Most law firms using AI cannot produce a current Data Processing Agreement if the SRA or a client asked for it today. This guide gives COLPs, Practice Managers, and Managing Partners the framework to change that — in six to eight weeks.
A 14-page practical guide to AI vendor due diligence that satisfies ISO 42001 Clause 6.6 and SRA Code 6.3 simultaneously. The six-question framework, three-tier risk model, DPA essentials, the Vendor Due Diligence Record structure, and a week-by-week implementation sequence. No specialist legal technology resource required.
One-time purchase · No subscription · Instant download · 14pp print-ready PDF
Most law firms that use AI are using someone else's AI. They have not built their own model. They have licensed a commercial product. And that creates a governance gap firms routinely underestimate.
SRA Code 6.3 — the confidentiality obligation — does not distinguish between data shared with counsel, data shared with an expert witness, and data shared with an AI vendor's system. The obligation is the same in each case: the firm must ensure appropriate protections are in place. And the obligation to obtain those protections rests with the firm — not the vendor.
Confidentiality
Client information in any AI vendor's system is subject to the firm's confidentiality obligations in full. A DPA is not optional — it is the evidence that the obligation is met.
Competence
Selecting an AI vendor requires understanding what the system does and its known limitations. A vendor who cannot document its limitations cannot be selected under a competence standard.
Systems & Controls
A vendor relationship with no due diligence, no contractual protections, and no review cadence is the absence of systems and controls. The SRA holds the firm — not the vendor — responsible.
A structured pocket guide that takes a COLP or Practice Manager from zero vendor governance to an audit-ready evidence position in six to eight weeks, without requiring a specialist legal technology function.
The four SRA obligations that vendor due diligence serves — Code 6.3 (confidentiality), Code 1.4 (competence), Code 2.1 (systems and controls), and Code 3.1 (supervision of AI-assisted work) — each mapped to what the obligation requires at the vendor level. Includes the Warning on compliance asymmetry: most vendors will not proactively provide what the firm needs; the obligation to ask and negotiate rests with the firm.
SRA Code 6.3 · 1.4 · 2.1 · 3.1Clause 6.6 expanded for a law firm context: supplier selection criteria (what to assess, minimum acceptable standard for data governance, security certification, AI system documentation, training data policy, and incident notification SLA), supplier evaluation and documentation requirements, the five essential contractual arrangements (DPA, incident notification, audit rights, exit assistance, subcontractor clause), ongoing monitoring requirements, and the EU AI Act supply chain cross-reference for EU-based vendors.
ISO 42001 Clause 6.6 · EU AI Act Art. 9The three-tier risk model — Tier 1 (High: privileged client data, client-facing outputs), Tier 2 (Medium: non-privileged client data, internal-facing), Tier 3 (Low: no client data, administrative) — with the due diligence requirement for each tier. Includes the six questions every vendor must answer regardless of tier, with what each answer should contain and what a non-compliant answer looks like. Includes the Warning on the most common error: Tier 3 systems drifting to Tier 1 when fee earners paste client instructions into general-purpose AI tools.
Three-Tier Model · Six-Question FrameworkThe five-section consolidated evidence artefact for ISO 42001 Gap 9 and SRA Code 6.3: Vendor Identity, Pre-Adoption Assessment, Contractual Protections, Ongoing Review Log, and Risk Decision. What each section contains, who owns it, how it is updated. The eight-item evidence checklist for each vendor. The gap-response table — what to do when a vendor fails a criterion, for each tier.
Vendor DD Record · Evidence Checklist · Gap-Response TableThe week-by-week implementation sequence from zero vendor governance to a defensible evidence set: Week 1 (AI system inventory), Week 2 (Tier 1 identification and DPA status), Weeks 3–4 (six-question framework for Tier 1 vendors), Weeks 4–5 (Tier 1 DPA review), Weeks 5–6 (Tier 2 due diligence), Weeks 6–7 (Tier 3 confirmation), Weeks 7–8 (COLP sign-off and compliance calendar diarising). Includes the "what good looks like at month three" benchmark.
Seven-Week Sequence · COLP Sign-Off · CAL-AIMS-LG-001Regardless of risk tier, every AI vendor your firm uses must be able to answer these six questions. The guide expands each one with what a satisfactory answer contains, what a non-compliant answer looks like, and what to do when a vendor cannot or will not answer.
EU, UK, US, or other. Relevant to UK GDPR international transfer obligations and SRA confidentiality requirements. Data stored outside the UK or EU without adequate safeguards is a potential Code 6.3 breach.
A 'yes' without client consent is a potential breach of Code 6.3. The answer should be 'no, unless you opt in' — and that must be in writing in the DPA, not buried in standard terms.
Every organisation with access to your client data — not just the primary vendor. The list must be available on request and the vendor must notify you in advance of changes. Absence of a sub-processor list is a disqualifying gap for Tier 1 systems.
How quickly will you tell us if there is a security incident? 24 hours is best practice; 72 hours is the UK GDPR standard for controller notification to the ICO. This must be a contractual commitment, not a verbal assurance.
Hallucination rates, accuracy limitations, content types the system handles poorly, and training data cutoffs. This is the competence evidence — a vendor who cannot answer this question in writing cannot be selected under Code 1.4.
Data deletion or return timeline, written confirmation of deletion, and format of data return. Without this clause in the DPA, the firm may face a GDPR retention problem on termination and cannot confirm to clients that their data has been deleted.
Most AI vendors — including reputable, well-funded ones — will not proactively provide all the information a law firm needs to meet its SRA obligations. The obligation is on the firm to ask, to request the documentation, and to negotiate contractual protections where they are absent from standard terms. Signing a standard vendor agreement without review does not satisfy the due diligence obligation. If a vendor refuses to provide a DPA for a system that processes client data, that is a disqualifying gap.
Not every AI system carries the same risk. Due diligence should be proportionate. Use the AI register to assign each system a risk tier — then apply the corresponding level of due diligence.
Processes privileged client data; outputs used directly in client advice or documents; client-facing
Full DD questionnaire; DPA reviewed by COLP or solicitor; security certification checked; incident notification SLA confirmed in contract; training data restriction confirmed; annual review minimum
Processes non-privileged client data (e.g. billing, contact info); outputs reviewed before use; internal-facing
DPA in place and reviewed; data jurisdiction confirmed; security certification checked; training data policy confirmed; annual review minimum
No client data; outputs reviewed before use; purely administrative (scheduling, billing, HR tasks)
Confirm no client data enters system in writing; standard vendor terms reviewed; review triggered on significant system change only
Law firms routinely underestimate how quickly a general-purpose AI tool becomes a client data processor. A fee earner using a consumer AI chatbot to draft a letter — and including the client's name, matter details, or instructions — has made that tool a Tier 1 system without any of the Tier 1 due diligence in place. The firm's AI use policy must be explicit about which systems are approved for client data and at what tier. Staff training on data classification is the control that prevents unintended tier migration.
If your firm does not currently have a vendor due diligence programme for AI, the following sequence gets you to a defensible evidence set without requiring specialist legal technology resource.
List every AI tool the firm uses — including general-purpose tools that fee earners may be using individually without firm approval. Use the AI register structure from ISO 42001 Gap 3. Assign each system a risk tier using the three-tier model.
Focus on systems that process privileged client data. For each Tier 1 system, confirm whether a Data Processing Agreement currently exists and has been reviewed. If not, request one — in writing — from the vendor immediately.
Send the six questions to each Tier 1 vendor. Request the DPA, security certification, sub-processor list, and written training data policy. Document the responses in the Vendor Due Diligence Record for each vendor.
The COLP or a nominated solicitor reviews each Tier 1 DPA against the five contractual requirements in the guide: DPA, incident notification SLA, audit rights clause, exit assistance clause, and subcontractor clause. Identify gaps. Seek amendments where required. Record the review and outcome in the Vendor Due Diligence Record.
Apply the same process to Tier 2 systems with lighter-touch review: confirm DPA is in place, confirm data jurisdiction, check security certification. Record in the Vendor Due Diligence Record for each Tier 2 vendor.
For each Tier 3 system, obtain written confirmation from the fee earner responsible that no client data enters the system. Record this in the AI register alongside the tier assignment. Communicate data classification rules to all fee earners using Tier 3 tools.
COLP reviews and signs off risk decisions for all vendors. Annual review dates are diarised in the Unified Compliance Calendar (CAL-AIMS-LG-001). Vendor Due Diligence Records are filed in the document management system, cross-referenced in the AI register. At month three, the firm can produce an AI register, a Vendor Due Diligence Record for every Tier 1 and Tier 2 system, COLP sign-off, and next review dates — a defensible evidence set for SRA regulatory review and ISO 42001 assessment.
Every framework element in the guide is dual-referenced — ISO 42001 Clause 6.6 on one side, the SRA Code obligation on the other. This means completing the guide satisfies both the ISO management system requirement and the SRA professional conduct obligation in a single evidence trail. No duplication. No separate programmes.
The five-section Vendor Due Diligence Record structure is defined in full: what goes in each section, who owns it, and how it is updated at annual or triggered review. The eight-item evidence checklist for each vendor tells you exactly what documents to hold. The gap-response table tells you what to do when a vendor fails a criterion at each risk tier.
The seven-week implementation sequence is designed for COLPs and Practice Managers working without a dedicated legal technology function. Every step names who does what, what document is produced, and what evidence is created. The guide is sized for a firm of any scale — from a small regional practice to a large regional or national firm with multiple office locations.
The guide cross-references the EU AI Act (Regulation (EU) 2024/1689) supply chain obligations for deployers of high-risk AI systems — relevant for firms using EU-based AI vendors or advising clients on EU AI Act compliance. The Clause 6.6 due diligence process, applied to EU-based vendors, provides the framework for verifying deployer obligations under Article 9.
Gap 9 — vendor due diligence — carries direct COLP accountability under SRA Code 2.1. This guide is written for the people who own that accountability, not the people who advise on it.
14-page pocket guide. Instant download. One-time purchase.
Processed by Stripe · Secure checkout · 60-day money-back guarantee · Instant download after purchase
Yes. SRA Code 6.3 (confidentiality) and Code 2.1 (systems and controls) apply regardless of firm size. A sole practitioner using an AI drafting tool that processes client instructions has the same vendor due diligence obligation as a large national firm. The seven-week implementation sequence in the guide is designed to be completed by a COLP working alone — it does not require a dedicated legal technology team or specialist resource. The three-tier risk model scales proportionately: a small firm with fewer AI systems completes the programme faster, not differently.
A DPA is a necessary condition — not a sufficient one. Having a DPA does not mean it covers all five contractual requirements in Part 2 of the guide (incident notification SLA, audit rights clause, exit assistance clause, subcontractor clause, and training data restriction). Many standard vendor DPAs omit one or more of these. The guide's Part 4 evidence checklist identifies what the DPA must contain and what to do when it does not. If you have a DPA but have not reviewed it against the Clause 6.6 checklist, the gap is still open.
The free guide identifies Gap 9 (vendor due diligence) as one of five high-priority SRA risk gaps and explains why it creates SRA exposure. The Gap Severity Matrix confirms that Gap 9 is rated High severity and identifies the consolidated artefact (Vendor Due Diligence Record) that closes it. This pocket guide is the operational instrument that builds that artefact — it gives you the framework, the record structure, and the implementation sequence. The three products are designed to be used in sequence: identify the gap, confirm the risk level, then implement the close.
Major AI vendors typically offer standard DPAs that can be accepted or negotiated — most established legal technology platforms and large LLM providers have enterprise DPA options. The guide addresses this directly: the firm should not accept standard terms as the complete picture, but should review them against the Part 2 checklist and request amendments where gaps are identified. If a vendor refuses to provide a DPA at all for a system processing client data, the guide recommends treating that as a disqualifying gap — the firm should not use that system with client data until a DPA is in place. The guide also covers how to document a risk decision when a vendor cannot meet a specific criterion, so the gap is managed and evidenced rather than simply ignored.
Yes. The purchase licence permits internal firm use — sharing with the COLP, Practice Manager, Managing Partner, and other governance roles within the purchasing firm. It does not permit resale, redistribution to third parties, or use as a deliverable in consulting or legal advisory engagements. Multi-firm licences and consultant licences are available — contact support@unuslondon.com.
The six-question framework. The three-tier risk model. The Vendor Due Diligence Record. The seven-week implementation sequence. Everything a COLP needs to own this gap. £47.
One-time · Instant download · 14pp print-ready PDF · 60-day guarantee · No specialist resource required