Technology Competence for Lawyers: A Practical Annual Checkup
A once-a-year review of the technology risks that affect real legal work, from client communication and filing to AI, vendors, security, and recovery.
Technology competence does not mean a lawyer must become the firm’s system administrator. It means knowing enough about the tools used in a representation to recognize material benefits and risks, ask sensible questions, and arrange qualified help when needed.
Comment 8 to ABA Model Rule 1.1 includes the benefits and risks of relevant technology among the changes in law and practice lawyers should keep abreast of. Jurisdictions implement professional rules differently, so the firm’s review should begin with the rules, opinions, and court requirements that actually apply.
An annual checkup makes the duty manageable. Put it on the calendar, include the people who know the daily work, and keep a short record of decisions.
1. How do clients send and receive sensitive information?
List email, portals, shared links, text messages, video meetings, electronic signatures, and any consumer file-transfer tools that have entered the workflow.
Check whether the method fits the sensitivity of the matter. Confirm recipient addresses before sending, set sensible link expiration and access controls, and give clients a clear way to verify unusual requests. Decide when ordinary email is acceptable and when stronger safeguards are needed.
2. Who can enter the firm’s systems?
Review active users, administrators, temporary accounts, former staff, vendors, and shared credentials. Require MFA, preferably phishing-resistant methods, for important accounts. Make sure recovery methods do not quietly bypass the stronger login.
Check laptops and phones for encryption, supported software, screen locking, secure disposal, and the ability to remove firm data after loss or departure.
3. Can the firm meet deadlines during an outage?
Do not limit this question to whether a backup job ran. Restore a sample of matter files, calendars, email, practice data, and financial reports. Record how long it took and what failed.
Maintain an alternate way to reach the calendar, essential contacts, courts, staff, and clients when the main provider or office connection is unavailable.
4. What changed in the firm’s vendors?
Review current terms, security materials, subprocessors, data locations, breach-notification commitments, integrations, export methods, and pricing. Ask who holds encryption keys and who can access client content.
Run a sample export before the firm needs one. A vendor relationship is easier to supervise when the firm understands both entry and exit.
5. Where is AI already being used?
Ask without accusation. Lawyers and staff may be using AI in research tools, office software, transcription, email, document review, or personal chatbot accounts without thinking of each feature as a separate system.
For each use, identify the information supplied, provider terms, task, failure consequences, required review, client instructions, court rules, and fee treatment. Replace vague approval with a short list of approved tools and uses. Give people a quick path to request another one.
6. Are legal sources and electronic evidence handled properly?
Review how lawyers validate online authority, preserve web material, collect messages and collaborative documents, manage metadata, and produce electronically stored information. The relevant skill depends on the practice. A litigator’s discovery risks differ from a real-estate lawyer’s signing and wire risks.
Identify the matters where outside technical help may be needed. Competence includes knowing when not to improvise.
7. Are money and identity changes independently verified?
Test the procedure for new wire instructions, payment-account changes, password resets, and requests from senior lawyers. Require a call using a known number and, for consequential actions, a second approver.
Review one completed transaction to see whether the procedure exists in records as well as policy.
8. Do staff know what to report?
Training should cover the incidents people might actually encounter: a suspicious sign-in, unexpected MFA prompt, misdirected email, lost device, fraudulent payment request, unusual AI output, or accidentally shared file.
Make reporting easy and blame-free. Early notice often matters more than perfect diagnosis by the first person who sees the problem.
Finish with owners and dates
A checkup that produces only observations will be repeated next year. For each gap, name an owner, a due date, and the evidence that will show it is fixed. Examples include a restored file set, an updated user list, a signed vendor answer, or a completed payment-verification test.
Keep the scope proportionate to the practice, but do not confuse a small firm with a low-risk one. A solo lawyer may hold immigration records, health information, trade secrets, criminal-defense files, or client funds with little administrative backup.
The purpose of the review is not to collect technology for its own sake. It is to make sure that the firm’s ordinary tools still support competent, confidential, and dependable legal work.
Primary references
This article offers general information, not legal or ethics advice. Check the rules and opinions that apply in your jurisdiction.
This article is general information for legal professionals, not legal advice or an ethics opinion. Rules of professional conduct vary by jurisdiction—consult yours.