your response commitment for a suspected compromise, in hours The breach assessment clock starts before you know the scope
How long are logs retained, and will you produce a forensic account on request Without this, the regulatory filing has no evidentiary basis
Do you act for parties adverse to our clients, and how would you tell us A supplier conflict is not covered by a standard confidentiality clause
What happens to our data and documentation if this agreement ends Exit terms matter most when you least want to negotiate them
Who tests restores, how often, and may we see the last report An untested backup is a hypothesis, not a continuity plan

Practical order of operations

Get the regulator’s checklist in front of the providers first. Add the breach-response and log-retention clauses to the draft agreement second. Compare monthly figures last, and expect the firm-specific requirements to add something to the number.

That addition is the cost of the obligations the practice already carries. It was simply being paid in risk rather than in fees.

JP Defence
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.