Guide
Cloud vendor due diligence for law firms: a 24-question checklist you can reuse
Cloud vendor due diligence for law firms: a reusable 24-question checklist on security, data, contract, continuity and governance, with a decision record.
By Raghav R Handa, practising lawyer17 min read
TL;DR
- Ask the same 24 questions of every vendor in five areas: security, data handling, contract, continuity and governance.
- Get answers from the vendor's own documents (security page, trust centre, agreement), not from marketing, and test what you can yourself.
- Score each, note the gaps, decide to accept, mitigate or reject, and write a one-paragraph dated decision.
- Re-run it yearly and whenever the vendor changes its terms or you change how you use it.
Before any cloud tool touches client data, ask it the same 24 questions, in five areas: security, data handling, contract, continuity and governance. Take the answers from the vendor's own documents, test what you can yourself, score them, note the gaps and write a dated decision. That record is what shows a regulator, an insurer or a client that your choice was reasoned. This is a practical checklist, not legal advice; it gives you the questions, where to find each answer, how to judge it, and a decision template.
Scale the effort to the risk
| Tool holds | Effort |
|---|---|
| Tier 1: nothing sensitive (templates, public material) | A quick look: terms, MFA, export |
| Tier 2: ordinary client information | The full checklist |
| Tier 3: sensitive or privileged information | The full checklist, plus legal review of the agreement and a client-consent decision |
| Tier 4 data | Do not use a general tool at all |
The checklist
| # | Question | A good answer looks like | Where to find or how to test |
|---|---|---|---|
| SECURITY | |||
| 1 | Independent audit or certification (such as SOC 2 or ISO 27001)? | Current report or certificate, on the plan you will use | Trust centre; read scope and period |
| 2 | Multi-factor authentication available and enforceable? | Yes, with an admin setting to require it | Admin settings; enable it and try to log in without it |
| 3 | Encryption in transit and at rest? | Yes, stated in documentation | Security overview |
| 4 | Role-based access and page-level permissions? | Yes, with granular control | Create a test user and test restrictions |
| 5 | Audit log of access and changes? | Yes, on your plan, with stated retention | Admin area; check what it records |
| 6 | Single sign-on and automated user provisioning? | Available if you need them | Plan comparison |
| DATA HANDLING | |||
| 7 | Where is data stored? | Stated regions, with any residency option | Security overview; DPA |
| 8 | Who are the subprocessors? | A published list with change notice | Legal or trust pages |
| 9 | Is customer data used to train AI models? | No, by contract, including subprocessors | AI security statement; terms |
| 10 | How long is data retained after deletion? | A stated, short period | Privacy policy; DPA |
| 11 | What AI features exist, and what can they access? | Documented, with admin controls | AI documentation; admin settings |
| CONTRACT | |||
| 12 | Data processing agreement available? | Yes, signed or accepted by default | Legal pages |
| 13 | Business associate agreement if you handle health data? | Available on a stated plan | Security or compliance page; sales |
| 14 | Breach notification commitment? | Prompt notice with stated timing | DPA; terms |
| 15 | Liability and indemnity terms? | Read them; know what you are accepting | Terms of service |
| 16 | Governing law and dispute forum? | Acceptable to you and your insurer | Terms of service |
| CONTINUITY | |||
| 17 | Can you export everything, in usable formats? | Yes, tested by you | Export a sample and open it |
| 18 | Backups and recovery? | Stated, with a recovery process | Security overview; ask support |
| 19 | Service-level and uptime record? | Published status page and history | Status page |
| 20 | Exit: what happens to data when you leave? | Deletion on request, with confirmation | Terms; ask support |
| GOVERNANCE | |||
| 21 | Admin controls for sharing and guests? | Can disable public sharing and review guests | Admin settings; test |
| 22 | Support available when something goes wrong? | A route to a human, with stated response | Ask a real question and time it |
| 23 | Does it change terms often, and is notice given? | Notice of material change | Terms; change history |
| 24 | Who in your firm owns it? | A named person, with a review date | Your vendor register |
Contract clauses to look for
| Clause | What you want | Red flag |
|---|---|---|
| Data ownership and use | You own your data; vendor uses it only to provide the service | A licence to use your data for the vendor's own purposes |
| Data processing agreement | Present, covering processing instructions, security, subprocessors, transfers and assistance | None, or one that excludes your use |
| Breach notification | Prompt notice with a stated period | No commitment |
| Subprocessors | A list and notice of change with a chance to object | Silent changes |
| Return and deletion on exit | Export and deletion within a stated period, with confirmation | No deletion commitment |
| Liability cap | Understand it; ask what is excluded | A cap that makes any claim worthless, with no cover for data breaches |
| Term and price changes | Notice of increases; ability to leave | Auto-renewal with no notice |
| Governing law and forum | Acceptable to you and your insurer | A forum that makes any dispute impractical |
| AI and training | No training on your data; a stated retention | Silent rights to train |
Tests you can run yourself in an hour
- MFA. Turn it on for a test user and confirm you cannot log in without it.
- Sharing. Share a page to a test guest, then revoke it; confirm access stops. Check whether a public link can be disabled.
- Permissions. Restrict a page and confirm a member who is not named cannot see it, including in search.
- Export. Export a sample workspace; open the files; check structure and attachments.
- Audit log. Perform an action; find it in the log.
- Support. Ask a real question and time the answer.
- Backup or restore. Restore a deleted item, or ask how.
Scoring and the decision
- Mark each question Meets, Partly or Does not meet, with the source.
- For each gap, decide: accept (document why), mitigate (a setting, a process, a narrower use), or reject the tool.
- Treat gaps on security, breach notice, data use and export as serious.
- Write a paragraph: what the tool is for, what data goes in, the gaps and how you addressed them, and the date.
- Set a review date within a year.
| Rating | Meaning | Action |
|---|---|---|
| Green | Meets all high-weight questions | Approve |
| Amber | Gaps in some questions, with mitigations | Approve with conditions and a review date |
| Red | Fails a high-weight question with no adequate mitigation | Reject or restrict to tier 1 |
A filled-in decision record (illustrative)
"Tool: [Workspace tool], paid plan. Purpose: matter records, deadlines, time and knowledge for a five-person firm. Data: tier 2; tier 3 matters stored outside, referenced by link; tier 4 excluded. Evidence: SOC 2 Type 2 and ISO 27001 summaries reviewed; subprocessor list and data processing agreement on file. Configuration: MFA required; public sharing disabled; restricted area for sensitive matters; AI scoped to wiki only. Gaps: no audit log on this plan (mitigated by monthly access review); retention at AI providers up to 30 days (mitigated by excluding tier 3 from AI). Owner: managing partner; backup: office manager. Decision: approved with conditions, [date]. Next review: [date]."
Common mistakes
- Accepting marketing claims in place of documents.
- Doing due diligence once and never refreshing it.
- Not testing export until you need to leave.
- Forgetting the integrations and automations that connect the tool to others.
- Applying the full checklist to everything, then abandoning it. Scale it to risk.
Keep the result in a vendor register in your workspace (see Notion for paralegals and legal ops). Then read the legal tech stack by job, what compliance labels mean and what regulators actually require.
Frequently asked questions
What should a law firm check before using a cloud tool?
Security controls (certifications, MFA, encryption, access controls, audit logs), data handling (location, retention, deletion, subprocessors, use for training), the contract (data processing agreement, breach notification, liability), continuity (export, backups, exit) and governance (admin controls, support). Record the decision.
How do I record a vendor decision?
In a short note in a vendor register: the tool, what data it holds, who owns it, the answers to the checklist, any gaps and how you addressed them, the decision and the date, plus a review date.
Is a security certification enough?
No. Certifications show a vendor runs a security programme. They do not show that your configuration is safe or that the contract protects you, so use them as one input among several.
What contract clauses matter most?
Data ownership and use, a data processing agreement, breach notification timing, subprocessor change notice, data return and deletion on exit, liability and indemnity limits, governing law and forum, price-change notice, and any clause allowing use of your data for the vendor's own purposes, including AI training.
How do I test a vendor claim myself?
Try it. Enable and enforce MFA; share a page and revoke access; export your data and open the export; restore from a backup; read the audit log; ask support a real question and time the answer. A claim you have tested is worth more than one you have read.
How often should I repeat due diligence?
Yearly for critical tools, and whenever the vendor changes its terms, ownership or features, you start using it for new data, or a client or regulator imposes requirements.
What if a vendor will not answer my questions?
That is itself an answer. For a tool holding client data, a vendor that will not describe its security, provide an agreement or explain data handling is a red flag; choose another, or restrict what you put in.
Do I need a questionnaire for every tool?
Scale the effort to the risk. A tool that holds client data deserves the full checklist; a tool that holds nothing sensitive needs a lighter check. Tier your tools the same way you tier your data.
Related guides
- Can lawyers use Notion for client data? Confidentiality, ethics and a safe setup
- Is Notion HIPAA, SOC 2 and GDPR compliant? What it means for a law firm
- Is Notion secure enough for attorney-client privilege? How privilege is lost, and how to avoid it
- Do lawyers need bar-approved software? What regulators actually require