Guide
Do lawyers need bar-approved software? What regulators actually require
Do lawyers need bar-approved software? Usually not: regulators set duties, not tool lists. What they ask and how to evidence a reasonable choice.
By Raghav R Handa, practising lawyer15 min read
TL;DR
- In most places no bar association maintains a list of approved practice software. Regulators set duties and leave the tool choice to you.
- What you must be able to show is a reasoned choice: you understood the tool, protected confidences, supervised it and kept the records required.
- A few regulators publish technology guidance or specific rules (especially for trust accounting and records); read yours, plus any insurer and client requirements.
- Write down your choice and why, in a one-page technology decision record. That note is your best evidence.
Generally no. Most bar associations and law societies do not approve, certify or ban practice-management software. They set duties (competence, confidentiality, supervision of anyone who handles client information, and proper records) and expect you to choose tools that let you meet them. A few regulators have specific rules, especially on trust accounting and record-keeping. This is a general explainer, not legal advice for any one jurisdiction; always read your own regulator's current guidance. The practical lesson: you are not looking for an approved list, you are building a record that shows a reasoned choice.
Three regulatory models
| Model | How it works | What you do |
|---|---|---|
| Duty-based (most common) | The rules set duties and outcomes; no tool is approved or banned | Choose, configure and supervise tools so you can meet the duties; document the reasoning |
| Guidance-based | The regulator publishes opinions or guidance on cloud, security and AI | Read it, follow it, and cite it in your decision record |
| Specific-rule | Particular rules on trust or client-account records, retention, e-filing or data location | Meet the rule exactly; choose tools that support it; test the outputs |
What regulators typically ask
| Duty | What it means for software |
|---|---|
| Competence | You understand the tool's benefits and risks well enough to use it responsibly, including how your data is handled |
| Confidentiality | Reasonable steps to keep client information from unauthorised access: access control, encryption, careful sharing |
| Supervision | Vendors and staff who handle client data are overseen appropriately; AI output is checked |
| Records | You can produce required records, including trust records, on request, in usable form |
| Continuity | You can recover and keep working if the tool fails, the vendor changes terms or you leave it |
| Communication | Clients are told what they need to know about how their information is handled |
Where to find the rules for your jurisdiction
| Where you practise | Start with |
|---|---|
| United States | Your state's rules of professional conduct and ethics opinions on cloud computing and AI; the ABA Model Rules and formal opinions as background |
| England and Wales | The SRA Standards and Regulations; Law Society guidance on technology and AI; ICO guidance |
| Canada | Your provincial law society's code and practice resources; the Federation's Model Code; PIPEDA or provincial privacy law |
| India | The Bar Council of India rules; State Bar Councils; the Digital Personal Data Protection Act, 2023 |
| Australia | Your state or territory regulator and law society practice guidance |
| New Zealand, Singapore, Ireland | The New Zealand Law Society, the Law Society of Singapore, the Law Society of Ireland and the privacy regulators; see our pages for each |
Many US bars have issued opinions on cloud computing, and the ABA publishes a survey of them. Search your regulator's site for "cloud", "technology", "artificial intelligence" and "confidentiality". See our pages for New Zealand, Singapore, Ireland, Canada, India, UK and US.
Insurers and clients: the second and third rulebooks
- Your insurer. Professional indemnity or malpractice insurers ask about controls (MFA, backups, deadline and conflict systems) at proposal and renewal. Answer truthfully, keep the evidence, and read policy conditions.
- Your clients. Banks, insurers, public bodies and large corporates often send outside-counsel guidelines covering data location, approved tools, security standards and AI. They are contractual, and they can be stricter than the regulator. Record them on the matter.
A technology decision record (one page)
The single most useful artefact. Keep one per significant tool, in your vendor register.
| Field | What to write |
|---|---|
| Tool and version or plan | For example, the product, the plan and the date you chose it |
| Purpose | What it is used for in the firm |
| Data in scope | Tier of data it holds; categories excluded |
| Duties considered | Competence, confidentiality, supervision, records, continuity, with a line each |
| Evidence reviewed | Security statement, certifications, agreements, subprocessor list, with dates |
| Configuration | MFA, permissions, sharing, AI and connection settings |
| Gaps and mitigations | What did not meet your standard and what you did about it |
| Client and insurer requirements | Any that apply, and how you meet them |
| Owner and backup owner | Named people |
| Exit plan | How you export and leave |
| Decision and date | Approved, approved with conditions, rejected |
| Next review | A date within a year |
A decision matrix for comparing tools
| Criterion | Tool A | Tool B | Weight |
|---|---|---|---|
| Security controls (MFA, encryption, access) | Score 0 to 3 | Score 0 to 3 | High |
| Data handling and location | High | ||
| Agreement terms (DPA, BAA, breach notice) | High | ||
| Export and exit | High | ||
| Fit for your workflow | Medium | ||
| Cost, including add-ons | Medium | ||
| Support | Medium |
Red flags
- The vendor will not describe its security or provide an agreement.
- No multi-factor authentication or granular permissions.
- Unclear data location or no way to learn it.
- No export, or an export that loses structure.
- No commitment to notify you of a breach.
- Terms that let the vendor change how it uses your data without notice.
- No named contact, no status page, no incident history.
What to do this week
- List your tools and the data each holds.
- Find your regulator's guidance on technology and AI and read it.
- Read your insurer's requirements and any client guidelines.
- Write a decision record for your three most important tools.
- Calendar a yearly review.
Next: can lawyers use Notion for client data?, HIPAA, SOC 2 and GDPR, the vendor due diligence checklist and the security pillar.
Frequently asked questions
Do I need bar-approved software to practise?
Generally no. Most regulators do not approve or maintain lists of practice-management or cloud tools. They impose duties of competence, confidentiality, supervision and record-keeping, and expect you to choose tools that let you meet them. A few have specific rules, notably for trust accounting and records, so check your own regulator.
How do I show I made a reasonable software choice?
Keep a short record: what the tool is for, what data goes in, the security measures you checked (certifications, access controls, encryption, backups, exit), the agreement you accepted, who is responsible and the date. Review it yearly. That demonstrates a reasoned decision if you are ever asked.
Where do I find my regulator's technology guidance?
On your bar association or law society website, usually under practice management, ethics opinions, risk management or technology guidance. Many publish opinions on cloud computing and, increasingly, on artificial intelligence. Your professional indemnity or malpractice insurer may also publish requirements.
Does my insurer care what software I use?
Often, yes. Insurers may ask about security controls, multi-factor authentication, backups and how you manage deadlines and conflicts, and some set conditions. Read your policy and renewal questions, since their requirements can be stricter than the regulator's.
Can a client dictate which software I use?
Clients, particularly banks, insurers and government bodies, often impose outside-counsel guidelines covering data location, approved tools, security standards and AI use. Those are contractual and can be stricter than the rules of your regulator, so read them at the start of each engagement.
Are there any software requirements that are mandatory?
Some jurisdictions have specific requirements for trust or client account records, retention and producibility, and some require certain filings to be made through specific systems such as a court's e-filing portal. These are about records and processes, not endorsed brands.
What are red flags when choosing legal software?
A vendor that will not state its security practices or provide an agreement, no export route, no breach notification commitment, no multi-factor authentication, unclear data location, and terms that let it change how it uses your data without notice.
How often should I revisit my software decisions?
At least yearly, and whenever a vendor changes its terms or features, you add a new type of data or use (such as AI), a client imposes requirements, or your regulator issues new guidance.
Related guides
- Can lawyers use Notion for client data? Confidentiality, ethics and a safe setup
- Is Notion HIPAA, SOC 2 and GDPR compliant? What it means for a law firm
- Is Notion secure enough for attorney-client privilege? How privilege is lost, and how to avoid it
- The ABA Model Rules applied to cloud tools and AI: what each rule asks of a lawyer