Lawyers are no strangers to documentation requests, dense forms and tight deadlines. But a client security questionnaire can still rattle even a well-run firm. The request may arrive as a spreadsheet with 150 questions, a portal link tucked into an onboarding email or a new set of outside counsel guidelines due by Friday.
Before long, the legal administrator is tracking down policies, the IT team is confirming technical settings, HR is pulling training records and firm leadership is trying to determine what the firm can confidently promise. The problem is often not that the firm lacks security controls. It is that no one has had to assemble the answers, evidence and responsible owners in one place before.
The questionnaire is testing more than individual controls
To the client’s legal team, the law firm is trusted counsel. To its security, procurement and risk teams, the firm is also a third party that receives confidential information and may exchange data through email, document systems, client portals, cloud platforms and other providers. The Association of Corporate Counsel’s model security controls reflect that perspective, treating outside counsel as one of the external organizations a company may evaluate before entrusting it with sensitive information.
That is why a questionnaire may jump from multifactor authentication and employee training to data retention, incident notification, backups and vendor oversight. Each question addresses a particular control, but together they test whether the firm understands where client information resides, limits access appropriately, prepares for security incidents and can continue serving clients if systems become unavailable.
The NIST Cybersecurity Framework 2.0 organizes these responsibilities around six functions: Govern, Identify, Protect, Detect, Respond and Recover, offering a useful view of the outcomes clients are evaluating.
Two firms may use similar security tools and still give clients different levels of confidence. One can identify control owners, provide current documentation and explain how its processes are tested. The other may have comparable protections but struggle to produce consistent answers or evidence. Demonstrating how security works can matter nearly as much as the controls themselves.
The controls clients typically ask about
Although questionnaires vary, outside counsel model controls and established security frameworks repeatedly return to the same parts of a security program. CISA’s baseline cybersecurity performance goals similarly identify a limited set of practices intended to reduce meaningful risk.
The questions generally fall into four broad categories, with policies, ownership and review practices cutting across each one:
- Identity and access: Does the firm require multifactor authentication, limit access based on job responsibilities and remove access promptly when an attorney or staff member leaves? Clients may also ask about remote connections, personal devices and administrative accounts.
- Information and system protection: How does the firm handle encryption, managed devices, endpoint protection, email security, patching, vulnerability testing, data retention and secure disposal? These questions look beyond the primary network to the firm’s broader working environment.
- Incident response and continuity: How would the firm detect suspicious activity, respond to an incident, notify affected clients and continue urgent legal work during an outage? Clients may request information about response plans, tested backups and business continuity exercises.
- Vendors and AI: How does the firm evaluate cloud providers and other vendors that may handle client data? Clients may also ask whether the firm has approved AI tools and clear rules for confidential information. The ABA’s Formal Opinion 512 reinforces that lawyers using generative AI must consider existing duties involving competence, confidentiality, communication and fees.
Requirements may be more detailed for clients in regulated or security-conscious industries, but the broader concern is consistent: Does the firm apply appropriate security practices across its people, systems, information and providers?
Having the controls is only half the answer
A “yes” may get the firm through the first round, but clients often follow with another question: Can you provide evidence? The request may range from a current policy to records showing when a process was last tested.
Common examples include:
- Security policies with an owner and recent review date
- Security awareness training completion records
- User access reviews and offboarding documentation
- Vulnerability assessment or penetration testing summaries
- Backup restoration and business continuity test results
- Incident response plans and exercise records
- Cyber insurance and vendor due diligence documentation
Some of that evidence may come from the firm’s cloud, security or technology providers, but the firm still needs to understand what each document covers. A provider’s SOC 2 report, for example, does not demonstrate that the law firm has configured access correctly, reviews user permissions or follows its own offboarding procedures.
Supporting documents allow the client to determine whether security practices are current, consistently applied and more than a written intention. A policy stating that access is reviewed regularly carries more weight when the firm can show when the review occurred, who completed it and how exceptions were resolved.
Some clients may request independent assurance, such as a SOC 2 report or ISO/IEC 27001 certification. Those can provide a standardized way to evaluate a security program, but they are not universal requirements. The ISO/IEC 27001 standard can also be implemented without pursuing certification. The appropriate level of assurance depends on the firm’s clients, information and contractual requirements.
When the honest answer to a question is “not fully,” the firm should avoid stretching a qualified response into a yes. It can instead describe the control currently in place, any compensating safeguards and the plan for addressing the remaining gap.
Evidence also needs to match the firm’s current practices. An impressive document library is not useful when policies are outdated, technical settings have changed, or different people provide conflicting answers to the same question.
A questionnaire is not the same as an audit
Most client requests begin with a questionnaire or a request for security documentation, not a formal audit. An ABA cybersecurity report found that 22% of respondents had been asked by a client or prospect to complete a security questionnaire, while only 14% had faced an actual security audit or other review.
The distinction matters:
- A questionnaire relies primarily on the firm’s answers and may lead to requests for evidence.
- A third-party risk assessment is more structured and may produce conditions or remediation requirements.
- An audit or technical assessment involves closer examination or independent testing of defined controls.
A questionnaire can still escalate if an answer raises concerns or conflicts with the documentation provided. Firms should respond carefully without treating every request as a formal audit.
Make the next request easier to answer
Law firms do not need to rebuild their response every time a client asks. A practical readiness process should include:
- A designated response owner who coordinates input from IT, risk, HR, firm leadership and outside providers
- A control matrix linking common questions to policies, evidence, responsible owners and known gaps
- An approved answer library so similar questions receive accurate and consistent responses
- A secure evidence repository containing current policies, reports, test results and insurance documents
Before a response is submitted or new outside counsel requirements are accepted, the firm should also review technical answers alongside the related contract language. Notification deadlines, audit rights, data-location requirements, restrictions on providers and client-specific AI rules can create obligations that extend well beyond completing the questionnaire.
Firms that receive a high volume of recurring requests may benefit from a trust center, a controlled online location for approved security information. Public information should generally remain high-level, while detailed policies, assessment reports, penetration testing summaries and other sensitive materials should be shared through controlled access. For many mid-sized firms, an internal repository and established approval process will provide most of the same value without the overhead of a public-facing portal.
The strongest response is not the longest or most polished. It is accurate, current and supported by evidence the firm can produce without a last-minute search.
If client security requirements are exposing gaps in your controls, documentation or ownership, Afinety can help your law firm assess what is in place, organize the supporting evidence and prioritize what needs attention. Talk with the Afinety team about preparing for the next client request before it arrives.

