ISO 42001 × SRA Standards & Regulations › Legal Series › AI Vendor Due Diligence Pocket Guide — £47
Also in this series: Free Guide · £19 Matrix · £167 Guide
ISO 42001 Clause 6.6 · SRA Code 6.3 · Legal Edition · Pocket Guide · £47

The AI Vendor Your Firm
Signed Up to Is Processing
Client Data Right Now.

Most law firms using AI cannot produce a current Data Processing Agreement if the SRA or a client asked for it today. This guide gives COLPs, Practice Managers, and Managing Partners the framework to change that — in six to eight weeks.

A 14-page practical guide to AI vendor due diligence that satisfies ISO 42001 Clause 6.6 and SRA Code 6.3 simultaneously. The six-question framework, three-tier risk model, DPA essentials, the Vendor Due Diligence Record structure, and a week-by-week implementation sequence. No specialist legal technology resource required.

One-time purchase · No subscription · Instant download · 14pp print-ready PDF

ISO 42001 Clause 6.6 Decoded SRA Code 6.3 Aligned Six-Question DD Framework Three-Tier Risk Model DPA Essentials Checklist Seven-Week Implementation
The Gap

The Moment Client Data Enters a Vendor's System, Your SRA Obligations Travel With It.

Most law firms that use AI are using someone else's AI. They have not built their own model. They have licensed a commercial product. And that creates a governance gap firms routinely underestimate.

The Core Problem

The vast majority of law firms using AI have not completed adequate due diligence on those AI vendors — and many could not produce a current Data Processing Agreement if the SRA or a client asked for it today.

SRA Code 6.3 — the confidentiality obligation — does not distinguish between data shared with counsel, data shared with an expert witness, and data shared with an AI vendor's system. The obligation is the same in each case: the firm must ensure appropriate protections are in place. And the obligation to obtain those protections rests with the firm — not the vendor.

SRA Code 6.3

Confidentiality

Client information in any AI vendor's system is subject to the firm's confidentiality obligations in full. A DPA is not optional — it is the evidence that the obligation is met.

SRA Code 1.4

Competence

Selecting an AI vendor requires understanding what the system does and its known limitations. A vendor who cannot document its limitations cannot be selected under a competence standard.

SRA Code 2.1

Systems & Controls

A vendor relationship with no due diligence, no contractual protections, and no review cadence is the absence of systems and controls. The SRA holds the firm — not the vendor — responsible.

The Deliverable

Fourteen Pages. Five Parts. One Defensible Evidence Set.

A structured pocket guide that takes a COLP or Practice Manager from zero vendor governance to an audit-ready evidence position in six to eight weeks, without requiring a specialist legal technology function.

PG-AIMS-LG-001 v1.0 · ISO 42001 × SRA Standards & Regulations · Legal Edition

AI Vendor Due Diligence for Law Firms

£47 · 14pp
Part 1
The SRA Obligations Framework for AI Vendors

The four SRA obligations that vendor due diligence serves — Code 6.3 (confidentiality), Code 1.4 (competence), Code 2.1 (systems and controls), and Code 3.1 (supervision of AI-assisted work) — each mapped to what the obligation requires at the vendor level. Includes the Warning on compliance asymmetry: most vendors will not proactively provide what the firm needs; the obligation to ask and negotiate rests with the firm.

SRA Code 6.3 · 1.4 · 2.1 · 3.1
Part 2
ISO 42001 Clause 6.6 Decoded

Clause 6.6 expanded for a law firm context: supplier selection criteria (what to assess, minimum acceptable standard for data governance, security certification, AI system documentation, training data policy, and incident notification SLA), supplier evaluation and documentation requirements, the five essential contractual arrangements (DPA, incident notification, audit rights, exit assistance, subcontractor clause), ongoing monitoring requirements, and the EU AI Act supply chain cross-reference for EU-based vendors.

ISO 42001 Clause 6.6 · EU AI Act Art. 9
Part 3
A Proportionate Due Diligence Approach

The three-tier risk model — Tier 1 (High: privileged client data, client-facing outputs), Tier 2 (Medium: non-privileged client data, internal-facing), Tier 3 (Low: no client data, administrative) — with the due diligence requirement for each tier. Includes the six questions every vendor must answer regardless of tier, with what each answer should contain and what a non-compliant answer looks like. Includes the Warning on the most common error: Tier 3 systems drifting to Tier 1 when fee earners paste client instructions into general-purpose AI tools.

Three-Tier Model · Six-Question Framework
Part 4
The Vendor Due Diligence Record

The five-section consolidated evidence artefact for ISO 42001 Gap 9 and SRA Code 6.3: Vendor Identity, Pre-Adoption Assessment, Contractual Protections, Ongoing Review Log, and Risk Decision. What each section contains, who owns it, how it is updated. The eight-item evidence checklist for each vendor. The gap-response table — what to do when a vendor fails a criterion, for each tier.

Vendor DD Record · Evidence Checklist · Gap-Response Table
Part 5
Implementing Vendor Due Diligence — Seven-Week Sequence

The week-by-week implementation sequence from zero vendor governance to a defensible evidence set: Week 1 (AI system inventory), Week 2 (Tier 1 identification and DPA status), Weeks 3–4 (six-question framework for Tier 1 vendors), Weeks 4–5 (Tier 1 DPA review), Weeks 5–6 (Tier 2 due diligence), Weeks 6–7 (Tier 3 confirmation), Weeks 7–8 (COLP sign-off and compliance calendar diarising). Includes the "what good looks like at month three" benchmark.

Seven-Week Sequence · COLP Sign-Off · CAL-AIMS-LG-001
The Six-Question Framework

What to Ask Every AI Vendor — and What to Demand in Writing

Regardless of risk tier, every AI vendor your firm uses must be able to answer these six questions. The guide expands each one with what a satisfactory answer contains, what a non-compliant answer looks like, and what to do when a vendor cannot or will not answer.

01
Data Jurisdiction · SRA Code 6.3 · UK GDPR
Where is our data stored?

EU, UK, US, or other. Relevant to UK GDPR international transfer obligations and SRA confidentiality requirements. Data stored outside the UK or EU without adequate safeguards is a potential Code 6.3 breach.

02
Training Data · SRA Code 6.3 · Client Consent
Do you use our data to train your models?

A 'yes' without client consent is a potential breach of Code 6.3. The answer should be 'no, unless you opt in' — and that must be in writing in the DPA, not buried in standard terms.

03
Sub-Processors · SRA Code 6.3 · UK GDPR Art. 28
Who are your sub-processors?

Every organisation with access to your client data — not just the primary vendor. The list must be available on request and the vendor must notify you in advance of changes. Absence of a sub-processor list is a disqualifying gap for Tier 1 systems.

04
Incident Notification · SRA Code 6.3 · UK GDPR Art. 33
What is your incident notification commitment?

How quickly will you tell us if there is a security incident? 24 hours is best practice; 72 hours is the UK GDPR standard for controller notification to the ICO. This must be a contractual commitment, not a verbal assurance.

05
System Limitations · SRA Code 1.4 · ISO 42001 Cl. 6.6
What are the known limitations of your AI system?

Hallucination rates, accuracy limitations, content types the system handles poorly, and training data cutoffs. This is the competence evidence — a vendor who cannot answer this question in writing cannot be selected under Code 1.4.

06
Data Return / Deletion · SRA Code 6.3 · UK GDPR Art. 17
How do we get our data back or deleted at end of contract?

Data deletion or return timeline, written confirmation of deletion, and format of data return. Without this clause in the DPA, the firm may face a GDPR retention problem on termination and cannot confirm to clients that their data has been deleted.

Warning — Compliance Asymmetry

Most AI vendors — including reputable, well-funded ones — will not proactively provide all the information a law firm needs to meet its SRA obligations. The obligation is on the firm to ask, to request the documentation, and to negotiate contractual protections where they are absent from standard terms. Signing a standard vendor agreement without review does not satisfy the due diligence obligation. If a vendor refuses to provide a DPA for a system that processes client data, that is a disqualifying gap.

The Risk Model

Proportionate Due Diligence — Scaled to What Each System Does With Client Data

Not every AI system carries the same risk. Due diligence should be proportionate. Use the AI register to assign each system a risk tier — then apply the corresponding level of due diligence.

Tier
System Characteristics
Due Diligence Required
Tier 1
High

Processes privileged client data; outputs used directly in client advice or documents; client-facing

Full DD questionnaire; DPA reviewed by COLP or solicitor; security certification checked; incident notification SLA confirmed in contract; training data restriction confirmed; annual review minimum

Tier 2
Medium

Processes non-privileged client data (e.g. billing, contact info); outputs reviewed before use; internal-facing

DPA in place and reviewed; data jurisdiction confirmed; security certification checked; training data policy confirmed; annual review minimum

Tier 3
Low

No client data; outputs reviewed before use; purely administrative (scheduling, billing, HR tasks)

Confirm no client data enters system in writing; standard vendor terms reviewed; review triggered on significant system change only

The Most Common Error — Tier 3 Systems Drifting to Tier 1

Law firms routinely underestimate how quickly a general-purpose AI tool becomes a client data processor. A fee earner using a consumer AI chatbot to draft a letter — and including the client's name, matter details, or instructions — has made that tool a Tier 1 system without any of the Tier 1 due diligence in place. The firm's AI use policy must be explicit about which systems are approved for client data and at what tier. Staff training on data classification is the control that prevents unintended tier migration.

The Implementation Sequence

Zero to Audit-Ready in Seven Weeks.

If your firm does not currently have a vendor due diligence programme for AI, the following sequence gets you to a defensible evidence set without requiring specialist legal technology resource.

Week 1
Inventory your AI systems

List every AI tool the firm uses — including general-purpose tools that fee earners may be using individually without firm approval. Use the AI register structure from ISO 42001 Gap 3. Assign each system a risk tier using the three-tier model.

Week 2
Identify your Tier 1 systems and DPA status

Focus on systems that process privileged client data. For each Tier 1 system, confirm whether a Data Processing Agreement currently exists and has been reviewed. If not, request one — in writing — from the vendor immediately.

Weeks 3–4
Complete the six-question framework for each Tier 1 vendor

Send the six questions to each Tier 1 vendor. Request the DPA, security certification, sub-processor list, and written training data policy. Document the responses in the Vendor Due Diligence Record for each vendor.

Weeks 4–5
Review Tier 1 DPAs against the contractual checklist

The COLP or a nominated solicitor reviews each Tier 1 DPA against the five contractual requirements in the guide: DPA, incident notification SLA, audit rights clause, exit assistance clause, and subcontractor clause. Identify gaps. Seek amendments where required. Record the review and outcome in the Vendor Due Diligence Record.

Weeks 5–6
Tier 2 due diligence

Apply the same process to Tier 2 systems with lighter-touch review: confirm DPA is in place, confirm data jurisdiction, check security certification. Record in the Vendor Due Diligence Record for each Tier 2 vendor.

Weeks 6–7
Tier 3 confirmation

For each Tier 3 system, obtain written confirmation from the fee earner responsible that no client data enters the system. Record this in the AI register alongside the tier assignment. Communicate data classification rules to all fee earners using Tier 3 tools.

Weeks 7–8
COLP sign-off and compliance calendar diarising

COLP reviews and signs off risk decisions for all vendors. Annual review dates are diarised in the Unified Compliance Calendar (CAL-AIMS-LG-001). Vendor Due Diligence Records are filed in the document management system, cross-referenced in the AI register. At month three, the firm can produce an AI register, a Vendor Due Diligence Record for every Tier 1 and Tier 2 system, COLP sign-off, and next review dates — a defensible evidence set for SRA regulatory review and ISO 42001 assessment.

What You Get

Everything a COLP Needs to Own This Gap.

⚖️ Dual Framework

SRA Code and ISO 42001 Clause 6.6 Mapped Together

Every framework element in the guide is dual-referenced — ISO 42001 Clause 6.6 on one side, the SRA Code obligation on the other. This means completing the guide satisfies both the ISO management system requirement and the SRA professional conduct obligation in a single evidence trail. No duplication. No separate programmes.

📋 The Record Template

Vendor Due Diligence Record — Five-Section Structure

The five-section Vendor Due Diligence Record structure is defined in full: what goes in each section, who owns it, and how it is updated at annual or triggered review. The eight-item evidence checklist for each vendor tells you exactly what documents to hold. The gap-response table tells you what to do when a vendor fails a criterion at each risk tier.

🔍 Practical Framework

A Programme Any Firm Can Run — No Tech Specialist Needed

The seven-week implementation sequence is designed for COLPs and Practice Managers working without a dedicated legal technology function. Every step names who does what, what document is produced, and what evidence is created. The guide is sized for a firm of any scale — from a small regional practice to a large regional or national firm with multiple office locations.

🇪🇺 EU AI Act

EU AI Act Supply Chain Obligations Cross-Referenced

The guide cross-references the EU AI Act (Regulation (EU) 2024/1689) supply chain obligations for deployers of high-risk AI systems — relevant for firms using EU-based AI vendors or advising clients on EU AI Act compliance. The Clause 6.6 due diligence process, applied to EU-based vendors, provides the framework for verifying deployer obligations under Article 9.

14 Pages
Print-Ready PDF
5 Parts
Structured Guide
6 Vendor Questions
Framework
7 Week
Implementation
Who It's For

Written for the People With Personal Accountability for This Gap.

Gap 9 — vendor due diligence — carries direct COLP accountability under SRA Code 2.1. This guide is written for the people who own that accountability, not the people who advise on it.

Primary

COLPs & Practice Managers

✓Use the seven-week sequence to build the firm's vendor due diligence programme from scratch — with no specialist resource
✓Use the Vendor Due Diligence Record structure to produce COLP-signed evidence for every Tier 1 and Tier 2 vendor
✓Use the six-question framework in every new AI vendor conversation — before any contract is signed
✓Use the gap-response table to make documented risk decisions when vendors fail due diligence criteria
Primary

Managing Partners & Senior Leadership

✓Commission the vendor due diligence programme from the guide — assign the COLP as owner and the Practice Manager as implementation lead
✓Use the three-tier model to understand the firm's current vendor risk exposure before the board presentation
✓Use the "what good looks like at month three" benchmark to set the programme success criteria
✓Share with professional indemnity insurers as evidence of systematic AI vendor risk management
ISO 42001 Clause 6.6 · SRA Code 6.3 · Legal Edition · PG-AIMS-LG-001 v1.0

AI Vendor Due Diligence for Law Firms

14-page pocket guide. Instant download. One-time purchase.

£47
One-time purchase
No subscription
Instant access
VAT may apply
✓The four SRA obligations at stake — Code 6.3, 1.4, 2.1, 3.1 — each mapped to vendor due diligence requirements
✓ISO 42001 Clause 6.6 decoded for law firms — selection criteria, evaluation, contractual arrangements, ongoing monitoring
✓The six-question framework — what to ask every vendor and what to demand in writing
✓Three-tier risk model — Tier 1 / 2 / 3 — with due diligence requirements for each tier
✓Five-section Vendor Due Diligence Record — structure, ownership, eight-item evidence checklist, gap-response table
✓Seven-week implementation sequence — week-by-week from zero to audit-ready evidence set
✓EU AI Act Article 9 supply chain cross-reference for EU-based vendors
✓14pp · Print-ready PDF · Written for COLPs and Practice Managers · No specialist resource required
Purchase & Download — £47 →

Processed by Stripe · Secure checkout · 60-day money-back guarantee · Instant download after purchase

Instant download 60-day guarantee One-time purchase No subscription
ISO 42001 × SRA Standards & Regulations — Legal Series

Complete the Series

Free 5 SRA Risk Gaps
Lead magnet — 5 gaps, SRA investigation scenarios, Warning boxes, First Fix actions. 16pp.
Download Free →
£19 Gap Severity Matrix
All 9 gaps · SRA mapping · severity · EU AI Act. Single-page A3 PDF.
Learn More →
You are here £47 Vendor DD Pocket Guide
Clause 6.6 decoded · SRA Code 6.3 · 6 questions · 3-tier model · 7-week plan.
£167 Integration Guide + Calendar
Full dual-framework mapping · 8 chapters · 27-activity compliance calendar.
Learn More →
Questions

Frequently Asked Questions

Yes. SRA Code 6.3 (confidentiality) and Code 2.1 (systems and controls) apply regardless of firm size. A sole practitioner using an AI drafting tool that processes client instructions has the same vendor due diligence obligation as a large national firm. The seven-week implementation sequence in the guide is designed to be completed by a COLP working alone — it does not require a dedicated legal technology team or specialist resource. The three-tier risk model scales proportionately: a small firm with fewer AI systems completes the programme faster, not differently.

A DPA is a necessary condition — not a sufficient one. Having a DPA does not mean it covers all five contractual requirements in Part 2 of the guide (incident notification SLA, audit rights clause, exit assistance clause, subcontractor clause, and training data restriction). Many standard vendor DPAs omit one or more of these. The guide's Part 4 evidence checklist identifies what the DPA must contain and what to do when it does not. If you have a DPA but have not reviewed it against the Clause 6.6 checklist, the gap is still open.

The free guide identifies Gap 9 (vendor due diligence) as one of five high-priority SRA risk gaps and explains why it creates SRA exposure. The Gap Severity Matrix confirms that Gap 9 is rated High severity and identifies the consolidated artefact (Vendor Due Diligence Record) that closes it. This pocket guide is the operational instrument that builds that artefact — it gives you the framework, the record structure, and the implementation sequence. The three products are designed to be used in sequence: identify the gap, confirm the risk level, then implement the close.

Major AI vendors typically offer standard DPAs that can be accepted or negotiated — most established legal technology platforms and large LLM providers have enterprise DPA options. The guide addresses this directly: the firm should not accept standard terms as the complete picture, but should review them against the Part 2 checklist and request amendments where gaps are identified. If a vendor refuses to provide a DPA at all for a system processing client data, the guide recommends treating that as a disqualifying gap — the firm should not use that system with client data until a DPA is in place. The guide also covers how to document a risk decision when a vendor cannot meet a specific criterion, so the gap is managed and evidenced rather than simply ignored.

Yes. The purchase licence permits internal firm use — sharing with the COLP, Practice Manager, Managing Partner, and other governance roles within the purchasing firm. It does not permit resale, redistribution to third parties, or use as a deliverable in consulting or legal advisory engagements. Multi-firm licences and consultant licences are available — contact support@unuslondon.com.

ISO 42001 Clause 6.6 · SRA Code 6.3 · Gap 9 · Legal Edition

Your firm's AI vendors are processing client data. The SRA obligation to govern them is already in force.

The six-question framework. The three-tier risk model. The Vendor Due Diligence Record. The seven-week implementation sequence. Everything a COLP needs to own this gap. £47.

Get the Pocket Guide — £47 →

One-time · Instant download · 14pp print-ready PDF · 60-day guarantee · No specialist resource required