Guide

Do lawyers need bar-approved software? What regulators actually require

Do lawyers need bar-approved software? Usually not: regulators set duties, not tool lists. What they ask and how to evidence a reasonable choice.

By , practising lawyer15 min read

TL;DR

  • In most places no bar association maintains a list of approved practice software. Regulators set duties and leave the tool choice to you.
  • What you must be able to show is a reasoned choice: you understood the tool, protected confidences, supervised it and kept the records required.
  • A few regulators publish technology guidance or specific rules (especially for trust accounting and records); read yours, plus any insurer and client requirements.
  • Write down your choice and why, in a one-page technology decision record. That note is your best evidence.
Free downloadLawyerOS — Matters, Clients, Billing & AIGet it

Generally no. Most bar associations and law societies do not approve, certify or ban practice-management software. They set duties (competence, confidentiality, supervision of anyone who handles client information, and proper records) and expect you to choose tools that let you meet them. A few regulators have specific rules, especially on trust accounting and record-keeping. This is a general explainer, not legal advice for any one jurisdiction; always read your own regulator's current guidance. The practical lesson: you are not looking for an approved list, you are building a record that shows a reasoned choice.

Three regulatory models

ModelHow it worksWhat you do
Duty-based (most common)The rules set duties and outcomes; no tool is approved or bannedChoose, configure and supervise tools so you can meet the duties; document the reasoning
Guidance-basedThe regulator publishes opinions or guidance on cloud, security and AIRead it, follow it, and cite it in your decision record
Specific-ruleParticular rules on trust or client-account records, retention, e-filing or data locationMeet the rule exactly; choose tools that support it; test the outputs

What regulators typically ask

DutyWhat it means for software
CompetenceYou understand the tool's benefits and risks well enough to use it responsibly, including how your data is handled
ConfidentialityReasonable steps to keep client information from unauthorised access: access control, encryption, careful sharing
SupervisionVendors and staff who handle client data are overseen appropriately; AI output is checked
RecordsYou can produce required records, including trust records, on request, in usable form
ContinuityYou can recover and keep working if the tool fails, the vendor changes terms or you leave it
CommunicationClients are told what they need to know about how their information is handled

Where to find the rules for your jurisdiction

Where you practiseStart with
United StatesYour state's rules of professional conduct and ethics opinions on cloud computing and AI; the ABA Model Rules and formal opinions as background
England and WalesThe SRA Standards and Regulations; Law Society guidance on technology and AI; ICO guidance
CanadaYour provincial law society's code and practice resources; the Federation's Model Code; PIPEDA or provincial privacy law
IndiaThe Bar Council of India rules; State Bar Councils; the Digital Personal Data Protection Act, 2023
AustraliaYour state or territory regulator and law society practice guidance
New Zealand, Singapore, IrelandThe New Zealand Law Society, the Law Society of Singapore, the Law Society of Ireland and the privacy regulators; see our pages for each

Many US bars have issued opinions on cloud computing, and the ABA publishes a survey of them. Search your regulator's site for "cloud", "technology", "artificial intelligence" and "confidentiality". See our pages for New Zealand, Singapore, Ireland, Canada, India, UK and US.

Insurers and clients: the second and third rulebooks

  • Your insurer. Professional indemnity or malpractice insurers ask about controls (MFA, backups, deadline and conflict systems) at proposal and renewal. Answer truthfully, keep the evidence, and read policy conditions.
  • Your clients. Banks, insurers, public bodies and large corporates often send outside-counsel guidelines covering data location, approved tools, security standards and AI. They are contractual, and they can be stricter than the regulator. Record them on the matter.

A technology decision record (one page)

The single most useful artefact. Keep one per significant tool, in your vendor register.

FieldWhat to write
Tool and version or planFor example, the product, the plan and the date you chose it
PurposeWhat it is used for in the firm
Data in scopeTier of data it holds; categories excluded
Duties consideredCompetence, confidentiality, supervision, records, continuity, with a line each
Evidence reviewedSecurity statement, certifications, agreements, subprocessor list, with dates
ConfigurationMFA, permissions, sharing, AI and connection settings
Gaps and mitigationsWhat did not meet your standard and what you did about it
Client and insurer requirementsAny that apply, and how you meet them
Owner and backup ownerNamed people
Exit planHow you export and leave
Decision and dateApproved, approved with conditions, rejected
Next reviewA date within a year

A decision matrix for comparing tools

CriterionTool ATool BWeight
Security controls (MFA, encryption, access)Score 0 to 3Score 0 to 3High
Data handling and locationHigh
Agreement terms (DPA, BAA, breach notice)High
Export and exitHigh
Fit for your workflowMedium
Cost, including add-onsMedium
SupportMedium

Red flags

  • The vendor will not describe its security or provide an agreement.
  • No multi-factor authentication or granular permissions.
  • Unclear data location or no way to learn it.
  • No export, or an export that loses structure.
  • No commitment to notify you of a breach.
  • Terms that let the vendor change how it uses your data without notice.
  • No named contact, no status page, no incident history.

What to do this week

  1. List your tools and the data each holds.
  2. Find your regulator's guidance on technology and AI and read it.
  3. Read your insurer's requirements and any client guidelines.
  4. Write a decision record for your three most important tools.
  5. Calendar a yearly review.

Next: can lawyers use Notion for client data?, HIPAA, SOC 2 and GDPR, the vendor due diligence checklist and the security pillar.

Frequently asked questions

Do I need bar-approved software to practise?

Generally no. Most regulators do not approve or maintain lists of practice-management or cloud tools. They impose duties of competence, confidentiality, supervision and record-keeping, and expect you to choose tools that let you meet them. A few have specific rules, notably for trust accounting and records, so check your own regulator.

How do I show I made a reasonable software choice?

Keep a short record: what the tool is for, what data goes in, the security measures you checked (certifications, access controls, encryption, backups, exit), the agreement you accepted, who is responsible and the date. Review it yearly. That demonstrates a reasoned decision if you are ever asked.

Where do I find my regulator's technology guidance?

On your bar association or law society website, usually under practice management, ethics opinions, risk management or technology guidance. Many publish opinions on cloud computing and, increasingly, on artificial intelligence. Your professional indemnity or malpractice insurer may also publish requirements.

Does my insurer care what software I use?

Often, yes. Insurers may ask about security controls, multi-factor authentication, backups and how you manage deadlines and conflicts, and some set conditions. Read your policy and renewal questions, since their requirements can be stricter than the regulator's.

Can a client dictate which software I use?

Clients, particularly banks, insurers and government bodies, often impose outside-counsel guidelines covering data location, approved tools, security standards and AI use. Those are contractual and can be stricter than the rules of your regulator, so read them at the start of each engagement.

Are there any software requirements that are mandatory?

Some jurisdictions have specific requirements for trust or client account records, retention and producibility, and some require certain filings to be made through specific systems such as a court's e-filing portal. These are about records and processes, not endorsed brands.

What are red flags when choosing legal software?

A vendor that will not state its security practices or provide an agreement, no export route, no breach notification commitment, no multi-factor authentication, unclear data location, and terms that let it change how it uses your data without notice.

How often should I revisit my software decisions?

At least yearly, and whenever a vendor changes its terms or features, you add a new type of data or use (such as AI), a client imposes requirements, or your regulator issues new guidance.