Outside Counsel Guidelines: When Your Client Writes Your Security Policy

George
By George
28 August 2026
Client document driving eight security controls

The first sign is usually a PDF attached to a new matter. A corporate client, an insurance carrier, or a bank sends its outside counsel guidelines, and somewhere after the billing rules and the staffing rules is a section on information security that reads like a contract, because it is one. The firm is now expected to encrypt specific data, enforce multi-factor authentication, report a suspected breach within a set number of hours, destroy files on request, and prove all of it when asked.

Most small and mid-sized firms sign these terms and hope they are in compliance, which works until a client checks. This guide explains what the security sections of outside counsel guidelines typically require, where those requirements come from, how they differ from a security questionnaire, what to do when a clause asks for something the firm does not have, and how to produce the evidence a client will eventually request. It is written for managing partners and firm administrators, and it reflects the work GlobeVM does delivering IT and cybersecurity for law firms across Los Angeles.

What Outside Counsel Guidelines Are, and Why They Now Read Like a Security Contract

Outside counsel guidelines are a client's written rules for the law firms it hires. They traditionally cover billing format, rate approval, staffing, conflicts, reporting, and communication, and over the past decade they have grown a fourth leg: specific, auditable requirements for how the firm protects the client's confidential information. The security section is often longer than the billing section now, and it is the part most firms read least carefully.

The shift has a clear cause. Corporate legal departments sit inside companies that run vendor risk programs, answer to regulators, and carry cyber insurance, and all three of those forces treat a law firm as a third party holding sensitive data. A firm that stores a client's deal documents, litigation files, or employee records is, from the company's point of view, no different from any other vendor, and it gets the same contract language.

The Template Most Guidelines Copy

Much of that language traces to one document. In March 2017 the Association of Corporate Counsel published its Model Information Protection and Security Controls for Outside Counsel Possessing Company Confidential Information, a set of thirteen control areas written in contract style so legal departments could drop them into their own guidelines. The areas cover written security policies, data retention and destruction, encryption and breach reporting, physical security, logical access controls, monitoring, vulnerability management, system and network security, the client's right to review the firm's systems, industry certification, background screening, cyber liability insurance, and subcontractors.

Nearly a decade later the Model Controls still shape what firms receive, and the ACC followed them in December 2020 with a Data Steward Program for assessing and accrediting firms against a standardized framework. When a guideline arrives with a 24 hour breach clause or a 30 day destruction clause, those numbers are usually inherited from the ACC document rather than invented by the client.

Guidelines Are Part of the Engagement, Not a Courtesy

Guidelines are typically incorporated into the engagement by reference, which means accepting the matter accepts the terms, and updated versions often arrive annually with a request to acknowledge them. They sit on top of the ethics floor rather than replacing it. California lawyers already owe clients a duty to preserve confidences under Business and Professions Code section 6068(e)(1) and Rule 1.6, and the State Bar's Formal Opinion 2020-203 says that duty includes assessing the risks to electronically stored client information, taking reasonable steps to secure it, monitoring for breaches, and notifying affected clients as soon as reasonably possible.

What the guidelines add is specificity and contractual force. The ethics rules ask for reasonable efforts; the guideline says which efforts, by when, with what proof. A firm that acknowledges terms it cannot meet has created a contract problem and a candor problem at the same time, and the second one is the more dangerous of the two.

Who Sends Them

Corporate legal departments are the obvious source, but they are not the only one. Insurance carriers issue litigation management guidelines to their panel defense firms, and those documents now carry data security sections of their own. Banks, healthcare organizations, public agencies, and technology companies all have versions, and a five lawyer firm with a single corporate client or a single carrier relationship is as bound by the document as a national firm.

The Security Requirements That Show Up Most Often

The table below collects the clauses a small or mid-sized firm is most likely to encounter, what they typically say, and what meeting them involves. Individual guidelines vary, and the exact wording in a firm's own documents controls, but the pattern is consistent enough that a firm can prepare for it before the next PDF arrives.

Identity, Access, and Devices

Accounts and Permissions

The 2017 Model Controls asked for two-factor authentication on remote access, which was ambitious then and is minimal now. Guidelines written in the last few years expect MFA on email, the document management system, practice management, and any cloud service that holds client data, with no exception for senior partners. They also expect least privilege, meaning each person reaches only what their role requires, and a reliable process for removing access the day someone leaves, which is exactly the ground covered by identity and access management done properly.

Laptops, Phones, and Home Offices

Devices draw their own clauses. Laptops and phones that hold or access client data are expected to be encrypted, locked, remotely wipeable, and kept current, and guidelines increasingly extend that to home offices. California's Formal Opinion 2023-208 on working from home makes the same point from the ethics side, so a firm that meets the guideline usually satisfies the bar at the same time.

Encryption and Secure Transfer

The Model Controls recommend encrypting client data wherever it rests, including backups and any third party's servers, using solutions certified against the federal FIPS 140-2 standard with encryption keys stored separately from the data. They also call for encryption in transit and on portable media. In practice that means full-disk encryption on every computer, cloud storage that encrypts by default, backups that are encrypted before they leave the building, and an end to sending client documents as ordinary email attachments.

That last point is where most guidelines and most firms collide. A guideline that requires encrypted transfer is really requiring a client portal, a document system with controlled external sharing, or an encrypted email option that is used every time rather than when someone remembers. Our guide to secure file sharing for law firms covers what a defensible setup looks like, and the same setup is what an auditor will look for.

Clauses mapped to controls and evidence

Breach Notification Windows and Incident Response

The clause that causes the most anxiety is the breach clock. The Model Controls call for notice to the client within 24 hours of discovering an actual or suspected event, and guidelines in circulation today commonly sit between 24 and 72 hours. The word suspected matters, because it means the clock starts before the firm knows what happened, and the clause asks for notice of an event, not a completed investigation.

Two things make that clause workable. The first is detection, because a firm cannot report within 24 hours an intrusion it discovers in three weeks, so the clause is, in effect, a requirement to have monitoring in place. The second is a written incident response plan that names who decides an event is reportable, who contacts the client, and who handles the parallel obligations: the ethics duty to investigate and notify affected clients described in ABA Formal Opinion 483 and California's Formal Opinion 2020-203, and, when personal information is involved, the notification duties under California's breach statute. The guideline adds a contractual deadline to obligations the firm already has.

Blocked and approved paths for AI

Retention, Return, and Destruction at the End of a Matter

Clients increasingly want their data gone when the matter ends. The Model Controls say a firm should keep client information only as long as needed for the purpose it was provided, return or destroy it on request, commonly within 30 days, and certify in writing that it has done so. The same document carves out sensible exceptions: routine email exchanges, attorney work product, information the firm must keep under legal or ethical obligations, copies held for disaster recovery, and latent data that would take forensic tools to reach.

The operational problem is that client data lives in more places than the matter folder. It is in email, in backups with their own retention schedules, on the laptops of people who worked the file, and in any vendor the firm used. A destruction clause is really a request for a matter-closing workflow that knows all of those places, and it has to coexist with the firm's own file retention policy and with any legal hold, which is why the exceptions language matters and why a certificate should say exactly what was and was not destroyed.

Vendors, Cloud, and Flow-Down

The subcontractor clause makes the firm responsible for everyone it lets near the client's data and requires a written agreement that imposes the same controls on them. The 2017 document named e-discovery providers, cloud storage, copy vendors, and offsite storage as examples. In 2026 the list also includes the cloud document management system, practice management software, transcription and AI tools, and the firm's IT provider itself.

That last item deserves a plain statement. Under most guideline definitions, a managed IT provider that administers the firm's systems is a subcontractor with access to client data, so the firm should expect its provider to accept flow-down terms in writing and to produce evidence on request. A provider that cannot do either is a compliance gap the client will eventually find.

Training, Screening, Testing, and Insurance

The remaining clauses are less technical and more administrative, which is why they are skipped. Guidelines expect annual security training for everyone with access to client data, background screening of employees and contractors with an annual certification to the client, regular vulnerability scanning, and annual penetration testing. The Model Controls recommended cyber liability coverage with a minimum of ten million dollars; practitioners at the time reported that the highest minimum they had seen from an actual client was five million, and the figures in a firm's own guidelines vary widely, so the number to satisfy is the one in the document in front of you.

Insurance and guidelines reinforce each other. Carriers now condition coverage on the same controls clients require, including MFA, endpoint protection, tested backups, and an incident plan, so a firm that closes its guideline gaps usually improves its renewal at the same time.

The Newest Clause: Generative AI

Guidelines revised since 2024 increasingly address generative AI directly. The common terms prohibit entering client information into public AI tools, require the client's consent or at least disclosure before AI is used on its matters, and ask the firm to review vendor terms for how prompts and documents are stored and used for training. Whether a firm can use AI without risking privilege is a question we have covered in depth, and the guideline version of the question is simpler: a written AI policy, technical controls that block unapproved tools, and a record of which approved tools touched the matter. Our guide on AI and privilege inside law firms covers the underlying analysis.

Outside Counsel Guidelines Versus Security Questionnaires

Firms often treat the two as the same exercise, and they are not. A questionnaire is an assessment: a client asks how the firm does things, the firm answers, and the answers become representations. A guideline is an obligation: the firm agrees to do things, continuously, for as long as the engagement lasts. The table below draws the line.

The two documents also feed each other. The answers given on a questionnaire should match what the guidelines require and what the firm does, and the easiest way to keep them aligned is to answer every questionnaire from the same evidence library the guidelines demand. Our guide to responding to security questionnaires covers the answering side; this article is about the obligations that remain after the form is submitted.

What to Do When a Guideline Asks for Something You Do Not Have

Every firm that reads its guidelines closely finds gaps. The Model Controls themselves acknowledge that some measures may be too burdensome in a given situation, and the document was written as a baseline legal departments might consider rather than a universal standard. The way a firm handles a gap matters more than the gap itself.

Read for the Control, Not the Label

Some clauses name a specific technology or certification when what the client needs is an outcome. A guideline that mentions layered network architecture from 2017 is asking for segmentation and intrusion detection, which modern tools deliver differently. ISO 27001 certification is described in the Model Controls as recommended but optional, and a client's security team will usually accept a documented program with equivalent controls when the firm explains it. Reading past the label finds the requirement the firm can satisfy.

Negotiate, Document, or Fix, but Never Pretend

A gap has three legitimate resolutions: negotiate the clause, document an exception with the compensating control the firm has in place, or fix it on a stated timeline. All three involve telling the client. Clients with mature vendor programs handle exceptions routinely and would far rather receive a clear explanation than discover an unmet clause during an audit or, worse, during an incident, when the unmet clause becomes the story.

Silence is the one choice that fails every time. A firm that acknowledges guidelines it has not read, or answers a questionnaire with the controls it intends to have, is betting that nobody checks, and the firms that lose that bet do not usually get the client back.

Let the Most Restrictive Client Set the Baseline

A firm with ten institutional clients does not need ten security programs. It needs one program that meets the strictest requirement in each category, plus a record of which client imposed it. The practical tool is an obligations register: one line per clause, with the client, the control that satisfies it, the person who owns it, the evidence that proves it, and the date it was last reviewed. Building and maintaining that register is the center of the compliance and risk management work a firm does with its IT provider, because the technical half of every line lives in systems the provider runs.

The register also answers the question clients ask most during a review, which is not whether the firm has a control but whether it can show the control was in place on a specific date. A dated register with attached evidence turns that question into a lookup rather than a scramble.

The Evidence a Firm Should Be Able to Produce

Audit and review rights are rarely exercised in full, but clients do ask for documents, and a firm's ability to produce them quickly is itself evidence of a working program. The items below are what a guideline-driven review typically requests, and most of them are generated by the firm's IT tooling rather than written by hand.

  • The written information security policy set, with the date of its last annual review
  • An MFA enforcement report covering every user and every system that holds client data
  • A device encryption status report for laptops, desktops, and phones
  • Patching and vulnerability scan summaries, plus the most recent penetration test letter
  • Training completion records and the phishing simulation results behind them
  • The background screening certification the guideline requires
  • The incident response plan and the date of its last tabletop exercise
  • Backup and restore test results showing recovery was proven, not assumed
  • The vendor inventory with flow-down agreements and SOC 2 reports for cloud services
  • Destruction certificates for closed matters and the matter-closing procedure behind them
  • A current certificate of cyber liability insurance
  • Offboarding and access review records for the past year

A firm does not need all of this in a single binder on day one. It needs to know which items exist, which are missing, and who produces each, and then to close the missing ones in an order that matches the clauses the firm's own clients emphasize.

One binder answering six client questionnaires

Who Owns Guideline Compliance Inside the Firm

Guidelines fail in small firms for a structural reason: they arrive addressed to the partner who handles the client, the security clauses belong to IT, and nobody owns the middle. The split below is a workable default for a firm without a general counsel or a security officer, and the point is less the exact allocation than the fact that every row has a name.

The IT provider's column is larger than many firms expect, which is the reason to confirm a provider can play it before guidelines arrive rather than after. Firms that rely on managed IT across Los Angeles should ask their provider directly whether it has signed client flow-down terms before and what evidence it can generate on request.

A Working Sequence for a Small Firm

Meeting guidelines is a project the first time and a routine afterward. The sequence below is how a firm with a few institutional clients can get from a drawer of unread PDFs to a program it can defend, without stopping billable work to do it.

  1. Collect every set of guidelines, litigation management guidelines, and engagement letter with security terms, including the versions clients have updated since the original engagement.
  2. Extract every security obligation into the register, one clause per line, noting the client and the deadline or frequency attached to it.
  3. Map each line to the control the firm has today, and mark the ones with nothing behind them.
  4. Close the gaps in priority order: MFA and encryption first, then backups and the incident plan, then training, vendor agreements, and the matter-closing workflow.
  5. Build the evidence library so each register line points to a document or report.
  6. Write to clients about any clause the firm is handling through an exception or a timeline, before they ask.
  7. Review the register annually and whenever a client issues revised guidelines, and keep the dates.

None of this requires a large firm's budget. It requires someone to own the register, an IT provider that treats the technical lines as its deliverables, and a habit of reading the security section before acknowledging it. Firms working with IT support in Westlake Village and across the Conejo Valley and the Valley can fold the annual register review into the same cycle as their security awareness training and insurance renewal.

Frequently Asked Questions

In most engagements, yes. Guidelines are typically incorporated into the engagement terms, so accepting the matter accepts them, and a clause the firm does not meet is a contract issue as well as a client relations issue. The firm's own counsel should confirm how a specific client's documents are structured, but the safe assumption is that every security clause is enforceable.
Multi-factor authentication, encryption of client data at rest and in transit, access on a need-to-know basis, breach notification within a set window, a written incident response plan, annual training, vulnerability management and penetration testing, written agreements with subcontractors, return or destruction of client data at the end of a matter, audit rights, minimum cyber insurance, and, increasingly, restrictions on generative AI. Most of these trace to the Association of Corporate Counsel's 2017 Model Controls.
The ACC Model Controls call for notice within 24 hours of discovering an actual or suspected event, and guidelines in use today commonly require 24 to 72 hours. The clause asks for notice of an event, not a finished investigation, which means the real requirement is monitoring that can detect an intrusion and a plan that names who calls the client. The firm's separate ethical and statutory notification duties continue to run on their own timelines.
Yes. Clients send the same document regardless of firm size, and a solo or small firm holding a corporate client's data is bound by it in the same way. What changes is how the firm meets it: small firms often satisfy clauses with cloud services and a managed IT provider rather than in-house staff, and they should document compensating controls and exceptions where a clause written for a large firm does not fit.
A questionnaire assesses what the firm does today, and its answers become representations the client relies on. Guidelines obligate the firm to maintain specific controls for the life of the engagement and usually give the client the right to audit and request certification. The two should be answered from the same evidence so the firm never represents a control it is not operating.

The Firm That Can Show Its Work Keeps the Client

Outside counsel guidelines are not going to get shorter, and the security sections are not going to get softer. They are also less mysterious than they look: most clauses trace to a single 2017 template, most controls are ordinary security practice a firm should have anyway, and most reviews come down to whether the firm can produce a document with a date on it. A firm that reads the security section before acknowledging it, keeps an obligations register, and treats its IT provider as the owner of the technical lines can meet nearly any guideline a client sends.

GlobeVM builds and runs the security side of these obligations for law firms in the Los Angeles area, from MFA and encryption through incident plans, vendor flow-down, and the evidence library a client review expects. If a client's guidelines are sitting unread in your inbox, contact GlobeVM for a free review of what they require and where your firm stands.

Comments

0 Comments