Guide

Cloud vendor due diligence for law firms: a 24-question checklist you can reuse

Cloud vendor due diligence for law firms: a reusable 24-question checklist on security, data, contract, continuity and governance, with a decision record.

By , practising lawyer17 min read

TL;DR

  • Ask the same 24 questions of every vendor in five areas: security, data handling, contract, continuity and governance.
  • Get answers from the vendor's own documents (security page, trust centre, agreement), not from marketing, and test what you can yourself.
  • Score each, note the gaps, decide to accept, mitigate or reject, and write a one-paragraph dated decision.
  • Re-run it yearly and whenever the vendor changes its terms or you change how you use it.
Free downloadLawyerOS — Matters, Clients, Billing & AIGet it

Before any cloud tool touches client data, ask it the same 24 questions, in five areas: security, data handling, contract, continuity and governance. Take the answers from the vendor's own documents, test what you can yourself, score them, note the gaps and write a dated decision. That record is what shows a regulator, an insurer or a client that your choice was reasoned. This is a practical checklist, not legal advice; it gives you the questions, where to find each answer, how to judge it, and a decision template.

Scale the effort to the risk

Tool holdsEffort
Tier 1: nothing sensitive (templates, public material)A quick look: terms, MFA, export
Tier 2: ordinary client informationThe full checklist
Tier 3: sensitive or privileged informationThe full checklist, plus legal review of the agreement and a client-consent decision
Tier 4 dataDo not use a general tool at all

The checklist

#QuestionA good answer looks likeWhere to find or how to test
SECURITY
1Independent audit or certification (such as SOC 2 or ISO 27001)?Current report or certificate, on the plan you will useTrust centre; read scope and period
2Multi-factor authentication available and enforceable?Yes, with an admin setting to require itAdmin settings; enable it and try to log in without it
3Encryption in transit and at rest?Yes, stated in documentationSecurity overview
4Role-based access and page-level permissions?Yes, with granular controlCreate a test user and test restrictions
5Audit log of access and changes?Yes, on your plan, with stated retentionAdmin area; check what it records
6Single sign-on and automated user provisioning?Available if you need themPlan comparison
DATA HANDLING
7Where is data stored?Stated regions, with any residency optionSecurity overview; DPA
8Who are the subprocessors?A published list with change noticeLegal or trust pages
9Is customer data used to train AI models?No, by contract, including subprocessorsAI security statement; terms
10How long is data retained after deletion?A stated, short periodPrivacy policy; DPA
11What AI features exist, and what can they access?Documented, with admin controlsAI documentation; admin settings
CONTRACT
12Data processing agreement available?Yes, signed or accepted by defaultLegal pages
13Business associate agreement if you handle health data?Available on a stated planSecurity or compliance page; sales
14Breach notification commitment?Prompt notice with stated timingDPA; terms
15Liability and indemnity terms?Read them; know what you are acceptingTerms of service
16Governing law and dispute forum?Acceptable to you and your insurerTerms of service
CONTINUITY
17Can you export everything, in usable formats?Yes, tested by youExport a sample and open it
18Backups and recovery?Stated, with a recovery processSecurity overview; ask support
19Service-level and uptime record?Published status page and historyStatus page
20Exit: what happens to data when you leave?Deletion on request, with confirmationTerms; ask support
GOVERNANCE
21Admin controls for sharing and guests?Can disable public sharing and review guestsAdmin settings; test
22Support available when something goes wrong?A route to a human, with stated responseAsk a real question and time it
23Does it change terms often, and is notice given?Notice of material changeTerms; change history
24Who in your firm owns it?A named person, with a review dateYour vendor register

Contract clauses to look for

ClauseWhat you wantRed flag
Data ownership and useYou own your data; vendor uses it only to provide the serviceA licence to use your data for the vendor's own purposes
Data processing agreementPresent, covering processing instructions, security, subprocessors, transfers and assistanceNone, or one that excludes your use
Breach notificationPrompt notice with a stated periodNo commitment
SubprocessorsA list and notice of change with a chance to objectSilent changes
Return and deletion on exitExport and deletion within a stated period, with confirmationNo deletion commitment
Liability capUnderstand it; ask what is excludedA cap that makes any claim worthless, with no cover for data breaches
Term and price changesNotice of increases; ability to leaveAuto-renewal with no notice
Governing law and forumAcceptable to you and your insurerA forum that makes any dispute impractical
AI and trainingNo training on your data; a stated retentionSilent rights to train

Tests you can run yourself in an hour

  1. MFA. Turn it on for a test user and confirm you cannot log in without it.
  2. Sharing. Share a page to a test guest, then revoke it; confirm access stops. Check whether a public link can be disabled.
  3. Permissions. Restrict a page and confirm a member who is not named cannot see it, including in search.
  4. Export. Export a sample workspace; open the files; check structure and attachments.
  5. Audit log. Perform an action; find it in the log.
  6. Support. Ask a real question and time the answer.
  7. Backup or restore. Restore a deleted item, or ask how.

Scoring and the decision

  1. Mark each question Meets, Partly or Does not meet, with the source.
  2. For each gap, decide: accept (document why), mitigate (a setting, a process, a narrower use), or reject the tool.
  3. Treat gaps on security, breach notice, data use and export as serious.
  4. Write a paragraph: what the tool is for, what data goes in, the gaps and how you addressed them, and the date.
  5. Set a review date within a year.
RatingMeaningAction
GreenMeets all high-weight questionsApprove
AmberGaps in some questions, with mitigationsApprove with conditions and a review date
RedFails a high-weight question with no adequate mitigationReject or restrict to tier 1

A filled-in decision record (illustrative)

"Tool: [Workspace tool], paid plan. Purpose: matter records, deadlines, time and knowledge for a five-person firm. Data: tier 2; tier 3 matters stored outside, referenced by link; tier 4 excluded. Evidence: SOC 2 Type 2 and ISO 27001 summaries reviewed; subprocessor list and data processing agreement on file. Configuration: MFA required; public sharing disabled; restricted area for sensitive matters; AI scoped to wiki only. Gaps: no audit log on this plan (mitigated by monthly access review); retention at AI providers up to 30 days (mitigated by excluding tier 3 from AI). Owner: managing partner; backup: office manager. Decision: approved with conditions, [date]. Next review: [date]."

Common mistakes

  • Accepting marketing claims in place of documents.
  • Doing due diligence once and never refreshing it.
  • Not testing export until you need to leave.
  • Forgetting the integrations and automations that connect the tool to others.
  • Applying the full checklist to everything, then abandoning it. Scale it to risk.

Keep the result in a vendor register in your workspace (see Notion for paralegals and legal ops). Then read the legal tech stack by job, what compliance labels mean and what regulators actually require.

Frequently asked questions

What should a law firm check before using a cloud tool?

Security controls (certifications, MFA, encryption, access controls, audit logs), data handling (location, retention, deletion, subprocessors, use for training), the contract (data processing agreement, breach notification, liability), continuity (export, backups, exit) and governance (admin controls, support). Record the decision.

How do I record a vendor decision?

In a short note in a vendor register: the tool, what data it holds, who owns it, the answers to the checklist, any gaps and how you addressed them, the decision and the date, plus a review date.

Is a security certification enough?

No. Certifications show a vendor runs a security programme. They do not show that your configuration is safe or that the contract protects you, so use them as one input among several.

What contract clauses matter most?

Data ownership and use, a data processing agreement, breach notification timing, subprocessor change notice, data return and deletion on exit, liability and indemnity limits, governing law and forum, price-change notice, and any clause allowing use of your data for the vendor's own purposes, including AI training.

How do I test a vendor claim myself?

Try it. Enable and enforce MFA; share a page and revoke access; export your data and open the export; restore from a backup; read the audit log; ask support a real question and time the answer. A claim you have tested is worth more than one you have read.

How often should I repeat due diligence?

Yearly for critical tools, and whenever the vendor changes its terms, ownership or features, you start using it for new data, or a client or regulator imposes requirements.

What if a vendor will not answer my questions?

That is itself an answer. For a tool holding client data, a vendor that will not describe its security, provide an agreement or explain data handling is a red flag; choose another, or restrict what you put in.

Do I need a questionnaire for every tool?

Scale the effort to the risk. A tool that holds client data deserves the full checklist; a tool that holds nothing sensitive needs a lighter check. Tier your tools the same way you tier your data.