Why professional firms certify
Institutional clients send outside counsel guidelines and supplier questionnaires that ask the same questions every year. Panel appointments increasingly require certification. Insurers ask about it at renewal. ISO 27001 replaces dozens of bespoke answers with a single independently audited statement, and the discipline of the ISMS reduces the risk that actually keeps managing partners awake: a confidentiality breach on a client matter.
What the audit focuses on
Professional services firms run on documents and email, with people who work from courts, client sites, and home. The audit examines how confidentiality is preserved across all of that:
- Matter security. Classification of client information, access control at matter level, and ethical walls where required.
- Email and transfer. Controls on sending client information, including misdirected email prevention, encryption, and secure file sharing.
- Devices and remote work. Laptop and mobile device management, encryption, and what happens when a device is lost.
- People. Confidentiality undertakings, screening, awareness training that fee earners actually complete, and leaver processes for staff who take client relationships with them.
- Retention and disposal. File retention policy, deletion at end of retention, and secure destruction of paper.
- Suppliers. Practice management, e-discovery, transcription, and cloud providers who process client information.
Minimizing disruption
We plan audits around court dates, quarter-ends, and deal cycles. Interviews with fee earners are short, scheduled in advance, and conducted remotely where possible. Most of the evidence comes from IT, risk, and HR, and can be reviewed without interrupting client work.
Scope
Whole-firm scopes across all offices are the norm. Multi-office firms can be certified under one certificate with offices sampled across the cycle rather than visited every year.