Skip to main content
RiskZeroCertifiers

Industries

ISO 27001 certification for legal and professional services

Certification for firms whose clients demand confidentiality evidence, planned around fee-earning work rather than against it.

Why organizations in this sector certify

  • Client outside counsel guidelines and supplier security requirements
  • Panel appointments and institutional client onboarding
  • Professional indemnity and cyber insurance conditions

Why professional firms certify

Institutional clients send outside counsel guidelines and supplier questionnaires that ask the same questions every year. Panel appointments increasingly require certification. Insurers ask about it at renewal. ISO 27001 replaces dozens of bespoke answers with a single independently audited statement, and the discipline of the ISMS reduces the risk that actually keeps managing partners awake: a confidentiality breach on a client matter.

What the audit focuses on

Professional services firms run on documents and email, with people who work from courts, client sites, and home. The audit examines how confidentiality is preserved across all of that:

  • Matter security. Classification of client information, access control at matter level, and ethical walls where required.
  • Email and transfer. Controls on sending client information, including misdirected email prevention, encryption, and secure file sharing.
  • Devices and remote work. Laptop and mobile device management, encryption, and what happens when a device is lost.
  • People. Confidentiality undertakings, screening, awareness training that fee earners actually complete, and leaver processes for staff who take client relationships with them.
  • Retention and disposal. File retention policy, deletion at end of retention, and secure destruction of paper.
  • Suppliers. Practice management, e-discovery, transcription, and cloud providers who process client information.

Minimizing disruption

We plan audits around court dates, quarter-ends, and deal cycles. Interviews with fee earners are short, scheduled in advance, and conducted remotely where possible. Most of the evidence comes from IT, risk, and HR, and can be reviewed without interrupting client work.

Scope

Whole-firm scopes across all offices are the norm. Multi-office firms can be certified under one certificate with offices sampled across the cycle rather than visited every year.

Questions

Questions from legal and professional services clients

How much partner time will the audit take?
Leadership interviews are typically one hour at Stage 2 and shorter at surveillance. The bulk of the audit involves the people who run IT, risk, HR, and knowledge management, plus short interviews with a sample of fee earners about how they handle client information day to day.
Can the scope cover only certain practice areas?
It can, but clients usually expect the whole firm. Scoping to a practice area is difficult because IT, HR, and document management are shared. Whole-firm scopes are the norm and are not much harder to audit.
We use a document management system. Is that enough for access control?
It is the foundation. The auditor will look at how matter-level security is applied, who can override it, whether ethical walls are enforced, and how access is reviewed when people change roles or leave.

Ready to scope your audit?

Tell us about your organization, your ISMS scope, and your target date. We reply with a fixed-fee quote and available audit dates within two business days.